Lab notes · 2026-09-13

What the delegation costs: 139 German zones, 146 ms in one country, 21 ms on anycast

How Germany delegates read the delegation of 139 zones that matter in Germany from one vantage point and found that 52 of them (37 %) have every nameserver address in one country with no sign of anycast. It could not say what that costs. This note can: the same 139 zones, one SOA query with NSID per nameserver address, from the same 1,000 RIPE Atlas probes for every address and both families, the probes drawn per country in proportion to population. 548 addresses, roughly 530,000 answers, a resolver's view from where the people are.

One rule for reading the numbers: a resolver does not ask a random nameserver, it learns which one answers fastest and keeps asking that one. So for every zone and every probe we take the best round trip over all the zone's addresses, IPv4 and IPv6 together. That is the lookup time a well-behaved resolver at that probe actually pays. A probe that gets no usable answer from any address is a failure, not a slow answer. As in the first note, we do not name zones.

Same zones, now measured

The delegation classes from the first note translate into three bands. The 52 zones with everything in one country and no anycast hint have a worldwide median of 146 ms. The 76 zones with an anycast hint, a provider known to run anycast or a site marker in the server identity, sit at 21 ms. The 11 zones in between, addresses in more than one country but no anycast hint, are a mix: four of them are clearly anycast that does not announce itself and answer in 20 to 27 ms, four stand in one region after all and answer in 140 to 145 ms.

Dot plot of the 139 zones by worldwide median lookup time, in three rows: one country without anycast hint, anycast hint, other
Every zone as one dot, worldwide median from 1,000 probes. The one-country zones form a block between 140 and 157 ms; the anycast zones sit between 6 and 40 ms with a tail to 93.

The block on the right is not a long tail, it is a wall. 47 of the 52 one-country zones have a worldwide median above 100 ms, and their medians are within 17 ms of each other, because they are all measuring the same thing: the distance from the rest of the world to Frankfurt.

One country, measured

In Europe the two classes sit at 27 ms and 12 ms, which is the difference between "somewhere in Germany" and "in your city". Everywhere else the difference is the ocean. Asia: 184 ms against 26. South America: 196 against 25. North America: 123 against 13. Africa: 152 against 54. Oceania, with eight probes and one ocean more: 295 against 14. The Middle East is the one region where the anycast zones do not win big, 68 against 50, because few providers have sites there, and from there Frankfurt is not much farther than the nearest anycast site.

Grouped bar chart of median lookup time per continent for the three delegation classes
Median lookup time per continent and class. Middle East is the only region where one country is not a step change.

Another way to say the same thing: for a one-country zone, 18 % of all probes wait more than 200 ms for a lookup, and the 90th percentile of a typical zone is 223 ms. For an anycast zone, 0.8 % of probes wait more than 200 ms and the 90th percentile is 69 ms. A resolver in São Paulo pays 170 ms extra every time the record expires from its cache. Whether that matters depends on who the users are. For a state portal it probably does not. For the eight DAX-40 zones in this class it does, on every uncached query from every customer abroad.

The server identities tell the same story from the other side. Among the zones whose nameservers publish an NSID at all, the one-country zones show a median of 2 distinguishable locations. The anycast zones show 60.

By group

The DAX-40 zones are fast: median 22 ms, 5 of 60 above 100 ms. The federal government is not: median 143 ms, 17 of 27 above 100. The state portals are the slowest group, 145 ms, 14 of 17 above 100, which follows from the first note, where 14 of 17 stood in one country. Public broadcasters are split down the middle, 78 ms, 6 of 14. Banks, insurers, telcos and grid operators are split too, 91 ms, 9 of 21, with a wide spread from 10 to 154 ms.

Two panels: median of the zone medians per group, and share of zones slower than 100 ms per group
Median of the zone medians per group, and how many zones in each group are slower than 100 ms worldwide.

The groups sort by class, not by budget. Federal zones are outsourced almost without exception, but 18 of 27 went to providers that run their nameservers in one country. The DAX zones are 48 of 60 on anycast. Nothing in the numbers says a state portal needs to be fast in Jakarta. They say that the choice has a price, and what the price is.

