routing · severity info
RPKI ROA depth
Distribution of how many RPKI ROAs route-announcing networks publish, from none to many.
Measured every Sunday · last updated
How it is measured
bulk feeds only — no network is probed. The ROA count already carried on each ASN's census row from the RPKI validated payload, banded: none / single / few (2–9) / many (10+). Population unit: ASN; segmented by country and RIR.
Why it matters
rpki-roa-coverage answers yes or no, and the yes hides a range. A network with one ROA has done the hard part — the RIR portal, the key ceremony — and is recorded as covered, while any prefix that ROA does not cover still validates as not-found, exactly as if nothing had been published. The shape of the distribution is where the adoption story actually is.
Limits of this measurement
A ROA count is not prefix coverage, and this metric must not be read as one. Proving a network's announcements are covered needs the full RIS prefix table joined to the VRP set; that is a different measurement and is not made here. A single ROA covering a network's only prefix is complete coverage; a single ROA at a network announcing fifty is not — from the VRP dump alone the two are indistinguishable.
The base rate
Measured over the full population of networks, from public bulk sources.
Every segment
Pick one to see the citable answer, with its trend and methodology.
Show the remaining 74 segments
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.