Summary

  • Philip F. Smith began the Routing Report on 23 February 1999 to turn a BGP feed into a dated, regional and public account of what one Internet vantage point could actually see; by 27 August 2026, its DIX-IE view examined more than 1.06 million IPv4 entries and published explicit comparisons among announcements, registry allocations, aggregation possibilities and ROA states.
  • The report’s value depends on boundaries it states openly: it processes selected best paths, ignores alternatives in its principal analysis and cannot determine commercial intent, service reachability or legal authority. It can expose discrepancies and create peer pressure, but operators retain the decision—and the consequence—of changing a route.

The route table at 04:04

At 04:04 Australian Eastern Standard Time on 27 August 2026, one router at DIX-IE in Tokyo supplied a view containing 1,067,679 IPv4 routing-table entries. The analysis derived 409,542 prefixes after maximum aggregation by origin autonomous system, a deaggregation factor of 2.61, and 527,020 unique aggregates after removing what its method classified as unneeded subnets. It counted 79,000 autonomous systems. It also separated 732,044 prefixes covered by a valid Route Origin Authorization from 1,417 invalids and 334,218 for which no ROA was present.

Those numbers look global. They carry the scale and precision of a census. Yet the most important words on the page are not the totals. They are the location, time and method attached to them.

The data came from APNIC’s router at DIX-IE, formerly NSP-IXP2, and from the best paths that router had selected. It was not every route available to every operator. It was not every alternative held by that router. It was not proof that a destination answered, that traffic used the displayed path in both directions, or that the organisation named beside an ASN had approved every announcement. The report was a disciplined view of the control plane from a particular place.

That distinction is the centre of Philip F. Smith’s contribution. The Routing Report says its first edition appeared on 23 February 1999, during explosive commercial growth when public examination of the table was scarce. Smith began producing a daily report, with encouragement from APNIC and industry colleagues, to inspect the table by Regional Internet Registry region. A surviving APNIC meeting page from March 2000 describes his analysis as interpretations from daily dumps of the full IPv4 BGP table seen at APNIC’s router in Japan.

The act was modest in one sense: collect a feed, process it, publish the result. In another sense it rearranged the burden of proof. An allocation ledger could say which address block had been distributed through which registry. An operator could describe its network as large, resilient or efficiently engineered. The Routing Report placed a third entity between those claims: a reproducible observation of what a router was actually learning.

Why the report needed to exist

The project’s own history starts with the CIDR Report. As classful addressing gave way to Classless Inter-Domain Routing, the earlier report encouraged aggregation by naming networks that could reduce the global table. Smith’s explanation says the CIDR Report was essentially the only public examination available and operated at a global level that hid regional variation. His Routing Report was born from the need for a more detailed regional picture.

The distinction mattered because registration and routing are not copies of the same database. Registries distribute number resources and maintain records about them. Routers exchange reachability through BGP according to local policy.

A prefix may be allocated but not announced. An announced prefix may be more specific than the allocation from which it came. The origin visible in BGP may be inconsistent with a registry or authorization record. A private, reserved or unallocated ASN may appear in a path. A special-use or apparently unallocated address block may be announced. None of those states can be inferred reliably from the allocation ledger alone.

Smith’s report turned that mismatch into recurring columns. It counted entries, origin ASes, transit ASes, prefixes by registry region, path lengths, 32-bit ASNs, prefixes from unregistered ASNs, announcements from unallocated address space and possible aggregation savings. Later versions incorporated RPKI states. Each metric joins at least two layers that institutions often blur: what a registry says exists, what an authorization entity permits, and what a routing speaker exposes to an observer.

The value is not that one layer defeats the others. A live announcement does not prove title or permission. A registry entry does not prove the route is active. A valid ROA does not prove the path is benign, the service is reachable or the announcement matches a customer contract. A report that keeps the fields separate helps an operator ask the next question instead of allowing one record to impersonate an answer to every question.

