Catchment observability for anycast operators

Your users in São Paulo may be landing in Frankfurt. Nothing in your monitoring would tell you.

You announce the prefix. BGP decides who lands where. anycast.dev measures which networks reach which of your nodes, IPv4 and IPv6 side by side, from thousands of vantage points worldwide, and shows you what changed and why.

No agent, no access to your systems. Measured from the outside, delivered in 7 days.

catchment diff · sample output
$ anycast-dev catchment diff --run 2026-08-21 --against 2026-08-14 --af 4

prefix            country  origin    before   after    Δrtt
45.160.12.0/24    BR       AS28573   GRUFRA   +138 ms
177.72.240.0/24   BR       AS262589  GRUFRA   +141 ms
190.2.128.0/24    AR       AS7303    GRUFRA   +152 ms
200.27.64.0/24    CL       AS22047   GRUFRA   +167 ms
… 1,198 more

summary   1,204 /24s moved (3.1 % of catchment) · BR/AR/CL → FRA
trigger   AS-path change via upstream AS3356, first seen 03:14 UTC
v6        unaffected — v6 catchment for BR still GRU
playbook  prepend ×1 on FRA toward AS3356 · measured effect in 4/5 similar cases

Anycast operators fly blind

Catchment drift

An upstream changes path selection and a whole region quietly lands on the wrong node, 50 to 150 ms slower. No alert fires. You hear about it from a customer, or never.

Wasted PoPs

A site attracts almost no traffic because BGP never sends anyone there. Capacity planning is guesswork without a catchment map.

IPv6 is a second, invisible network

The v4 and v6 catchments of the same service can look completely different. Almost nobody measures v6 separately. We always do.

Free · self-service

Free catchment snapshot

0 € one zone · report in 5 to 10 minutes

Give us your zone. We look up its nameservers and query them for the SOA record with the NSID bit set from about 300 RIPE Atlas probes worldwide, IPv4 and IPv6, then hand you the HTML report. No signup, nothing to install, no access to your systems.

Three checks per visitor per day — every measurement spends RIPE Atlas credits. We store your address to reach you about the result. No newsletter.

Product 1 · available now

Anycast Health Check

2,500 € fixed price, excl. VAT · delivered in 7 days

  • Catchment map of your anycast service, IPv4 and IPv6: which countries and ASNs reach which node
  • Latency per region and per node, with the outliers named
  • Consistency checks across nodes: SOA serial, NSID, v6 and TCP reachability
  • Written report with prioritised BGP recommendations
  • One follow-up call to walk through the findings

Measured from thousands of RIPE Atlas vantage points across the world's networks. Nothing to install. We need NSID or per-node hostnames enabled on your nameservers, that is all.

Sign in with your e-mail, then check out with Stripe. Your reports and subscription live in one place.

Product 2 · launching

Continuous external monitoring

from 99 € per month

Your nameservers measured around the clock from vantage points worldwide: latency per region, availability, answer correctness, and SOA serial drift between your nodes, the symptom of a broken zone transfer that nobody notices until a customer does.

Sign in with your e-mail, then check out with Stripe. Your reports and subscription live in one place.

Not sure yet? Run the free snapshot above and see your catchment first.

Lab notes

We run our own anycast network to measure, break and fix. The write-ups, with method and data:

All notes: anycast.dev/notes · RSS

How we measure

From the outside: thousands of vantage points

We query your anycast address from RIPE Atlas probes across thousands of networks and record which node answers (NSID / hostname.bind), how fast, over v4 and v6. The result is a catchment map without touching your infrastructure. This is the method behind the Health Check and the monitoring service.

From the inside: the open-source agent

For continuous, prefix-level catchment maps we are building a small open-source agent that runs on your nodes (Verfploeter method, proven at B-Root and .nl). It aggregates dnstap metadata per minute and collects probe replies. Query names and full client addresses never leave your server. The code is public at github.com/portalix/anycast-agent, so you can read what leaves your network before you run it.

Correlated with public BGP data

Every shift is matched against RIPE RIS and RouteViews: which AS path changed, through which upstream, at what time. You get the cause in plain language, not a graph to interpret.

Recommendations with measured effect

Prepends and communities are tested on our own lab network and their catchment effect is measured. Recommendations come with an observed success rate, not a guess.

Measured by a network you can look up

anycast.dev is run on our own anycast infrastructure: a production network carrying our domains, and a measurement lab with its own ASN — AS218833 (ANYCAST-LAB) — announcing 94.249.165.0/24 and 2a03:5840:161::/48 from Frankfurt and New Jersey, over two different upstreams. Those prefixes serve the authoritative DNS for our own domains, dual-stack, and the same pipeline we sell measures that catchment every day. We find our own mistakes first.

Active measurements follow strict rate limits and a public opt-out. Method, probe addresses, abuse contact and opt-out live at anycast.org, the non-commercial side of this project.

Talk to a person

Questions, a network you want measured, or a partnership idea: hello@anycast.dev. Replies come from the engineer who does the measuring.