Release history

Every change to the Africa IPv6 & DNSSEC Deployment Monitor since the dashboard was first built, newest first.

2.15.0 New Fix

Checking the Harder Questions

The ccTLD tab added last time asked whether a country's registry servers answer simple questions over IPv6. This update asks two harder ones: do they answer questions correctly under real conditions, and does the internet's official record of who runs the domain actually match what the registry is running?

What's new

  • Two new checks on the ccTLD tab: does it handle EDNS(0) (a DNS extension nearly every modern lookup depends on), and can it deliver a large, signed answer over IPv6 without the answer getting lost.
  • This matters because a signed domain's answers are much bigger than a simple lookup. They often don't fit in a single small internet packet, and the server has to say "here's more, ask me again a different way." That second step is where DNS over IPv6 most often breaks, and the simple checks from last time couldn't see it at all.
  • Across Africa, 185 of 186 registry servers with IPv6 handle the extension correctly. Among the servers whose country domain is properly signed, all but a handful correctly deliver a full, large answer.
  • Two registries, Tunisia and Uganda, were found to have servers that sometimes fail this specific check over IPv6 even though they work fine over the older IPv4 internet. It isn't constant, sometimes it works and sometimes it doesn't, which is itself useful to know: it points at an unreliable connection rather than something switched off.
  • A second new check compares the internet's official record of who runs each country's domain against what the registry's own servers say. These can quietly drift apart when a registry adds or retires a server.
  • Four country domains were found where the official record is out of date: it still lists servers a registry has retired, or hasn't caught up with new servers a registry has brought online. Two more countries were found where the official record and the registry agree on which servers exist, but disagree about one server's actual address.

Good to know

  • Not every server could be checked for the address-matching question. Where a check couldn't be done, the tab says so plainly rather than guessing or assuming it passed.
  • The large-answer check only runs on country domains that are properly signed, since that's the only place a large answer actually gets sent. Everywhere else it's marked "not tested", not "failed".
2.14.0 New Fix

Measuring the Country's Own Domain

Until now the dashboard measured individual government and university domains. It now also measures the country's top level domain itself, the one the national registry runs, such as .ng or .za.

What's new

  • A new ccTLD tab on every country page.
  • It asks three things of each of the registry's nameservers. Does it have an IPv6 address? Does it answer over IPv6? And can it actually answer DNS questions over IPv6?
  • It also shows whether the country's domain is signed with DNSSEC.
  • Click any nameserver to see each of its addresses and what each one did.
  • This matters because the country's domain sits above every domain in the country. If the registry's servers cannot be reached over IPv6, nothing underneath them can be either, no matter how well an individual domain is set up.
  • Across Africa, 186 of 270 registry nameservers have IPv6 and 184 answer questions over it. 35 of 60 country domains are signed with DNSSEC. Four have no IPv6 anywhere.
  • Six countries also have an Arabic-script version of their domain alongside the Latin one, and both are measured. Algeria, Egypt, Morocco, Mauritania, Sudan and Tunisia.

Fixed

  • Equatorial Guinea has a page for the first time. It was the one country of 54 with no page, because no domains had been added for it. It has registry data like everyone else, and .gq turns out to be one of the better configured ones: all four of its nameservers work over IPv6.

Good to know

  • These checks run from one place, in Africa. A nameserver that answers here is not proven to answer from everywhere in the world.
  • The tab treats "answers DNS questions" as the trustworthy result and "responds to a ping" as a softer hint, because some networks block pings on servers that answer questions perfectly well.
2.13.0 New

This Page

A release history you are reading right now, written for people who use the dashboard rather than people who build it.

What's new

  • Every release from 2.0.0 onward, newest first, at /changelog.
  • Linked from "What's new" in the home page footer.
  • Awkward facts are kept rather than dropped. Where a number moved because the measurement got stricter rather than because anything got worse, it says so.
2.12.0 Security

Request Monitoring, and a Tighter Site

Operators can now ask for a domain to be added. Separately, the site publishes less than it used to, without changing anything you see.

What's new

  • Government and university operators can request monitoring for their domain.
  • The button appears on the home page and at the top of every country page.

Security

  • The raw data files behind the dashboard are no longer indexed by search engines.
  • The working files the build uses are no longer reachable over the web at all.
  • Country names are escaped before being shown in map tooltips.
2.11.0 New Fix

Address Space Rebuilt, Mobile Scrolling Fixed

The Address Space tab is now one row per organisation instead of one row per address block, and country pages scroll properly on a phone.

What's new

  • A member holding nine address blocks used to fill nine rows. Each organisation now gets a single row showing its first block and how many more it holds.
  • Click a row to see every block, with the status and allocation date for each.
  • BGP Routing shows four states instead of two: announced at full size, reachable only through smaller parts, not routed, or missing from the dataset.
  • The explanation at the top of each tab was rewritten in simpler language.