The method is a map of its limits

The technical explanation is unusually useful because it does not hide behind the word “global.” It says the principal report takes a BGP feed from an Internet router hosted by APNIC at DIX-IE. That router receives a full table from APNIC’s transit providers at the exchange. The analysis software expects a captured router table and ordinarily processes best paths only, ignoring alternatives. If a supplied feed has no path marked best, the software takes the first path, which it describes as basically the oldest path visible to the router.

This choice is defensible. A selected best path shows the route the local control plane prefers under its current inputs and policy. It gives the analysis one consistent entity per destination. Processing every alternative would answer a different question and make comparisons harder.

But the choice also excludes information. Another router can select another path. The same router may hold several paths while exposing only one to this analysis. Add-path deployments, route-reflector topologies, local preference, peering relationships and import policy all shape what is visible. A path absent from the report may exist elsewhere. A path present in Tokyo may not be selected in Brisbane, Singapore or Hong Kong. “Not seen” is not the same statement as “does not exist.”

The report’s caveat goes further. Smith writes that errors may remain in the analysis software and that some older reports were not rerun after bugs were fixed. That is not a weakness to be edited out of the story. It is part of the evidence contract. A time series can remain valuable when method changes and known discontinuities are visible. It becomes dangerous when an analyst silently turns corrected software into a claim that every historical value was produced on an identical basis.

This is why the report is better understood as an instrument than an oracle. Its method explains what it can resolve. Its vantage point explains where it looks from. Its timestamp explains when the claim held. Its caveats explain what a reader must not infer.

One million entries do not mean one million independent destinations

The headline count is easy to misread. A BGP routing-table entry is a prefix and associated path state in the observed control plane. Several entries can cover overlapping address space. A network may advertise an aggregate and more-specifics. Different origins can announce adjacent blocks. Traffic-engineering choices can make the visible table much larger than the smallest possible cover of the address space.

The Routing Report therefore offers several aggregation views. “Maximum aggregation” collapses prefixes without attending to origin AS or AS path. In the project’s example, a covering /16 can make a /24 and /21 disappear from the mathematical set even if those more-specific announcements carry different paths or operating purposes. A second measure aggregates by origin AS, retaining more distinctions. The deaggregation factor compares the observed table with a reduced counterfactual.

The counterfactual is useful because it reveals how much routing specificity is being purchased. It is not an instruction to withdraw every specific. A more-specific route may steer inbound traffic, isolate a failure domain, support multihoming, move a service during migration or reflect a commercial interconnection. Collapsing it could overload a link, remove a recovery path or make the aggregate continue to attract traffic when a component is unavailable.

The current report itself acknowledges the trade-off: maximum aggregation makes no allowance for deaggregation used for multihoming traffic engineering. That sentence prevents a table-efficiency metric from becoming an engineering verdict. The right operational question is not “How many prefixes could disappear?” It is “Which prefixes lack a continuing, evidenced purpose, and what breaks if they disappear?”

On 27 August the report counted 349,520 prefixes smaller than registry allocations. That is a monitoring population, not a guilty population. A reviewer can compare the specifics with origin, path, route policy, service design and failure history. The number directs attention. It does not settle the case.

The registry comparison does real work

Rejecting a simplistic enforcement use does not make the registry comparison optional. The report’s regional structure is meaningful precisely because routing data alone does not carry a reliable account of allocation history. It maps ASNs and address blocks into RIR regions, then asks different questions about prefixes announced by regional ASes and prefixes announced from regional address blocks.

Those are not interchangeable sets. An ASN associated with one service region can announce address space distributed through another. Historical early-registration transfers leave holes in nominal blocks. Address transfers and organisational changes complicate geographic stories. The report’s field definitions make the joins inspectable rather than hiding them inside a single regional total.

The same discipline applies to anomalous resources. On the dated DIX-IE view, the analysis reported 1,322 prefixes from unregistered ASNs, 524 prefixes from unallocated address space and one special-use prefix. Each count is a signal to verify the current IANA and RIR data, the origin, the path, the collector input and the intended use. It is not, by itself, proof of hijacking or fraud.

