Summary

  • RFC 3330 collected scattered special-use IPv4 blocks, making explicit that numerically similar addresses could obey radically different host, source, destination, forwarding and leakage rules.
  • Its table was a historical snapshot, not a permanent security oracle. Successor RFCs and the live IANA registry made classification multidimensional, versioned and subject to more-specific entries.

One number space contained several kinds of place

An ordinary allocation can identify a host reached through public routing. But 127/8 is supposed to return inside the host. RFC 1918 private space belongs inside administrative interiors. IPv4 link-local addresses serve one link when ordinary configuration is unavailable. Documentation and benchmark ranges exist so examples and controlled tests do not borrow live destinations. Multicast and limited broadcast follow still other forwarding rules.

Before RFC 3330, those meanings were scattered through individual RFCs and assigned-number records. The document assembled them into one view. It also separated IANA's standards-support assignments from ordinary space allocated to Regional Internet Registries. The result was more than a convenient table: it was an early operational type system layered over a flat numeric field.

The types were not interchangeable. A loopback destination should never leave the machine. A private source observed on an external interface should not be trusted as evidence of an internal origin. A documentation address belongs in prose and configuration examples, not as a reachable service dependency. Benchmark addresses belong in an isolated test method, not production forwarding.

RFC 3330's security section made the trust boundary explicit. The Internet does not inherently prevent abuse of special addresses. If an operator assumes every packet sourced from 10/8 came from inside, border devices must enforce that assumption. The address is a policy input, not an origin certificate. A packet capture containing private space proves what bits were observed, not where the packet was created.

“Special” was never one property

A single boolean loses the mechanism. An address may be valid as a source but not a destination, usable on a link but not forwardable, forwardable in a bounded domain but not globally reachable, or reserved so the protocol itself assigns meaning. A router, host, firewall, documentation checker and test harness therefore ask different questions about the same prefix.

RFC 3330 expressed those distinctions in prose. Its successors made them more formal. RFC 5735 replaced the 2002 snapshot and updated the catalog. RFC 6890 then created maintained IPv4 and IPv6 Special-Purpose Address Registries. Entries carry separate operational attributes, including source validity, destination validity, forwardability, global reachability and reservation by protocol.

RFC 8190 later clarified global reachability. It is an intended operational property, not a claim that no route will ever be advertised or no packet will ever leak. This matters in incident analysis. Seeing a supposedly non-global prefix in a public collector can show a leak, filter failure, spoofing or measurement artifact; it does not rewrite the registry property by observation alone.

Classification also needs longest-prefix logic. A broad block may contain a narrower assignment with different behavior. Checking only the first matching broad category can produce the wrong source or forwarding policy. The evidence receipt should name the exact longest matching entry and each attribute used by the decision.

The table changed because the network changed

RFC 3330 included blocks whose special status was ending or whose later treatment changed. That was not an error; it documented a moment. The danger begins when a 2002 snapshot is embedded permanently in software, security reports or compliance rules.

RFC 5737 later reserved three documentation prefixes rather than only the original TEST-NET block. RFC 3927 fully described IPv4 link-local behavior. RFC 6890 replaced prose snapshots with registries designed for maintenance. The live IANA IPv4 Special-Purpose Address Registry is therefore the operational source today, while RFC 3330 remains historical evidence of how the catalog formed.

Version matters in both directions. A modern registry cannot be projected backward to claim that an operator in 2002 was bound by a later property. An old RFC cannot be projected forward to classify a packet today. A defensible statement records the observation time, registry snapshot, exact prefix and decision fields.

The assignment process also separated technical requirements from general address policy. When an RFC needed a specialized IPv4 block for the standards process, it had to state technical needs such as size and prefix length. IANA would consult the RIRs and arrange the assignment near publication. RFC 3330 described that practice; it did not grant every experiment a permanent reservation or create new allocation rules by itself.

A registry entry did not enforce itself

The catalog could tell an implementer how a block was intended to behave. It could not make every host reject an invalid source, every border filter drop a leak, or every vendor refresh an embedded list. The distance between registry intent and observed behavior is an operational surface.

Private addresses may appear publicly because of spoofing or misconfiguration. Loopback values may appear in logs as local API conventions. Documentation addresses can escape from copied examples. Benchmark traffic can contaminate production telemetry. Each event requires the packet direction, interface, encapsulation, translation state and enforcement result—not only a lookup label.

This is why RFC 3330's lasting history is not the memorization of famous prefixes. It is the discovery that a globally shared identifier space needs exceptions with precise, maintained semantics. The address value, registry type, enforcement action and observed outcome are four different receipts. Collapse them, and a helpful catalog becomes a false claim about origin or reachability.

Sources