Summary

  • AS210574, registered to PH Bilisim Teknolojileri Limited Sirketi, is not an empty registration: independent routing trackers show nine to ten IPv4 /24s originated, with the core set at or near 100% global propagation.
  • The operator's PeeringDB entry still reports zero IPv4 and zero IPv6 prefixes and was last updated on 13 August 2025 - more than a year behind the routing record.
  • Through 2026 the RIPE aut-num was edited repeatedly: imports from AS48678, AS200010 and AS34927 in June, then from AS6205, with AS213382 listed as peer by July and September.
  • One announced prefix, 185.148.241.0/24, is listed as RPKI-invalid, and two /24s propagate at roughly 2.4%.

Registry identity and a year of edits

AS210574 is allocated under RIPE to PH Bilisim Teknolojileri Limited Sirketi (ORG-PBTL6-RIPE, registration number 1079768), a Turkish organisation typed as a local internet registry. The allocation dates to 27 October 2021, the AS name is POYRAZ, and the ASN type is recorded as hosting. The same objects show repeated maintenance across 2026: the aut-num was last modified on 15 September 2026, importing from AS6205 (HizliNet Teknoloji A.S.) and from its own as-set, while the organisation object was created on 17 February 2026 and last modified on 31 August 2026, carrying an İstanbul address in Ataköy that matches the operator's published contact address https://ipgeolocation.io/browse/asn/AS210574. Mirrors of those records add the allocation status and show a Halkalı address on an earlier version of the organisation object, indicating a documented address move during the year; they also capture a June 2026 aut-num that authorised imports from AS48678, AS200010 and AS34927 https://whois.ipip.net/AS210574. A later version of the aut-num, recorded in a whois mirror queried on 26 August 2026 and dated 24 July 2026, shows imports from AS6205 and AS213382 (PEERYX NETWORK SAS, France) - a different transit set again - and lists the abuse contact used for the network https://phish.report/contacts/POYRAZ.

What the routing tables show

Independent routing snapshots do not support reading AS210574 as dormant. Hurricane Electric's toolkit lists nine originated prefixes, eleven announced prefixes including two over IPv6, 2,304 originated IPv4 addresses, three observed BGP peers with AS48678 (Pentech Bilisim) as the IPv4 peer, and one internet exchange presence at the 4b42 Internet Exchange Point in Zurich; its page footer is dated 10 May 2026, so it describes spring rather than today https://bgp.he.net/AS210574.

ping.pe records ten announced /24s, nine of them RPKI-valid and one - 185.148.241.0/24 - invalid https://records.ping.pe/210574. Qrator Labs' Radar shows nine core /24s each observed by 540 to 563 peers, effectively full propagation: 5.250.253.0/24 at 563 observers, 213.238.180.0/24 at 554, 193.111.125.0/24 at 550, 46.36.201.0/24 at 547, 2.59.117.0/24 at 546, 45.59.70.0/24 at 545, 5.180.81.0/24 at 545, 185.223.77.0/24 at 545 and 87.76.139.0/24 at 540. The same view shows 141.98.112.0/24 and 141.98.115.0/24 at only about 2.4% propagation against a dozen observing peers, plus a cluster of /32 host routes with invalid RPKI at 1-2% propagation https://radar.qrator.net/as/210574/connectivity/prefixes.

bgp.tools, whose cached timestamps predate the 2026 registry edits, lists fourteen originated IPv4 prefixes including 91.151.90.0/24, 91.151.93.0/24, 213.142.157.0/24 and 185.148.242.0/24, names AS44547 (Netundweb) as upstream and peer, and records FogIXP membership at 10 Gbps https://bgp.tools/as/210574. check-host.cc reports ten routed prefixes and three peers https://check-host.cc/as/210574. ASN summaries published by ipinfo.io https://ipinfo.io/AS210574, ipregistry.co https://ipregistry.co/AS210574 and canon.whisper.security https://canon.whisper.security/asn/210574 carry the same ASN identity and Turkish registration.

