Lab notes · 2026-09-19

Who changed their ccTLD nameservers this year: 78 of 309, ten operator swaps, read from the root zone

The root zone is the only public record of who serves a country-code top-level domain. Every ccTLD is a handful of NS records and their glue addresses in that one file, and every time a registry adds, drops or moves a nameserver, the file changes and gets a new serial. We took an archive that keeps one copy per serial, 947 copies from 1 September 2025 to 16 September 2026, and diffed them, TLD by TLD, for all 309 ccTLDs including the 61 internationalised ones. No queries, no probes, no traffic: what follows is what the root zone itself says.

125 changes to the nameserver names or addresses of 78 ccTLDs, run by 56 registries in 55 countries and territories. 231 ccTLDs (75 %) did not change a name or an address in the whole year, 196 (63 %) did not change anything at all, not even a DS record. Key rollovers, which show up as DS changes without any change to the nameservers, we counted separately and left out: 86 of them at 54 ccTLDs.

The year, month by month

The quiet months have two to eight changes; February 2026 has 16 and July 2026 has 21. August and September 2026 look like the busiest months of the year, 20 and 21 changes, but 30 of those 41 are one registry: .in and its 15 internationalised ccTLDs moved from Tucows' generic trs-dns nameserver names to four names under registry.in, on exactly the same addresses, in two steps (new names on 27 August, old names dropped on 1 September). Without that one decision the two months have 5 and 6 changes. The same registry did the same for .in itself on 24 and 29 June.

Bar chart of ccTLD delegation changes per month from September 2025 to September 2026, with the .in family shown as a separate segment and DS-only changes as a line
Delegation changes per month, the .in family shown separately; DS-only changes as a line for comparison.

That is the first thing the year teaches: a change in the root is not always a change of operator. Of the 104 events that touched a nameserver name, 24 were renames only, a new name on the old addresses; of the 147 nameserver names that were added over the year, 79 were such renames, a new name on the address set of a name removed within two weeks. The .in family accounts for 64 of the 79, Jordan (.jo and its Arabic ccTLD) for 8, Vanuatu for 3, the Republic of the Congo for 2, Luxembourg and Bosnia for 1 each. We count a rename as a change of the record, not as a change of operator, and the operator numbers below exclude them.

Who appeared, who disappeared

We labelled every nameserver address with its operator (hostname, address range and origin AS, checked against NSID for 41 addresses, see the method) and asked, per ccTLD, which operators were in the delegation before and after each change. 21 ccTLDs gained an operator they did not have before, 15 lost one, 25 did one or the other.

Diverging bar chart per operator: number of ccTLDs in which the operator appeared during the year to the right, number from which it disappeared to the left
Per operator, the ccTLDs in which it appeared (right) and from which it disappeared (left). A rename on the same addresses does not count.

PCH appeared in 11 ccTLDs and disappeared from one. Seven of the eleven are registries adding one PCH anycast name next to what they had: Hungary (p.hu, 12 September 2025), the Democratic Republic of the Congo (pch.nic.cd, 12 December 2025), El Salvador (p.ns.sv, 22 January 2026), the Republic of the Congo (p.nic.cg, 1 May 2026), Nicaragua (ns5.ni, 2 July 2026), Indonesia (f.dns.id, 5 August 2026) and Senegal (ns-pch.nic.sn, 14 August 2026). The eighth is the Cayman Islands, where the second pair of Tucows' trs-dns names was swapped for a pair that answers from PCH's network (22 December 2025). The other three, Bahrain (.bh and its Arabic ccTLD) and Palau (.pw), moved from CentralNic to Tucows' TLD DNS service, and that service is two names run by Tucows (AS393818, NSID fra01.dns1) plus two names that answer from PCH (AS42, NSID 1.fra.pch), so PCH and Tucows appear together. The one ccTLD PCH left is American Samoa (.as), on 29 November 2025, the same day on which the fifth .as nameserver moved from Netnod's addresses to NS-Global's.

RcodeZero, the anycast service of the Austrian registry, appeared in five ccTLDs and left none: Bosnia and Herzegovina (lim.utic.net.ba, 1 October 2025), Lithuania (r.tld.lt, 28 April 2026), Luxembourg (r.ns.lu, 18 June 2026), and Greece with both .gr and .ελ (gr-a.ics.forth.gr, 7 and 9 July 2026). All four addresses answer with the same NSID, tld-all-fam1, from AS1921. In three of those five, Lithuania and the two Greek zones, the name that was removed at the same time was a CommunityDNS name: c.tld.lt three days after r.tld.lt arrived, gr-c.ics.forth.gr on the same day as gr-a. CommunityDNS appeared nowhere in the year. We do not know why; the root zone records the swap, not the reason.

