Every change to the Africa IPv6 & DNSSEC Deployment Monitor since the dashboard
was first built, newest first.
2.15.0NewFix
Checking the Harder Questions
The ccTLD tab added last time asked whether a country's registry
servers answer simple questions over IPv6. This update asks two harder ones: do they
answer questions correctly under real conditions, and does the internet's official record
of who runs the domain actually match what the registry is running?
What's new
Two new checks on the ccTLD tab: does it handle EDNS(0) (a DNS
extension nearly every modern lookup depends on), and can it deliver a large,
signed answer over IPv6 without the answer getting lost.
This matters because a signed domain's answers are much bigger than a simple lookup.
They often don't fit in a single small internet packet, and the server has to say "here's
more, ask me again a different way." That second step is where DNS over IPv6 most often
breaks, and the simple checks from last time couldn't see it at all.
Across Africa, 185 of 186 registry servers with IPv6 handle the extension correctly.
Among the servers whose country domain is properly signed, all but a handful correctly
deliver a full, large answer.
Two registries, Tunisia and Uganda, were found to have servers that sometimes fail
this specific check over IPv6 even though they work fine over the older IPv4 internet.
It isn't constant, sometimes it works and sometimes it doesn't, which is itself useful to
know: it points at an unreliable connection rather than something switched off.
A second new check compares the internet's official record of who runs each country's
domain against what the registry's own servers say. These can quietly drift apart when a
registry adds or retires a server.
Four country domains were found where the official record is out of date: it still
lists servers a registry has retired, or hasn't caught up with new servers a registry has
brought online. Two more countries were found where the official record and the registry
agree on which servers exist, but disagree about one server's actual address.
Good to know
Not every server could be checked for the address-matching question. Where a check
couldn't be done, the tab says so plainly rather than guessing or assuming it passed.
The large-answer check only runs on country domains that are properly signed, since
that's the only place a large answer actually gets sent. Everywhere else it's marked "not
tested", not "failed".
2.14.0NewFix
Measuring the Country's Own Domain
Until now the dashboard measured individual government and
university domains. It now also measures the country's top level domain itself, the one
the national registry runs, such as .ng or .za.
What's new
A new ccTLD tab on every country page.
It asks three things of each of the registry's nameservers. Does it have an IPv6
address? Does it answer over IPv6? And can it actually answer DNS questions over IPv6?
It also shows whether the country's domain is signed with DNSSEC.
Click any nameserver to see each of its addresses and what each one did.
This matters because the country's domain sits above every domain in the country.
If the registry's servers cannot be reached over IPv6, nothing underneath them can be
either, no matter how well an individual domain is set up.
Across Africa, 186 of 270 registry nameservers have IPv6 and 184 answer questions
over it. 35 of 60 country domains are signed with DNSSEC. Four have no IPv6 anywhere.
Six countries also have an Arabic-script version of their domain alongside the
Latin one, and both are measured. Algeria, Egypt, Morocco, Mauritania, Sudan and Tunisia.
Fixed
Equatorial Guinea has a page for the first time. It was the one country of 54 with
no page, because no domains had been added for it. It has registry data like everyone
else, and .gq turns out to be one of the better configured ones: all four of its
nameservers work over IPv6.
Good to know
These checks run from one place, in Africa. A nameserver that answers here is not
proven to answer from everywhere in the world.
The tab treats "answers DNS questions" as the trustworthy result and "responds to a
ping" as a softer hint, because some networks block pings on servers that answer
questions perfectly well.
2.13.0New
This Page
A release history you are reading right now, written for people
who use the dashboard rather than people who build it.
What's new
Every release from 2.0.0 onward, newest first, at /changelog.
Linked from "What's new" in the home page footer.
Awkward facts are kept rather than dropped. Where a number moved because the
measurement got stricter rather than because anything got worse, it says so.
2.12.0Security
Request Monitoring, and a Tighter Site
Operators can now ask for a domain to be added. Separately,
the site publishes less than it used to, without changing anything you see.
What's new
Government and university operators can request monitoring for their domain.
The button appears on the home page and at the top of every country page.
Security
The raw data files behind the dashboard are no longer indexed by search engines.
The working files the build uses are no longer reachable over the web at all.
Country names are escaped before being shown in map tooltips.
2.11.0NewFix
Address Space Rebuilt, Mobile Scrolling Fixed
The Address Space tab is now one row per organisation instead
of one row per address block, and country pages scroll properly on a phone.
What's new
A member holding nine address blocks used to fill nine rows. Each organisation
now gets a single row showing its first block and how many more it holds.
Click a row to see every block, with the status and allocation date for each.
BGP Routing shows four states instead of two: announced at full size,
reachable only through smaller parts, not routed, or missing from the dataset.
