Blog

Longer answers to the questions a report cannot fit in a panel. What a record can settle, what it cannot, and where a signal that looks decisive is worth less than it appears.

No news and no announcements. Each piece is about a decision somebody is in the middle of, and it names the registries, feeds and prefixes involved rather than talking around them.

  • IPv4 subnet cheat sheet: CIDR sizes, masks and special ranges

    The three tables everyone keeps re-deriving: every prefix from /8 to /30 with its address count and mask, the reserved ranges that explain odd log entries, and the ASN ranges that are never real networks. Bookmark it, and let the linked explainers pick up where the rows stop.

    3 min read

  • Bogons and martians: the addresses that should never reach you

    Somewhere in your logs is a packet whose source cannot exist: private space arriving from the open internet, or a range nobody was ever allocated. What bogons are, why they still show up, and how to filter them without silently blocking the future.

    4 min read

  • Dedicated vs shared IP addresses: whose reputation are you renting?

    Every hosting plan and sending platform eventually asks the same upsell question, and it is not about performance. On a shared address your fate is priced by strangers; on a dedicated one, by you, plus whatever the address did before you got it. The trade, honestly.

    3 min read

  • What is an ASN? Autonomous systems, explained

    Sooner or later every log, report and routing question leads to a number written like AS15169, and everything else about the network hangs off it. What an autonomous system actually is, who gets a number, how to read one, and where the number stops telling you things.

    4 min read

  • What a /24 actually gets you: subnet sizes for buyers and lessees

    Every listing in the address market is a slash number, and the sizes carry consequences the notation does not mention: what can be routed on its own, what can be split, and what the market will take back off your hands. CIDR for people about to pay for some of it.

    4 min read

  • Why IPv4 still costs money in the IPv6 era

    The successor protocol is finished, abundant and nearly free, yet a /24 of the old one still costs thousands and an industry brokers, leases and securitises it. The dual-stack economics behind the paradox, and what they mean if you hold or need address space.

    4 min read

  • WHOIS vs RDAP: how to read an IP registration record

    Running a whois is the first thing everyone does with an unfamiliar address, and reading the answer well is rarer than it should be. The fields that matter, the dates that change decisions, and the line between what a self-reported record shows and what it proves.

    5 min read

  • How IP blocklists actually work: DNSBLs, listings and delisting

    A bounce message names a list and a URL, and suddenly infrastructure you have never thought about is deciding whether your mail arrives. The DNS mechanism underneath, the list families that mean different things, how addresses get on, and what actually gets them off.

    5 min read

  • How IPv4 transfers work: moving address space between holders

    The free pool ran dry and a market took its place: millions of addresses now change hands yearly through a registry process most buyers see once. The kinds of transfer, the steps from agreement to registry update, and the longer list of things a transfer does not change.

    4 min read

  • RPKI invalid: why your prefix is being dropped, and how to fix it

    You announce your prefix and it works, mostly: some networks reach you, others cannot, with no pattern you can see. Before you chase a routing bug, check RPKI. Partial unreachability is often a ROA contradicting your announcement, frequently one the previous holder left behind.

    5 min read

  • Setting up reverse DNS (PTR records) for your subnet

    Forward DNS you set up in minutes. Reverse DNS on a block you control is the step people skip, because it needs a delegation nobody hands you, and it is the first thing many mail servers check. How PTR records, zone delegation and forward-confirmed rDNS actually work.

    5 min read

  • CGNAT explained: why one IP address is thousands of people

    You block an abusive address and unrelated users complain. The address is carrier-grade NAT: one public IP shared by thousands of subscribers, so it is not a person. What CGNAT is, how to recognise a shared address, and why it makes IP bans backfire.

    5 min read