Summary

  • ICANN says MTN Nigeria has enabled DNSSEC validation across its resolver infrastructure, while NiRA has separately signed the .ng country-code zone.
  • In Ghana, ICANN attributes a rise from about 20% to 98% validation to MTN Ghana’s resolver deployment; KINDNS lists the operator in its shared-private-resolver category.
  • APNIC Labs measures user paths, not the signing of all domains or the configuration of every resolver. Its 30-day sample reports 99.27% validation for Ghana and 62.00% for Nigeria, using a different window and method from ICANN’s rounded figures.

The most consequential sentence in ICANN’s 24 September account is not a percentage. It is the change of subject between two Nigeria claims. MTN Nigeria has enabled validation on recursive resolvers, ICANN reports. The Nigeria Internet Registration Association has signed .ng, it says separately. One operator checks answers on the way to users; the other makes a national zone’s answers capable of being checked. Training and coordination can encourage both, but neither duty can be performed merely by announcing the other.

ICANN credits work with the Nigerian Communications Commission, beginning with a December 2024 webinar, and says the country’s validation rate is approaching 60%. Its statement that MTN Nigeria contributed significantly is an operational attribution from the organization conducting the engagement, not an audit of MTN’s entire resolver fleet. Signing .ng is a different control surface. IANA records NiRA as the ccTLD manager, and ICANN says its Coalition for Digital Africa roadshow helped the registry sign the zone. That does not establish that every domain below .ng is signed, or that every Nigerian client uses a validating path.

Ghana makes the resolver side especially visible. ICANN attributes the country’s move from roughly 20% to 98% validation to MTN Ghana turning on validation across its recursive infrastructure. It also says MTN Ghana joined KINDNS. The programme’s own participant table places MTN Ghana under “Shared Private Resolver Operators,” a useful description of where practice has to change. Membership records a voluntary commitment to the programme; it is not a certificate that each operational practice has been independently tested.

There is an independent observation, but it must be read precisely. APNIC Labs’ 30-day table for 22 August through 20 September shows 99.27% of its Ghana sample as validating and 62.00% of its Nigeria sample as validating, with another 27.93% in the partial category for Nigeria. APNIC uses unique names in web advertisements to test whether sampled clients can retrieve a correctly signed name but not one with an invalid signature. It sees the resolver path used by those clients. It does not count all signed zones and cannot, from country totals alone, identify how much of the change MTN caused.

ICANN’s rounded 98% and near-60% should therefore not be presented as if they were the same APNIC observation at the same instant.

The distinction is operational rather than semantic. DNSSEC requires signed data and a validating route to the user. A parent-zone signature without a validating resolver can go unchecked; a validating resolver cannot authenticate an unsigned child merely because a national zone was signed. The two Nigerian actions and Ghana’s resolver change are complementary, not interchangeable milestones on a single institutional scorecard.

Sources