Providers

For the ten providers that serve at least five of the 139 zones, the median over their zones, worldwide and from Asia. Two clusters, and one line that straddles them.

ProviderZonesMedian worldwideMedian AsiaZones over 100 ms
Cloudflare76.5 ms5.7 ms0
AWS Route 53710.6 ms8.6 ms0
Akamai1016.2 ms24.5 ms0
NS1621.6 ms26.6 ms0
UltraDNS1023.2 ms32.5 ms0
CSC1425.0 ms37.3 ms0
self-operated28112.7 ms132.6 ms14
Deutsche Telekom10145.3 ms181.9 ms9
ITZBund6149.8 ms185.6 ms6
DFN10150.2 ms186.6 ms10

A zone with servers at two providers counts for both, which is why the self-operated line has 14 zones under 100 ms: they run their own servers next to an anycast provider, and the resolver picks the provider. The three providers at the bottom are a government IT provider, a research network and a telco, all with a real reason to keep the servers at home. The cost of that reason, from Asia, is 160 ms per lookup.

Failures and IPv6

About 4 % of the probes get no answer from any address on IPv4 and 3.4 % on IPv6, for every zone alike; that is probes that are offline, firewalled or without a route, so it is the fleet, not the zones. Only what a zone loses on top of that is its own. On IPv4, not a single zone does. On IPv6, nine zones lose more than 2 percentage points over the baseline, the worst one 16.8 % of all probes. 14 zones have no IPv6 nameserver at all, as in the first note. For 3 zones the IPv6 median is more than 30 ms above IPv4, which usually means the v6 addresses live somewhere else than the v4 ones.

Two things we only count. 25 zones answered with more than one SOA serial across their addresses inside the measurement window; a zone updated during those minutes looks exactly like a transfer that is lagging, and one snapshot cannot tell them apart. And 5,124 answers in 107 zones did not come from the nameserver at all but from a resolver in the probe's network that intercepts port 53; 40 distinct resolver identities, removed before every number above. DNSSEC made no difference to the round trip, as expected, so it is not in this note.

Method, so you can check it

Inventory as in the first note, then one DNS SOA query with the NSID bit per nameserver address, UDP, no retry, from the same 1,000 RIPE Atlas probes for every one of the 548 addresses (325 IPv4, 223 IPv6). Measurements 210626544 to 210836961, public; 450 of them ran on 11 September, the remaining 98 the next day after we hit the Atlas daily limit, so the note spans two days. The probe set is drawn per country in proportion to population, only from probes whose IPv4 and IPv6 both work, capped by how many such probes a country has: 114 countries covering 90 % of the world's population, with India (66 probes), China (26) and Nigeria (5) under-represented because Atlas has few probes there. Per continent: Europe 243, Asia 298, North America 155, South America 153, Africa 52, Middle East 50, Oceania 8. Per zone and probe we take the smallest round trip over all addresses that returned NOERROR with a serial; REFUSED, SERVFAIL and timeouts do not count. "Median" for a class or group is the median of the zone medians, one vote per zone. "Locations" is the number of distinct NSID values with machine and process suffixes folded; opaque binary identities are ignored. Intercepted answers are recognised per address as in our snapshot reports: on an address that one server identity answers almost entirely, a different identity seen from five probes or fewer never reached that server; on an address with no identity at all, the few answers that carry one came from somebody else's resolver. Continents are our own grouping, the same as in the other notes: the Middle East counted separately from Asia, Russia with Europe. Everything is a snapshot; the numbers move by a few milliseconds from one day to the next and by nothing that changes the picture.

We do not publish per-zone results. Where a zone's numbers look like a fault rather than a choice, the operator hears it from us first (see anycast.org for the disclosure rules). A SOA query is what every resolver on earth sends these servers all day; half a million from us over two days are noise.

What comes next

The lever behind these numbers is BGP, and we have our own network to pull it on. A follow-up note takes one prefix on AS218833 and prepends its way through a set of upstreams, with the same probes watching where the traffic lands after each step.