Current Status of RPKI — ROAs and ASPAs Across the Internet

Post by Gaurav Kansal Data last refreshed: 2026-09-14 16:52 IST LIVE — AUTO-UPDATED EVERY 24H
Current Status of RPKI — ROAs and ASPAs Across the Internet A warm parchment-themed blog banner showing RPKI adoption status across RIRs, APNIC region, and India. IS THE ROUTING TABLE ACTUALLY SECURE? RPKI Status ROAs & ASPAs A living snapshot, refreshed every 24 hours RIR coverage · APNIC region · India specific detail ASPA COVERAGE BY RIR RIPE NCC (1,958) ARIN (623) APNIC (329) LACNIC (140) AFRINIC (0) rpki.gauravkansal.in Auto-refreshed
228 129 93 61 3

RPKI (Resource Public Key Infrastructure) lets an Autonomous System prove two things with a cryptographic signature instead of just trusting BGP announcements: Whether any ASN is actually allowed to originate any given IP prefix, and whether it is actually allowed to sit in the path as someone's transit provider. A ROA (Route Origin Authorization) covers the first case — it stops one network from announcing someone else's IP range by mistake or on purpose. An ASPA (Autonomous System Provider Authorization) covers the second — it stops route leaks, where a network accidentally forwards a route to the wrong upstream.

This is a living post rather than a one-time write-up. The charts and numbers below are regenerated automatically every 24 hours directly from the RPKI repositories and each RIR's own delegation records, so what you're reading reflects the actual state of adoption as of the timestamp above.
📡 This data was captured 14 minutes ago (at last check).

The Global Picture

As of this refresh, here is ASPA adoption across all five Regional Internet Registries:

RIRASNs with ASPATotal ASNsCoverage
RIPENCC1,95839,8634.912%
ARIN62334,1031.827%
APNIC32931,2971.051%
LACNIC14014,3450.976%
AFRINIC02,7870.000%
ASPA adoption by RIR

ROA Publication — the Mature Baseline

Unlike ASPA, ROA (Route Origin Authorization) is well-established across every RIR. 'ASNs with a ROA' only means an ASN has signed at least one IPv4 or IPv6 resource — it doesn't mean everything that ASN announces is covered. A network with 1 of its 50 announced prefixes signed counts exactly the same as one with all 50 signed, if you only look at that column. The table also shows the actual object count — the total number of individually signed resources (VRPs) per RIR — and the average number of signed objects per covered ASN, which gives a sense of how deep the coverage actually goes, not just how many networks have started.

RIRASNs with ≥1 ROATotal ASNsASN CoverageTotal ROA ObjectsAvg No of Obj Covered per ASN
RIPENCC27,39439,86368.720%41,031,0581497.8
APNIC19,23031,29761.444%39,350,5932046.3
ARIN13,29434,10338.982%15,357,8971155.3
LACNIC7,09114,34549.432%5,983,560843.8
INDIA2,9836,20948.043%42,12714.1
AFRINIC1,7082,78761.285%4,041,5142366.2
ROA publication by RIR

The chart above shows the ASN-presence metric only for visual consistency with the ASPA chart.


ROV — Is Anyone Actually Checking?

Publishing a ROA or ASPA only matters if other networks validate against it. ROV (Route Origin Validation) measures that missing piece — not what's published, but what's actually enforced. APNIC Labs runs a continuous global measurement of this using anycast beacon routes delivered to end-user devices via an ad-measurement network: one route is permanently RPKI-valid as a control, another is permanently RPKI-invalid, and APNIC tracks what fraction of a country's users can still reach the invalid one — those users are sitting behind networks that are not dropping invalid routes. (The exact prefixes used aren't publicly disclosed, deliberately — publishing them would let networks treat them a special one rather than genuinely enforcing ROV everywhere. Full methodology: APNIC Labs, "How we measure". Worth noting: independent researchers (in the TORCH paper, which cross-checked APNIC's results against their own multi-prefix measurement) have pointed out that relying on a single invalid test prefix gives only a partial view compared to testing many prefixes simultaneously — treat these numbers as a solid trend indicator rather than an exact figure.)