A registry record can be stale. A report can use an outdated mapping file. A legitimate transition can briefly produce an unusual announcement. A typo can leak a private ASN into a path. An attacker can also exploit exactly these ambiguities. The safe response is neither blind trust nor automatic condemnation. It is an evidence chain that preserves the registry record, routing observation, time, viewpoint, authorization state, operator explanation and service effect.

ROA status adds an authorization signal, not a complete verdict

The modern report includes RPKI data from an NSRC validator cache using trust anchors from the five RIRs, plus APNIC and LACNIC AS0 trust-anchor material. This lets it classify observed prefixes by route-origin authorization state.

The 27 August IPv4 view contained 732,044 valid prefixes, 1,417 invalid and 334,218 with no ROA. Its IPv6 summary contained 197,504 valid, 105 invalid and 45,044 with no ROA. These counts show both substantial deployment and incomplete coverage. They also demonstrate why the categories need care.

“Valid” means the observed origin and prefix length are consistent with a matching authorization under the validator’s current inputs. It does not authenticate every AS in the path, prove the origin’s business right to carry a customer route, guarantee that the service is safe, or show that every operator enforces route-origin validation. “Invalid” can expose a harmful event, but it can also arise from a stale or incorrectly scoped ROA during a legitimate change. “Not found” records absence of matching authorization; it is not a synonym for malicious.

The report is most useful when these states become prompts for bounded action. An invalid that appears across several feeds, begins at a clear time and affects service deserves rapid coordination. A growing no-ROA population in a critical network can justify an adoption discussion. A valid route with an unexpected path still requires other evidence. The authorization signal narrows uncertainty without abolishing it.

Public measurement creates a different kind of power

A published ranking changes incentives even when its author cannot touch a router. The Routing Report lists ASNs that contribute many prefixes, ASNs with large theoretical aggregation savings and outliers in path prepending. Operators, peers, customers and researchers can compare a network with others. A name that repeatedly appears near the top can attract questions.

That visibility is power in a practical sense. It can make an otherwise private operating choice legible. It can turn a vague complaint about table growth into a specific conversation. It can help an engineer secure internal time to remove an obsolete announcement. It can reveal that a global narrative has different regional shapes.

Yet the historical record also shows the limit. Minutes from the APNIC Open Policy Meeting in February 2001 record a question about whether highlighting network problems created peer pressure. The discussion noted that the Routing Report and CIDR Report no longer seemed to exert the same pressure. It also recorded justified reluctance for RIRs to police Internet operations and the possibility that some visible practices made commercial sense, requiring allocation policy to be reconsidered rather than operators simply blamed.

This is an unusually mature boundary. Measurement can expose a cost borne by the shared routing system. It can also fail to see why a network accepted that cost. The registry has evidence about allocations but not complete knowledge of topology, traffic, contracts or failure modes. If it converts a table-size ranking into an enforcement rule, it risks optimizing the metric while damaging the network.

Smith’s significance is not that the report won an argument forever. It is that he maintained an entity around which the argument could remain empirical. The report could be ignored, challenged, corrected or supplemented. That is a more durable function than temporary peer pressure.

Operator forums gave the numbers a place to be contested

Data does not interpret itself. The report circulated through operator mailing lists and meetings, including NANOG, APOPS, the RIPE Routing Working Group, AfNOG and AusNOG. These venues brought together people capable of explaining an announcement, comparing observations and testing whether a proposed remedy survived local reality.

APNIC’s record of APOPS in 2005 names Smith as a co-chair and describes a forum that began as a mailing list for ISP operations engineers before meeting alongside regional conferences. That history matters for attribution. The report did not acquire legitimacy because one person issued a score. Its findings became useful when operators could inspect the method and answer with evidence.

An operator group is not automatically representative, and attendance does not create a mandate. Its practical advantage is narrower: it can lower the cost of technical rebuttal. An engineer can show that a more-specific route protects a multihomed site. Another can demonstrate that an old prefix has no remaining purpose. Someone maintaining the analysis can correct a parser or mapping. The argument is stronger when the method and the exception are both public.