The disagreement between trackers is itself informative. Counts run from nine originated prefixes in registry-derived views and Hurricane Electric, to ten at ping.pe and check-host.cc, to fourteen in a cached bgp.tools snapshot; the IPv6 picture is likewise split, with one tracker showing two announced IPv6 prefixes and registry-derived views showing none. Those are snapshot differences over partly announced space, not proof that any single figure is wrong.

The database that says nothing is announced

Against that, the operator's own interconnection record on PeeringDB is empty and old. The network entry for AS210574 (net 33946) shows zero IPv4 prefixes and zero IPv6 prefixes, an as-set RIPE::AS210574:AS-POYRAZ marked verified, an RIR status of ok, and a last-updated stamp of 13 August 2025 https://www.peeringdb.com/asn/210574. The same stale timestamps appear on the ASN view of the record https://www.peeringdb.com/net/33946. Contact details and a NOC entry are populated, so the record was set up deliberately; what has not happened is maintenance. PeeringDB prefix fields are self-reported and are commonly left at zero by smaller networks, but the mismatch here is stark enough to state plainly: the database says nothing is announced while three or four independent BGP views say several /24s are.

One invalid prefix and a weak pair

Two routing details deserve separate treatment. A route-origin authorisation for AS210574 does exist in the RIPE NCC's RPKI repository, so the operator is not absent from route-origin validation https://console.rpki-client.org/rsync.paas.rpki.ripe.net/repository/7ff0f555-dba7-4192-a01d-f6916d5bb84e/0/AS210574.roa.html. The invalid status attached to 185.148.241.0/24 therefore concerns one announcement rather than the network's absence from validation, and the weakly propagated pair at 2.4% is equally unresolved in the public snapshots: leased or recently moved address space, policy filtering by observatories, and prefixes flapping between snapshots would all produce similar readings.

A commercial surface, and its complaints

Commercially, the operator presents as a live Turkish hosting business rather than a shell. Its website advertises hosting and VPS services https://www.poyrazhosting.com.tr/, with an about page https://www.poyrazhosting.com.tr/hakkimizda.php and a contact page https://www.poyrazhosting.com.tr/iletisim.php. Third-party comparison data https://www.whtop.com/compare/hostingdunyam.com.tr,poyrazhosting.com.tr and a corporate LinkedIn presence https://www.linkedin.com/company/poyrazhosting corroborate an operating brand, and a LinkedIn post about the global cPanel disruption indicates a cPanel-based shared-hosting product line https://tr.linkedin.com/posts/poyrazhosting_d%C3%BCn-t%C3%BCm-d%C3%BCnyay%C4%B1-etkileyen-kritik-cpanel-activity-7455640497211121665-xz67. Customer-review platforms show real, if mixed, activity: Trustpilot carries reviews of the domain https://www.trustpilot.com/review/poyrazhosting.com.tr, and Turkish complaint platform Şikayetvar holds a claim that a VDS server was suspended despite payment https://www.sikayetvar.com/poyraz-hosting/odeme-dekontum-olmasina-ragmen-vds-sunucum-haksiz-sekilde-askiya-alindi and a joint complaint against Natro and Poyraz Hosting over DNS forwarding and support responsiveness https://www.sikayetvar.com/natro-hosting/natro-ve-poyraz-hostingde-dns-yonlendirme-sorunu-ve-musteri-destek-eksikligi. Those are customer allegations, not findings; they are evidence that a paying customer relationship exists, not evidence of how well it is served.

The bounded conclusion

The evidence supports a narrower claim than either "dormant ASN" or "thriving network". AS210574 is measurably originating address space with global visibility, and its registry objects were actively maintained through September 2026. What lags is the operator's own commercial and interconnection self-description, and what remains unexplained is the invalid prefix, the weakly propagated pair and the repeated rewriting of authorised transit. For a market where IPv4 space is scarce and small hosting brands are often assembled from leased capacity, that combination - live routes, stale metadata, rotating upstreams - is a recognisable stage of growth, not a verdict. The directory record for this operator, including its unresolved questions, is maintained at https://btw.media/en/directory/poyraz-hosting.