ROV enforcement rate: World vs India

As of 2026-09-13, 26.99% of internet users globally sit behind networks enforcing ROV.

Why isn't this just 0% or 100%? For any one person's connection, the answer really is close to binary — either the specific route they're using got blocked, or it didn't. The percentage you see is what happens when you average millions of individual "yes" or "no" answers together across a whole country, and the mix comes out somewhere in between for two main reasons.

The first is simple: a big operator runs routers in many cities, upgraded at different times, so some of its own customers are protected and others temporarily aren't, even under the same company.

The second is more interesting, and it's the one worth mentioning: you can end up protected even if you personally do nothing. If every path your network uses to reach the internet happens to go through an upstream provider that blocks invalid routes, that invalid route simply never arrives at your door — your own network gets counted as "protected" purely because of what your provider did, not because of anything you configured. Researchers studying this (at Cloudflare and independently at APNIC) call this "inherited" protection, and it's real enough that APNIC had to specifically redesign their measurement to account for it. The catch: this only holds if every path you use is through a provider that blocks invalids. The moment you have even one upstream, or one peer, that doesn't — the invalid route can slip in through that gap instead, and you're only partially protected.
KEY TAKEAWAY

A handful of major ISPs turning on ROV could protect the majority of a country's users — even users whose own ISP does nothing at all. This is exactly what the inherited-protection mechanism above means in practice: protection cascades downstream through the network, so adoption doesn't need to be universal to have an outsized effect.

For India specifically: if Jio, Airtel, BSNL, Vi, and Tata all turned ROV on, India's score would very likely jump well past 90%, for two different reasons layered together. Jio, Airtel, Vi, and BSNL are mainly retail providers — most of India's actual internet users connect through one of them directly, so their own adoption protects those users immediately, with no inheritance needed at all. Tata Communications is different: it's a major wholesale carrier that many smaller Indian ISPs buy transit from, so its adoption would cascade down to those smaller networks' customers too, protecting people who never touched Tata's network directly. The one thing that would hold the number back from a clean 90%+: any smaller ISP that also buys transit from a second, non-adopting provider as backup would still leak through that second path — so the real ceiling depends on how many of India's smaller networks are single-homed to one of these five versus quietly multihomed elsewhere too. Still, decisions by five companies moving the needle for an entire country is the whole point of this mechanism.

Where does India stand next to the countries doing this best? Here's the same 28-day filter rate, worldwide and then narrowed to Asia, both anchored on India so its position is easy to see either way:

Top ROV-enforcing countries worldwide, with India Top ROV-enforcing countries in Asia, with India

Both lists are restricted to countries with roughly 10 million or more internet users, so small countries with unusually high (or low) numbers don't crowd out the comparison. This candidate list is a manually maintained estimate, not a live feed, and is only recalculated every 48 hours rather than on every refresh, since these rankings don't move much day to day.


The APNIC Region

Zooming into APNIC specifically — 329 ASNs out of 31,297 total APNIC-delegated ASNs (1.051%) currently publish an ASPA object.

APNIC ASPA adoption by country
CountryASNs
IN64
AU56
BD46
PK27
NP20
NZ16
PH15
SG13
See all 32 countries ▾

Special Case: AS0

SPECIAL CASE: AS0

Not every ASPA declares real upstream providers — some declare none at all, on purpose. An ASPA can list Provider AS 0 instead of actual ASNs, which is a formal declaration: "I am at the top of the routing hierarchy — I have no transit providers." This is different from simply not publishing an ASPA at all (which just means "unknown" to a validator). An AS0 declaration converts that ambiguity into a hard "Invalid" if that network is ever seen receiving purported transit from anyone — useful specifically for networks that should never legitimately have an upstream, like an Internet Exchange's route server or a registry's own internal infrastructure.

