Skip to main content

Topic

DNS Delegation Power

Within the Topic facet, DNS Delegation Power topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

A blank regional dossier rests over a relief map of Africa as illuminated routes divide toward existing technical programs, an external partner network, and unresolved empty trays.

ICANN

ICANN Mapped AFRALO’s Requests Without Adopting Them

The most important phrase in the AFRALO-AfrICANN submission is not in the Board Chair’s reply. It is in the cover note: the statement was sent to the ICANN Board “for information purposes.” Six pages of recommendations then met a two-page response that acknowledged the problem…

Sep 20, 2026
A continuing blue DNS delegation diagnostic rail passes through verification gates while a separate amber bulk-alert rail stops at a closed gate.

Story

RIPE NCC Kept the Lameness Checks and Stopped the Emails

In 2009, RIPE NCC separated two activities that are often mistaken for one: it continued periodic checks of broken DNS delegations and ended the bulk email alerts generated from them. The decision is a useful historical operating case in what an infrastructure measurement can…

Sep 20, 2026
autistici.org — serverHold — 2026-08-28

ICANN

The autistici.org Hold Has a Timestamp but No Public Decision Receipt

PIR’s RDAP service records exactly when `autistici.org` changed and which registry controls remain applied. It cannot tell the public who connected a US sanctions designation to that domain-wide action, which rule governed the choice, why it happened before a wind-down licence…

Sep 20, 2026
Three side-by-side cards labelled BYLAWS, CONTRACTS and POLICIES beneath ICANN, with a magnifying glass and a small DNS network motif.

ICANN

The Enforcement Chain Behind ICANN’s Rules

ICANN's authority becomes consequential only when a policy, contract, compliance process and review route connect to an operational act. The public record identifies that chain, but it does not yet prove a single regulator-like mandate, a current universal contract baseline or an…

Sep 19, 2026

Global Cloud Services

Genesis Cloud’s Network Control Plane: When AS209045, DNS and Peering Still Do Not Prove Reachability

Public records can describe a cloud provider’s network identity without proving that customers have an independently observable path to its applications. Genesis Cloud’s case is therefore less a question of whether one registry entry is authoritative than of whether several…

Sep 19, 2026

ICANN

ICANN’s Authority Is Layered—and So Are Its Remedies

ICANN does not exercise one undifferentiated kind of power. Its authority is assembled from corporate instruments, Bylaws, policy procedures and private contracts; the route for challenging an action depends on which layer produced it.

Sep 17, 2026
Two separate DNS measurement bays compare one authoritative endpoint with two; unequal sample vessels and blank receipt sheets sit between them.

Story

APNIC’s Two-Nameserver Run Had Fewer Repeats. The Difference Still Needs a Reproduction Receipt

APNIC measured fewer authoritative DNS queries in a later run using two nameservers than in an earlier run using one. The observation is real in the published aggregates; the cause is not settled. A reproducible decision needs the two treatments to share a clock, cohort and…

Sep 15, 2026
Signed amber DNS record capsules pass unchanged through a plain relay toward a separate cyan verification instrument and trust anchor.

History

RFC 2065: The DNS Reply Crossed an Ordinary Server. Its Signature Carried the Trust

In January 1997, RFC 2065 proposed a security upgrade that did not require every machine carrying a DNS answer to become its judge. A security-aware resolver could retrieve signed records through a server that knew little about the new machinery and verify the evidence itself.…

Sep 15, 2026
Two separate cyan and amber network channels enter one circular exchange fabric, then branch toward distinct constellations of DNS query lights in a dark indigo room.

Story

AFRINIC’s Uganda Anycast Node Is Two Services, Not One

AFRINIC’s Uganda Anycast Node Is Two Services, Not One intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Story…

Sep 14, 2026
A blue DNS core with five protected functions continues while an amber alternative-name branch winds down through recorded state changes.

ICANN

ICANN’s Alternative-Name Integration Needs a Verifiable Turn-Down

ICANN’s draft model would let a gTLD registry coordinate the same name across the global DNS and another naming system. The report recommends a mandatory plan for switching that integration off. The harder governance test is whether the operator can later prove that every…

Sep 14, 2026
An abstract recursive-resolver bridge joins separate DNS transport paths and an IPv6 service path above a subtle map of Africa.

