Lab notes · 2026-09-11

How Germany delegates: 139 zones, 77 % outsourced, 60 % in one country

Before a resolver sends a single query to a zone, it already knows a lot about it: which nameservers the parent lists, where their addresses live, whether a DS record says the answers will be signed. We read exactly that, and nothing more, for 139 zones that matter in Germany: the DAX-40 companies (their main .de and .com), 27 federal government zones, the 16 states with 17 portal zones, 14 public broadcasters, and 21 zones from banks, insurers, telcos and grid operators.

Plain DNS queries from one server in Germany: NS from the parent and from the zone itself, A and AAAA of every nameserver, origin AS and registration country of every address, NSID and hostname.bind, SOA serial per address, DS in the parent, DNSKEY at the apex. No RIPE Atlas, no catchment, no load. 2 minutes 42 seconds for all of it. This note is about what is there, not about who is doing it wrong; we do not name zones.

Who runs the nameservers

107 of the 139 zones (77 %) have every nameserver at an outside provider. 17 (12 %) mix their own servers with a provider. 15 (11 %) run everything themselves. The federal government is the clearest case: 0 of 27 zones self-operated, 25 fully outsourced, 11 of those 25 to ITZBund, DFN or Deutsche Telekom, which is a government IT provider and a research network rather than a random cloud, but still somebody else's nameservers.

Stacked bars per group showing how many zones are self-operated, hybrid or outsourced
Self-operated, hybrid and outsourced zones per group. Federal government: nothing self-operated. DAX-40: 9 of 60.

The provider side is concentrated but not a monopoly. 27 zones have at least one nameserver they run themselves. CSC serves 14 zones, Akamai, DFN, Deutsche Telekom and UltraDNS 10 each, AWS Route 53 9, Cloudflare 7, ITZBund and NS1 6 each. Behind that, a long tail of more than forty providers with one to three zones: regional ISPs, state data centres, hosting companies, a university.

Horizontal bars of every provider serving at least three of the 139 zones, in descending order
Providers with at least three zones. A zone with servers at two providers counts for both.

One country, one network

84 zones (60 %) have every nameserver address registered in one country. 70 (50 %) have every address in a single autonomous system. Take both with a grain of salt: the country is where the prefix is registered, and an anycast provider registers in one place and answers from forty. So we also looked for anycast hints, a provider known to run anycast or a site marker in the server identity. 78 zones (56 %) have at least one. That leaves 52 zones (37 %) with all addresses in one country and no sign of anycast anywhere: their DNS, as far as we can tell from here, stands in one country, mostly in one network.

Grouped bars per group showing the share of zones with a DS record, all addresses in one country, all addresses in one AS and all nameservers with IPv6
Per group: share of zones with DS record, all addresses in one country, all addresses in one AS, all nameservers with IPv6.

That is not automatically wrong. A state portal whose users all sit in that state loses little if a resolver in Jakarta waits 250 ms for the first lookup. A DAX company with customers on four continents pays that on every uncached query, and if the one network has a bad day, all nameservers have it together. The point is that it should be a decision, and from the outside it mostly looks like a default. State portals: 14 of 17 in one country. Banks, insurers and grid operators: 15 of 21. Federal: 18 of 27. DAX-40: 30 of 60. Public broadcasters: 7 of 14.

DNSSEC: a quarter

34 zones (24.5 %) have a DS record in the parent; 35 carry a DNSKEY at the apex, so one zone is signed but not linked. Federal government 8 of 27, states 7 of 17, DAX-40 13 of 60, banks and grid operators 6 of 21. Public broadcasters: 0 of 14.

IPv6

86 zones (62 %) have an AAAA record for every nameserver. 14 (10 %) have none at all; the rest are mixed. Mixed is fine for reachability. None is a statement, in 2026, for zones that otherwise carry IPv6 on their websites.

Small things that were not supposed to be there

Six zones (4 %) list a different set of nameservers in the parent than in the zone itself. That is usually a leftover from a provider change and harmless until the old provider drops the zone. Three zones answered with different SOA serials from different addresses at the moment we asked; a zone transfer in flight looks exactly like that, and we asked once, so we count it as a note, not a finding. Zones have between 2 and 10 nameservers, median 4.

Method, so you can check it

Everything here comes from queries anyone can repeat with dig: NS at the parent and at the apex, A/AAAA for each nameserver name, origin AS and country from Team Cymru's DNS lookup, NSID and CH TXT hostname.bind/id.server plus SOA directly at each address (UDP, 3 s timeout, one retry), DS at the parent, DNSKEY at the apex. "Self-operated" means the AS name carries the zone's own name, or the nameserver sits under the zone's own domain and not in a known DNS provider's network; a vanity name like ns1.example.de pointing into a provider's AS counts as outsourced. Anycast cannot be measured from one vantage point; "anycast hint" means the provider is known to run anycast or the server identity carries a site marker. Multiple addresses are not evidence of anycast. Country is the registration country of the prefix. Serial drift is a snapshot.

We do not publish per-zone results. Where a zone's setup looks like a problem rather than a choice, the operator hears it from us first (see anycast.org for the disclosure rules).

What comes next

The delegation tells you where the nameservers are. It does not tell you what that costs a resolver in São Paulo or Singapore. That is the next note: the same 139 zones measured from 1,000 RIPE Atlas probes, weighted by population, one probe set for v4 and v6.