Currently, 3 APNIC-region ASN(s) publish an AS0 ASPA:

ASNOrganisationCountryProviders
AS9833HawkNet Labs Pty LtdAUAS0 only (no upstream)
AS55518Singapore Internet Exchange LimitedSGAS0 only (no upstream)
AS131211APNIC Member Services 2AUAS0 only (no upstream)

India

64 of India's 6,209 APNIC-delegated ASNs (1.031%) currently publish ASPA.

Progress Report — Who's Adopting, and When

The numbers above are a snapshot; this table is the timeline behind them. Every APNIC-region ASN gets logged here the first time it shows up publishing ASPA, with the date it was first observed - so instead of just knowing the current count, you can see who's actually been adopting it and when, not just India's ASNs but the whole APNIC region. Newest entries first.

ASNOrganisationCountryFirst Seen
AS24014Bond University LimitedAU2026-09-14
AS139053Jhongkar ITBD2026-09-14
AS141452Jhongkar ITBD2026-09-14
AS146957Click OnlineBD2026-09-14
AS9230Bangladesh Online LtdBD2026-09-14
AS17644Zorn TechnologiesBD2026-09-14
AS23955Tashi InfoComm LimitedBT2026-09-14
AS45754Clear Path Networks IncPH2026-09-14
See all 333 entries ▾

Recently Removed ASPA

The flip side of the table above: ASNs that WERE publishing ASPA and no longer are. This usually means one of a few things — a network deliberately withdrew it, a CA transition or renewal briefly dropped it. Newest removals first. If an ASN adopts, is removed, and later re-adopts, each removal is logged as its own separate event here — nothing gets silently merged or overwritten.

ASNOrganisationCountryLast Seen ActiveRemoved
AS154723Optical CommunicationBD2026-08-152026-09-10
AS137385Asian NetworkBD2026-08-312026-09-01
AS139317Ningbo Dahuamao Information Technology Co LtdCN2026-07-162026-08-24
AS153176PT LAPAK REGISTAR MURAHID2026-03-012026-08-24
AS151673Chen XinyuCN2026-07-232026-08-24
AS24322Infininet Global Pty LtdAU2025-12-222026-08-17
AS24381Infininet Global Pty LtdAU2025-12-242026-08-17
AS138038Wolf Network LabJP2025-12-032026-08-17
See all 21 entries ▾

For ROA, the picture is far more mature: 2,983 ASNs (48.043%) publish at least one ROA, covering 42,127 signed resources in total.

The number that actually matters most for India: only 1.14% of users are behind networks that enforce ROV — against a global average of 26.99%. Publishing ROAs and ASPAs doesn't protect anyone if the networks carrying India's traffic aren't actually checking them. That gap matters far more than the publication numbers above.
India ASPA coverage
ASNOrganisationProviders
AS4758National Informatics Centre9885, 55824
AS9829Bharat Sanchar Nigam Ltd174, 1273, 1299, 2914, 3257, 3491, 4755, 5580, 6453, 6762, 9498, 24029, 24457, 24470, 24508, 40009, 45489, 55836, 59200
AS9885National Knowledge Network4755, 9498, 11537, 20965, 23855, 24029, 24490, 55836
AS17747SITI NETWORKS LIMITED9498, 15169, 21357, 24029, 55836, 134375, 135188
AS38620National Knowledge Network55824
AS55806M/s VIVA COmmunications4755, 9498, 9583, 9730, 18229
AS55824National Knowledge Network4758, 9885
AS55847NKN EDGE Network55824
See all 64 ASNs ▾

Why Bother With Any of This?

If you run a network, here's the plain case for turning these on:

Closing Thoughts

These numbers move slowly, and that's expected — ASPA only protects a network once that network actually publishes it, and that depends on how ready each RIR's tools are and whether individual network operators get around to setting it up. This post keeps refreshing on its own, so come back for the current numbers instead of trusting whatever you read here on any one day.


Data sources: rpki-client console output, APNIC/RIPE/ARIN/LACNIC/AFRINIC delegated statistics files, RDAP lookups against rdap.apnic.net. Auto-refreshed every 24 hours. Snapshot generated: 2026-09-14 16:52 IST.