Story

AFRINIC’s ccTLD Test Cannot Set a Country’s IPv6 Ceiling

The deployment monitor makes a useful check of registry nameservers, then draws a conclusion about every site below them. A recursive resolver can cross a transport boundary that the wording leaves out.

Sep 14, 2026
Wordless editorial illustration of a broad legacy network intake being constrained beside distinct purpose-specific fibre routes, an hourglass exception tag and an accountable guiding hand.

IETF

DNS ANY Should Be Retired by Purpose, Not by Query Code

A server can stop answering an ambiguous DNS query in one release. It cannot, by that act alone, replace the diagnostics, discovery habits and legacy dependencies that grew around the query. The defensible unit of retirement is the purpose, with an owner and a substitute—not…

Sep 14, 2026
Wordless editorial illustration of an old and a newly preferred local discovery server on opposite sides of a reconciliation plane, with printer, display, sensor, workstation and controller paths aligned except for one unresolved service.

IETF

A ULD Server Handoff Needs Proof That Local Services Survived

The network can stay up while the printer, display and local controller quietly disappear. That is the awkward possibility inside a seemingly clean Unicast Local Discovery transition. A client may correctly choose a better server, close its old path and report success. Yet the…

Sep 13, 2026

IETF

The Zone Was Still Answering. The Signing Key Was Already Gone

A correctly signed zone can outlive the private key that produced it. That interval is not recovery; it is a perishable option whose value depends on preserving old cryptographic state while proving, clock by clock, that a replacement chain has taken over.

Sep 12, 2026
Four distinct DNS evidence paths enter a central TLSA validation chamber and emerge at an amber stop or a grey unauthenticated continuation.

IETF

DANCE 14 Turns Four TLSA Outcomes Into a Two-Way Server Decision

Four DNS observations can now enter the same TLS policy gate. The latest DANCE client-authentication draft tells a server what to do when it receives anything other than a DNSSEC-validated TLSA record set: abort, or continue while treating the client as unauthenticated. Revision…

Sep 12, 2026
An abstract resolver chamber marks an active exception while one comparison path completes and another fades before an outcome.

IETF

EDE 33 Can Show an NTA Without Showing It Changed the Answer

A new DNS diagnostic can make a hidden exception visible without explaining its effect. EDE 33 tells a client that a covering Negative Trust Anchor was active when a resolver generated a response. The current draft also allows the signal when the exception made no material…

Sep 12, 2026
Four brass network junctions receive glass conduits; one glows in its current socket while three use adjacent legacy sockets and intact parallel paths.

Story

RIPE NCC’s Four Stale IPv6 Glue Records Are Now Three. Root Repair Was Never a Batch.

One of four old IPv6 glue mappings identified after RIPE NCC’s AuthDNS renumbering has aligned with the nameserver’s current address. The other three have not. That split result reveals the real unit of root-zone maintenance: one delegation, one authorised decision and one…

Sep 12, 2026
AI editorial portrait of Gihan Dias beside two branching DNS structures representing Sri Lanka’s Sinhala and Tamil domains

History

Gihan Dias and the Two Names Sri Lanka Added to the Root

The smallest-looking part of a national network can expose its largest unfinished business. For Sri Lanka, two names in the DNS root showed that connecting a country and letting it recognise itself online were separate engineering tasks.

Sep 12, 2026
A text-free dark workbench shows two rails of paired file tiles, each with an intact seal, converging on a blank batch folio.

Story

LACNIC Signs 150 Reverse-DNS Files. The Batch Has No Manifest.

LACNIC’s public directory gives every reverse-DNS data file its own signature and checksum. What it does not give a whole-directory consumer is one signed statement saying which 150 filenames belong to the same completed publication.

Sep 12, 2026
AI editorial portrait of Demi Getschko beside a late-1980s academic-network terminal, a DNS hierarchy and a network map of Brazil

History

Demi Getschko and the Country Code That Arrived Before Brazil Spoke TCP/IP

On 18 April 1989, `.br` entered the DNS root while Brazilian academic networks were still speaking BITNET, HEPnet and other protocols. Demi Getschko's part in that sequence reveals a neglected infrastructure skill: securing a durable name, accepting responsibility for it and…

Sep 12, 2026