CentralNic (Team Internet) went both ways: it took over Colombia, where .co went from eight names (six UltraDNS names and two in Neustar security networks) to four registrydns.co names between 24 and 30 September 2025, and it disappeared from Bahrain and Palau as described above. Cloudflare disappeared from Barbados on 22 May 2026, where the four nic.bb names now point into a network we could not attribute (AS16686, hostname.bind says fra2). UltraDNS lost Colombia and restructured Vanuatu (four names to six, 5 September 2025). RIPE NCC's secondary service was removed from Syria and its Arabic ccTLD on 23 July 2026, leaving .sy with two nameservers. The Faroe Islands added two Netnod names to a delegation that had only CentralNic (12 February 2026), Namibia added a CZ.NIC name (31 July 2026), and the Democratic Republic of the Congo replaced three names in domestic and Contabo networks with two Gransy anycast names and one PCH name on a single day, all of them still without an IPv6 address.

Registries' own names are the largest category of movement that is not a provider: 21 names added, 16 removed, 8 renamed. Iceland rotated one server (f.nic.is in, b.nic.is out, February 2026). Slovakia dropped a, b and c.tld.sk on 16 March 2026, going from seven names to four, all of them now CentralNic. Malaysia dropped two old names and added e.nic.my (an Oracle Cloud instance in Singapore, NSID OCI E) and g.nic.my (an EC2 instance, hostname.bind ip-10-111-21-180), which are the registry's own servers in the sense that no DNS provider runs them. The Maldives replaced its three old names with four new ones between December 2025 and August 2026, among them its first nameservers with IPv6 (December) and one on a DigitalOcean machine (February). Russia's registry operator added c.tld-servers.ru to .ru, .рф and .su in July 2026. Finland added a tenth nameserver, f.fi, on 15 September 2025 (NSID f.fi1, in CGI's network), one of three ccTLDs among the 78 with ten names, next to .sa and .se.

Ten swaps within two weeks

ccTLDRegistry (IANA)OutInDates
.coMinTIC, ColombiaUltraDNS, two Neustar security networksCentralNic24 and 30 Sep 2025
.asAS Domain RegistryPCH, NetnodNS-Global29 Nov 2025
.cdOCPT, DR Congodomestic networks, ContaboGransy, PCH12 Dec 2025
.pwMIDC, PalauCentralNicTucows and PCH9 and 20 Feb 2026
.niUNI, NicaraguaUUNET, a domestic networka name on AWS (not attributed)23 Mar 2026
.ltKaunas University of TechnologyCommunityDNSRcodeZero28 Apr and 1 May 2026
.grICS-FORTHCommunityDNSRcodeZero7 Jul 2026
.ελICS-FORTHCommunityDNSRcodeZero, FORTH's own anycast7 and 9 Jul 2026
.bhTRA, BahrainCentralNicTucows and PCH14 and 22 Jul 2026
بحرين.TRA, BahrainCentralNicTucows and PCH15 and 22 Jul 2026

Ten ccTLDs, eight registries. In every case the new operator was in the root before the old one left, between zero and eleven days; none of the ten cut over in one step.

Addresses that moved, names that stayed

21 of the 125 changes did not touch a name, only an address. Nine of those are one operator renumbering: RIPE NCC moved the IPv6 side of its ccTLD secondary service from 2001:67c:e0::/48 to 2a13:27c0:30::/48, one ccTLD at a time between September 2025 and September 2026, visible in Guam, Guadeloupe, Uganda, Algeria, Eritrea, Syria, Palestine and their Arabic ccTLDs, nine zones in all. Sweden renumbered two of its ten names in February 2026, within the registry's own networks. Six nameservers kept their name and moved to a different network: one in Madagascar, one in Uzbekistan, two in the Turks and Caicos Islands (to IONOS) and the two registry.hm names of Heard Island (AS35916 to AS45671, 7 July 2026), the only change of the year whose ccTLD's IANA record still carries a date from before the period. The rest are single addresses appearing or vanishing: Kenya lost an IPv4 address on one name, Uzbekistan added addresses to one, Nigeria gained IPv6 on one, Albania's Australian secondary lost and regained its IPv6 glue within a week, and Saudi Arabia (.sa and its Arabic ccTLD) and Uganda lost the IPv6 address of one nameserver.

Over the 78 changed ccTLDs the nameserver count went from 391 to 403: 23 ccTLDs ended the year with more names, 8 with fewer, 47 with the same number. The IPv6-capable names went from 305 to 325; 26 ccTLDs have more of them than a year ago, 9 fewer. Three ccTLDs among the 78 end the year without a single IPv6 nameserver: the Democratic Republic of the Congo, Heard Island and Pakistan's Urdu ccTLD.