Fixed

  • The map used to capture upward and downward swipes on phones, which left the page stuck. Pinch to zoom and tap a country still work.
  • Address blocks were sorted as plain text, which put larger numbers in the wrong place.
  • Expanded rows on the Domain tab rendered as a broken table on phones.

Good to know

  • Routing percentages are lower than before, and more honest. The old method counted a block as announced if any part of it appeared anywhere in the global routing table, which overstated how much address space is really reachable. Nothing got worse. The measurement got stricter.
  • A block we have no information about is now labelled No data rather than being reported as not routed.
2.10.0 Fix

Map Boundaries Corrected

Three countries were drawn or shaded incorrectly on the Africa map.

Fixed

  • Somalia is drawn in full. The highlight previously left out the north west of the country.
  • Morocco no longer includes Western Sahara. The underlying map data merged the two, so the disputed territory was shaded as part of Morocco.
  • Sudan's data now appears. Its domains were being monitored, but the country was greyed out on the home page and the map.
2.9.0 New

Real Operator Names on Address Blocks

Address blocks now show who holds them instead of only a raw IPv6 prefix.

What's new

  • You now see the organisation, for example MTN Nigeria or Safaricom Limited.
  • Names were found for about 94 percent of allocations. The remainder still show the prefix.
2.8.0 New

BGP Routing Rebuilt Around Allocations

The tab now lists address blocks rather than networks, so you can see which allocations are actually in use.

What's new

  • Every block AFRINIC has allocated in the country appears with a clear announced or not routed status.
  • Summary counts for total allocations, blocks announced, and blocks not yet routed.
2.7.0 New

Address Space and BGP Routing Tabs

Two new tabs on every country page, and a short explanation at the top of each one.

What's new

  • Address Space shows every IPv6 block AFRINIC has allocated or assigned to organisations in the country.
  • BGP Routing shows which networks are announcing IPv6 on the global routing table.
  • Every tab now opens with a plain explanation of what it shows and where the data comes from.
2.6.0 New

Tabs, and Adoption by Network Operator

Country pages were reorganised, and adoption is now broken down per internet provider rather than one national figure.

What's new

  • Four tabs per country instead of one long page: Domain, End User Adoption, Address Space and BGP Routing.
  • A table showing how each internet provider in the country is doing on IPv6.
  • The map can be switched between Infrastructure, IPv6 Capable and IPv6 Preferred, each with its own colour scale.
2.5.0 New

End User IPv6 Adoption

Until now the site only showed whether government services support IPv6. This shows whether ordinary people in the country can actually use it.

What's new

  • Real world IPv6 usage per country, measured by the APNIC Measurement Lab and shown as two dials.
  • IPv6 Capable is the share of users who can reach IPv6 destinations.
  • IPv6 Preferred is the share who choose IPv6 when both are available.
2.4.0 New

Monthly Automatic Re-Scan

The monitor keeps itself up to date without anyone having to trigger a scan.

What's new

  • Every domain is re-checked on the first of each month, so the figures stay current.
2.3.0 Fix

The DNSSEC Card Was Showing the Wrong Number

The count labelled DNSSEC was reporting something else entirely, which made several countries look better than they were.

Fixed

  • The card was counting domains with IPv6 nameservers, not domains with working DNSSEC. Nigeria showed 4 signed domains when in fact none were signed.
  • DNS and DNSSEC are now separate cards, so the two can no longer be confused.
2.2.1 Data

First Full Scan Across 15 Countries

The dashboard was filled with real results for the first time.

What's new

  • All 40 domains across 15 countries were scanned and published.
2.2.0 New

NIST Style Results Table

The results table was redesigned to match the layout used by the NIST deployment monitor.

What's new

  • Plain words instead of codes. Cells read Operational, In Progress, No Progress, N/A or Unsigned.
  • Click any row for the detail behind the colour, including the raw technical codes, the SOA record and the DNSSEC state, with a legend explaining all of it.
2.1.0 Change

Clearer Summary Cards

The cards at the top of a country page did not match what their numbers actually counted.

Changed

  • The cards now show one count per service: DNS, Web and Mail.
  • The donut charts were removed. The same information reads better in the table below them.
2.0.0 First release

The Monitor, Rebuilt

The dashboard as you know it today, rebuilt from scratch as a fast static site.

What's new

  • A home page for the whole continent, with a flag for every country and a search box.
  • A page per country, with an interactive map of Africa alongside the data. Click any country on the map to jump to it.
  • Summary cards and a colour coded results table covering IPv6 on nameservers, web servers and mail servers, plus DNSSEC.
  • Faster and simpler underneath, with no live database behind it, so it loads quickly and has very little that can break.