Post by @phlash@mastodon.me.uk

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net
2026-09-07 DNS Root Server Addresses
Letter IPv4 address IPv6 address Operator Operator origin

A | 198.41.0.4 | 2001:503:ba3e::2:30 | Verisign | United States
B | 170.247.170.2 | 2801:1b8:10::b | usc-Ist | United States
C | 192.33.4.12 | 2001:500:2::c | Cogent Communications | United States
D | 199.7.91.13 | 2001:500:2d::d | University of Maryland | United States
E | 192.203.230 |.10 2001:500:a8::e | NASA Ames Research Center | United States
F | 192.5.5.241 | 2001:500:2f::f | Internet Systems Consortium | United States
G | 192.112.36.4 | 2001:500:12::d0d | Defense Information Systems Agency | United States
H | 198.97.190.53 | 2001:500:1::53 | U.S. Army Research Lab | United States
I | 192.36.148.17 | 2001:7fe::53 | Netnod | Sweden
J | 192.58.128.30 | 2001:503:c27::2:30 | Verisign | United States
K | 193.0.14.129 | 2001:7fd::1 | RIPE NCC | Netherlands
L | 199.7.83.42 | 2001:500:9f::42 | ICANN | United States
M | 202.12.27.33 | 2001:dc3::35 | WIDE Project | Japan
2026-09-07 DNS Root Server Addresses Letter IPv4 address IPv6 address Operator Operator origin A | 198.41.0.4 | 2001:503:ba3e::2:30 | Verisign | United States B | 170.247.170.2 | 2801:1b8:10::b | usc-Ist | United States C | 192.33.4.12 | 2001:500:2::c | Cogent Communications | United States D | 199.7.91.13 | 2001:500:2d::d | University of Maryland | United States E | 192.203.230 |.10 2001:500:a8::e | NASA Ames Research Center | United States F | 192.5.5.241 | 2001:500:2f::f | Internet Systems Consortium | United States G | 192.112.36.4 | 2001:500:12::d0d | Defense Information Systems Agency | United States H | 198.97.190.53 | 2001:500:1::53 | U.S. Army Research Lab | United States I | 192.36.148.17 | 2001:7fe::53 | Netnod | Sweden J | 192.58.128.30 | 2001:503:c27::2:30 | Verisign | United States K | 193.0.14.129 | 2001:7fd::1 | RIPE NCC | Netherlands L | 199.7.83.42 | 2001:500:9f::42 | ICANN | United States M | 202.12.27.33 | 2001:dc3::35 | WIDE Project | Japan

At the core of the global internet are the DNS root servers. These 13 go-to places are at the top of authority when it comes to making sure you can connect to any server with a domain name. What you might not know is that 10 of these 13 root servers are ultimately under US jurisdiction. Should that worry you? I guess not, the current system is quite robust. But I deal in risk assessment and probabilities. And I think this isn't an ideal setup.

en.wikipedia.org/wiki/Root_nam

#DNS #Centralisation

Phil Ashby :marmite: 🍵
@phlash @mastodon.me.uk

@jwildeboer
Is there any research on creating a more federated, byzantine emperor tolerant dns root structure?

See also PKI root certificate lists and who authorises changes to them (Mozilla, Microsoft, Apple and various Linux distros, primarily Debian)...

Jan Wildeboer 😷:krulorange:
@jwildeboer @social.wildeboer.net

@phlash Ah, the root certificates collection. Another point of centralisation. Though mostly focused on browsers, less on operating systems, where (for now) you can add your own root certificates, even on iOS and Android. It's a complex issue. And better solutions come from understanding how the current system works. That's the discussion I hope to fire up :)