This structure preserves local decision. The report identifies a discrepancy. The forum supplies review. The network that owns the production consequence chooses and executes the change. If that network does nothing, other networks still retain their own peering, filtering and commercial choices. Coordination works through evidence and reciprocal decisions rather than through a fictional central switch.

More vantage points improve the question, not abolish perspective

The Routing Report no longer relies on only the original Japanese feed. Its current home page lists DIX-IE, Brisbane, Singapore and Hong Kong data, as well as combined work. NSRC operates a related report for global research and education networks using voluntary feeds; the project describes about 30 sources in that context.

This expansion changes what can be tested. If an announcement appears in Tokyo but not Singapore, the difference may point to propagation, policy, collection or timing. If several views select different paths, they reveal topology and preference that one table would conceal. If an anomaly appears everywhere at nearly the same time, the case for a broad event strengthens.

But thirty views are still views. They do not sample every edge network, every private interconnection or every alternative path. Feed providers are not a statistically random population. A combined table can deduplicate prefixes while masking disagreements about path. Adding collectors reduces some blind spots and creates new questions about synchronization, comparability and feed health.

The correct gain is therefore not omniscience. It is triangulation. A single observation becomes one claim. Agreement among independent observations becomes stronger evidence. Disagreement becomes information to investigate. The network remains larger than the measurement system.

IXPs reveal the value of a local eye

An APNIC article about an APRICOT 2025 panel extends this argument. The panel began from the premise that Internet Exchange Points possess local and regional vantage points capable of exposing availability and performance that global public projects may not measure as accurately. Smith participated alongside operators and researchers, with the article noting his long involvement in establishing IXPs and assisting RouteViews.

An IXP sees a particular set of members and relationships. That limitation is also its advantage. A globally distributed probe system can show that a service is reachable from many places while missing a local path detour, domestic outage or exchange-specific withdrawal. An exchange can compare member and route-server observations with local operational context.

Again, the IXP does not become the authority over its members’ routers merely because it can measure them. Its data can support a member service, a resilience discussion or an incident timeline. The member controls import and export policy. The exchange controls its own collector and route-server systems. Researchers control analytical choices. Clear institutional boundaries allow these parties to contribute without pretending they share one command surface.

This is the broader history visible in Smith’s work. The NSRC biography connects him to early commercial Internet engineering, LINX, Cisco, APNIC, operator training, IXPs and operator groups. That record explains why the Routing Report was not merely a statistical hobby. It came from the operating culture in which an external view is valuable because no network can inspect the whole system from inside itself.

A person article must preserve the collaborators

The report bears Smith’s name and first-person account, but its public evidence rejects a lone-inventor story. He credits Tony Bates for the original CIDR Report inspiration, Geoff Huston for suggestions, bug reporters for corrections and APNIC for hosting the system, processing data and providing access to its router. Feed providers make the later multi-view work possible. RIR and IANA data supplies the registry comparisons. RPKI repositories and validators supply another layer. Operator lists create the audience and feedback channel.

Smith’s attributable decision was to build and sustain a recurring analytical publication around these inputs. That is consequential. Long-running measurements require mundane continuity: collecting feeds, updating mappings, adapting to new ASN formats, adding RIR regions, documenting metrics, correcting code and keeping output available. Persistence turns a snapshot into a record against which change can be observed.

It does not make every underlying contribution his. APNIC’s router is not his router. An operator’s announcement is not his decision. A ROA is not his authorization. A community response is not his command. Accurate credit makes the instrument more—not less—impressive because it reveals how thin coordination can outlast any one institution’s complete control.

Twenty-seven years is an operating result

A daily measurement project has a failure mode that a single paper does not: it can simply stop. The collection session breaks, a router changes format, a registry moves a file, an ASN no longer fits an old parser, a server is replaced, a maintainer changes role, or the audience drifts to newer tools. The result can remain technically interesting while becoming operationally unavailable.

