Anycast measurement lab

This is the non-commercial side of a small project that measures anycast catchments: which networks reach which node of an anycast service, over IPv4 and IPv6. The lab runs its own ASN and prefixes and announces them from a handful of locations. Today those prefixes carry only our own authoritative DNS; once measurement starts, they will also send low-rate probe packets to the Internet. This page documents exactly what that traffic will be, how to recognise it, and how to make it stop for your networks — the opt-out works before the first packet.

If you got here from a firewall log or a reverse-DNS lookup: here is how to confirm it was us, and here is the opt-out. No reason required, no questions asked.

Operated by Portalix UG (haftungsbeschränkt), München, Germany. The same team sells measurement services at anycast.dev; this lab is where the method is developed and published. The two are kept apart on purpose: the lab's prefixes carry no commercial service and no customer traffic.

Current status

Active probingnot started No measurement packets have been sent from lab prefixes yet. The prefixes below currently carry only authoritative DNS for our own domains.
ASNAS218833 (ANYCAST-LAB), assigned by RIPE NCC on 2026-08-28 via sponsoring LIR Via-Registry / Virtua Systems. Organisation: Portalix UG, abuse contact abuse@anycast.org.
IPv4 prefix94.249.165.0/24, announced since 2026-08-29. Leased from GHOSTnet GmbH (AS12586); RPKI ROA and IRR route object registered for AS218833. Carries 94.249.165.53 (authoritative DNS for our own domains) and 94.249.165.1.
IPv6 prefix2a03:5840:161::/48, announced since 2026-08-28. RPKI ROA and route6 object registered for AS218833. Carries 2a03:5840:161::53 (authoritative DNS) and 2a03:5840:161::1.
What the prefixes carryAuthoritative DNS for domains we own ourselves, dual-stack. No customer traffic, no probing yet. When active probing starts, the source addresses will be listed here before the first packet leaves.
Locationslive: Frankfurt (Virtua Systems / AS35661 upstream), New Jersey (Vultr / AS20473 upstream), both announcing both prefixes. Further locations are added as documented experiments.
External measurementsWe also run DNS measurements through RIPE Atlas. Those packets come from Atlas probes, not from our prefixes, and are governed by RIPE Atlas' own rules.
Last updated2026-08-29

What our probes do

We use the Verfploeter method (de Vries et al., IMC 2017; used in production at B-Root and for .nl): one lab node sends ICMP echo requests with the anycast address as the source; every lab node records which replies arrive there. The node that receives your reply is the node BGP routes you to. That is the whole measurement.

For the commercial Health Check we do not probe customer networks from here at all; those measurements are DNS queries from RIPE Atlas to the customer's own nameservers, ordered by that customer.

How to confirm it was us

  1. The source address is inside one of the prefixes listed under Status.
  2. dig -x <source address> returns a name ending in .anycast.org, for example probe-fra1.anycast.org. (Reverse DNS for the probe addresses is set before the first run; until then no probe traffic exists to check.)
  3. The RIPE database (whois <source address>) shows the lab ASN ANYCAST-LAB, organisation Portalix UG, and abuse@anycast.org as abuse contact.
  4. The ICMP payload contains the string anycast.org measurement - opt-out: https://anycast.org/#opt-out.

If a packet claims to be from us and fails these checks, it was not us. Please tell us at abuse@anycast.org; spoofed measurement traffic is something we want to know about.

Opt out

Send the prefixes or AS numbers you want excluded to optout@anycast.org, or use the form. We add them to the exclusion list within two business days, confirm by e-mail, and never probe them again. The list applies to every future run and to every lab node. No justification needed.

We keep the exclusion list private (it is a list of networks that asked not to be contacted). We verify that the requester is plausibly responsible for the prefix (RIPE/ARIN/APNIC contact, or mail from the network's domain) only to prevent someone from excluding networks they do not operate; we do not challenge the request itself.

What we store and publish

Why we do this

Anycast is how most of the Internet's DNS (and a good part of its CDNs) is delivered, and operators mostly cannot see where their traffic actually lands. The measurement method is published and well understood, but it has never been available to small operators. The lab exists to build that tooling in the open: the measurement agent is open source at github.com/portalix/anycast-agent, the method and results are published, and BGP traffic-engineering experiments on the lab's own prefixes are documented so others can learn from them.

References

Contact

Abuseabuse@anycast.org (also the abuse-c in the RIPE database)
Opt-outoptout@anycast.org
Network operationsnoc@anycast.org
PeeringPeeringDB: AS218833 — open peering policy, no exchange presence yet