Where the changes were

RegionccTLDsChangedShareOf which one registry
Europe671725 %
Asia953436 %16 in the .in family; 18 (19 %) without it
Oceania27622 %
Americas531019 %
Africa651117 %
other (.aq, .tf)20

Regions follow the UN geoscheme, internationalised ccTLDs count with their country. Europe's 17 are Albania, Bosnia, Bouvet Island, Finland, the Faroe Islands, Greece (.gr and .ελ), Hungary, Iceland, Lithuania, Luxembourg, Moldova, Russia (.ru and .рф), Slovakia, Sweden and .su.

The IANA date is not the change

Each ccTLD's page in the IANA root database carries a "Record last updated" date, and it is tempting to read it as the date of the last delegation change. It is not. 164 of the 309 ccTLDs have an IANA date inside our window; 87 of them (53 %) had no change to a nameserver name or address in the root zone in that time. 35 of the 87 had a DS change, which IANA also records; 52 had nothing in the root at all, so the update was contacts, addresses or URLs. The other way round works better but not perfectly: of the 78 ccTLDs that did change a nameserver, 56 have an IANA date within seven days of one of their changes, 22 do not. Greece's IANA record is dated 2 September 2026; the .gr swap happened on 7 July. Hungary's is dated 4 August 2026; the new PCH name arrived on 12 September 2025. Heard Island changed networks with no IANA update at all. If you want to know when a ccTLD's nameservers changed, read the root zone.

What this means for a registry

A change of delegation is the one moment in a ccTLD's year when the answer to "where do queries from home actually land" changes, and it is also the moment when nobody outside the registry checks. The new operator's anycast is announced, the root serial ticks, and from then on resolvers in the country go wherever BGP takes them. In Who checks the anycast vendors of Europe's ccTLDs we measured that for 26 ccTLDs and .eu at rest: the commercial anycast operators answer within about 10 ms of home, the registry-to-registry secondaries from 12 to 41 ms away, and the registry usually finds out from us. The 78 changes above are 78 moments where that measurement would have been worth having before and after, and for the ten swaps it would have shown whether the new vendor reaches the country as well as the old one did. The diff behind this note works on any two copies of the root zone. Run daily, it produces the before-and-after list for a ccTLD change, with operator labels, the morning after the change lands in the root.

Method, so you can check it

Source: the root zone as published by IANA, one file per SOA serial, two to three serials per day. We used a public git archive that stores one commit per serial (github.com/kidmin/rza, RRSIG records stripped, NS, glue and DS complete), 947 commits from serial 2025090102 to 2026091601, and checked its 16 September 2026 state against the zone we fetched ourselves from InterNIC and by AXFR from ICANN's xfr.lax.dns.icann.org the same evening; identical. For each ccTLD and each serial we extracted the NS names, the A and AAAA glue of every name (the root carries glue for every TLD nameserver, including those outside the TLD) and the DS set, and diffed consecutive serials. A "delegation change" is any change to the set of NS names or to the set of addresses; a DS change alone is a key rollover and counted separately. ccTLD means the two-letter TLDs plus the internationalised country-code TLDs, 309 in the window.

Operator labels: our provider mapper (nameserver hostname suffixes, verified host routes, address prefixes, origin AS from Team Cymru), reduced to one name per operator. Where the mapper had no provider, the label is "registry's own name" if the nameserver sits under the ccTLD itself, and "other network" otherwise. On 16 September 2026 we checked 41 of the addresses that carry weight in this note by hand with dig +nsid, hostname.bind, id.server and the origin AS, and 47 addresses in the script carry that verified label instead of the mapper's; the one correction that changed a number was Tucows' trs-dns service, where the ns10 pair answers from PCH's network and the mapper had booked all four names as Tucows. Labels are as of today, not as of the change; an address that changed hands inside the year would be mislabelled for the earlier part, and we found no such case. A rename is an added name whose address set equals a removed name's, in the same ccTLD, within 14 days; a swap is an operator disappearing and another appearing in the same ccTLD within 14 days. Regions follow the UN geoscheme.

Limits: the archive is unofficial (we verified only its last state against the live zone, not all 947). Glue tells you the address, not who runs the server; three names in this note we could not attribute and say so. "Operator appeared" is a statement about the root zone, not about traffic: whether the new nameserver answers, and from where, is a measurement, not a record. We did not measure any of the 78 here.

This note reads the public root zone and names no measurement results. Where a delegation looks like a problem rather than a choice, the operator hears it from us first (see anycast.org for the disclosure rules).

What comes next

None of the 78 changes was measured before and after: the record exists, the measurement does not. The next step is to run the diff daily and pair it with the home measurement, so that a ccTLD whose delegation changes is measured from inside its country with the method of Who checks the anycast vendors of Europe's ccTLDs, before the old operator leaves if the overlap allows, and after. In the ten swaps above that overlap was between zero and eleven days. The snapshot of all TLD delegations at one point in time is in How the TLDs delegate.