The Routing Report’s continuity from 1999 into 2026 is therefore part of the evidence. It survived the growth from three RIR comparisons to five, the widespread appearance of 32-bit ASNs, IPv6 routing, transfer-era registry complexity and the arrival of RPKI data. The current site also distinguishes feeds that are active from feeds that have retired. These are not glamorous facts about invention. They are the maintenance facts that make a long record usable.

Continuity should not be confused with perfect comparability. A metric added in 2026 cannot be projected backwards merely because the report name remained the same. A parser correction can create a break between old and new output. A changed transit feed alters the visible table even if the global routing system did not undergo the same change. A new RIR changes the regional classification. A reader who compares distant dates needs the method, input history and correction record as much as the output files.

This makes stewardship an active analytical task. The maintainer must decide whether to preserve an old result known to contain an error, regenerate it with new code or publish both with an explanation. Regeneration improves consistency but can erase the historical method. Preservation protects the record of what was reported but can invite false comparison. The project’s note that older outputs were not all rerun after bug fixes chooses transparency over silent revision.

For operators, the time series is most defensible when used to establish a baseline and locate a break. A sudden increase in prefixes, a new origin, a change in ROA status or a divergence among feeds can be tied to an exact interval. The report cannot provide the cause by itself, but it can narrow the search. A long-lived observation makes organisational memory less dependent on the engineer who happened to be watching at the time.

For institutions, the continuity has another lesson. The public benefit does not require the measurement system to own the entities it measures. It requires stable access, method documentation, preserved history and a credible correction path. APNIC could host a router and report service without claiming control over all announced prefixes. NSRC could extend the method to research and education networks through voluntary feeds without converting participation into jurisdiction.

For a person profile, this is also where observable character replaces reputation. The public record does not reveal Smith’s private motivation on every maintenance day. It does show a repeated choice to keep the instrument running, explain its categories, acknowledge errors and add viewpoints. Persistence is visible in the archive itself. It is a stronger basis for attribution than adjectives about vision or influence.

What the 2026 snapshot can and cannot say

The dated table supports several bounded conclusions. IPv4 routing remains a system of more than a million observed entries and tens of thousands of autonomous systems. The gap between observed prefixes and aggregation counterfactuals is large. Route-origin authorization covers a majority of observed prefixes in this view but leaves a substantial no-ROA population. Unexpected registry and special-use states remain observable rather than theoretical.

It cannot support a claim that the Internet has exactly 1,067,679 globally operative routes. The number can change within minutes and differs by viewpoint. It cannot show how many entries are unnecessary in production merely because mathematical aggregation can reduce them. It cannot prove that all 1,417 invalids were attacks or mistakes. It cannot translate path length into user performance. It cannot show traffic volume, contract terms, forwarding behavior after selection or end-to-end service availability.

The honesty of the instrument lies in keeping those absences visible. A strategic reader does not ask the report to become something it is not. The reader uses it to identify a discrepancy worth another query: another collector, a looking glass, an operator statement, an RIR record, an RPKI object, a configuration change or a service probe.

The durable contribution is a verification habit

Smith’s Routing Report demonstrates a simple discipline across twenty-seven years: state the observation point, preserve the time, define the calculation, expose the exceptions and invite a technically answerable dispute.

That habit is more important than any single league table. A registry can apply it when it distinguishes allocated resources from routed resources. An operator can apply it when it compares intended announcements with external views. A researcher can apply it when several collectors disagree. A policy body can apply it by publishing evidence without claiming that the evidence automatically supplies jurisdiction.

The report also demonstrates that transparency does not eliminate judgment. Someone chooses feeds. Someone defines aggregation. Someone maps resources to regions. Someone labels an outlier. Those choices should be reviewable, versioned and open to correction. The alternative is not neutrality; it is hidden methodology.

This is where the article’s title earns its second half. The Routing Report could observe. It could make discrepancies public. It could embarrass, persuade and educate. It could not command a network to remove a route, and it could not bear the service consequence if the advice was wrong. Its authority was evidentiary.

That is not a lesser authority. In a distributed network, it may be the kind that scales.

Sources