The explanation at the top of each tab was rewritten in simpler language.
Fixed
The map used to capture upward and downward swipes on phones, which left the
page stuck. Pinch to zoom and tap a country still work.
Address blocks were sorted as plain text, which put larger numbers in the
wrong place.
Expanded rows on the Domain tab rendered as a broken table on phones.
Good to know
Routing percentages are lower than before, and more honest. The old method
counted a block as announced if any part of it appeared anywhere in the global
routing table, which overstated how much address space is really reachable.
Nothing got worse. The measurement got stricter.
A block we have no information about is now labelled No data
rather than being reported as not routed.
2.10.0Fix
Map Boundaries Corrected
Three countries were drawn or shaded incorrectly on the
Africa map.
Fixed
Somalia is drawn in full. The highlight previously left out the north west
of the country.
Morocco no longer includes Western Sahara. The underlying map data merged the
two, so the disputed territory was shaded as part of Morocco.
Sudan's data now appears. Its domains were being monitored, but the country
was greyed out on the home page and the map.
2.9.0New
Real Operator Names on Address Blocks
Address blocks now show who holds them instead of only a
raw IPv6 prefix.
What's new
You now see the organisation, for example MTN Nigeria or Safaricom Limited.
Names were found for about 94 percent of allocations. The remainder still
show the prefix.
2.8.0New
BGP Routing Rebuilt Around Allocations
The tab now lists address blocks rather than networks, so
you can see which allocations are actually in use.
What's new
Every block AFRINIC has allocated in the country appears with a clear
announced or not routed status.
Summary counts for total allocations, blocks announced, and blocks not yet
routed.
2.7.0New
Address Space and BGP Routing Tabs
Two new tabs on every country page, and a short explanation
at the top of each one.
What's new
Address Space shows every IPv6 block AFRINIC has allocated or assigned to
organisations in the country.
BGP Routing shows which networks are announcing IPv6 on the global routing
table.
Every tab now opens with a plain explanation of what it shows and where the
data comes from.
2.6.0New
Tabs, and Adoption by Network Operator
Country pages were reorganised, and adoption is now broken
down per internet provider rather than one national figure.
What's new
Four tabs per country instead of one long page: Domain, End User Adoption,
Address Space and BGP Routing.
A table showing how each internet provider in the country is doing on IPv6.
The map can be switched between Infrastructure, IPv6 Capable and IPv6
Preferred, each with its own colour scale.
2.5.0New
End User IPv6 Adoption
Until now the site only showed whether government services
support IPv6. This shows whether ordinary people in the country can actually use it.
What's new
Real world IPv6 usage per country, measured by the APNIC Measurement Lab and
shown as two dials.
IPv6 Capable is the share of users who can reach IPv6
destinations.
IPv6 Preferred is the share who choose IPv6 when both are
available.
2.4.0New
Monthly Automatic Re-Scan
The monitor keeps itself up to date without anyone having
to trigger a scan.
What's new
Every domain is re-checked on the first of each month, so the figures stay
current.
2.3.0Fix
The DNSSEC Card Was Showing the Wrong Number
The count labelled DNSSEC was reporting something else
entirely, which made several countries look better than they were.
Fixed
The card was counting domains with IPv6 nameservers, not domains with working
DNSSEC. Nigeria showed 4 signed domains when in fact none were signed.
DNS and DNSSEC are now separate cards, so the two can no longer be confused.
2.2.1Data
First Full Scan Across 15 Countries
The dashboard was filled with real results for the first
time.
What's new
All 40 domains across 15 countries were scanned and published.
2.2.0New
NIST Style Results Table
The results table was redesigned to match the layout used
by the NIST deployment monitor.
What's new
Plain words instead of codes. Cells read Operational, In Progress,
No Progress, N/A or Unsigned.
Click any row for the detail behind the colour, including the raw technical
codes, the SOA record and the DNSSEC state, with a legend explaining all of it.
2.1.0Change
Clearer Summary Cards
The cards at the top of a country page did not match what
their numbers actually counted.
Changed
The cards now show one count per service: DNS, Web and Mail.
The donut charts were removed. The same information reads better in the table
below them.
2.0.0First release
The Monitor, Rebuilt
The dashboard as you know it today, rebuilt from scratch as
a fast static site.
What's new
A home page for the whole continent, with a flag for every country and a
search box.
A page per country, with an interactive map of Africa alongside the data.
Click any country on the map to jump to it.
Summary cards and a colour coded results table covering IPv6 on nameservers,
web servers and mail servers, plus DNSSEC.
Faster and simpler underneath, with no live database behind it, so it loads
quickly and has very little that can break.