How to read a prefix's routing history: gaps, origin changes and deaggregation
The registry says who holds a block. The routing table says what the block has been doing, and it has a longer memory than most sellers expect: public collectors have watched announcements since the late 1990s, and the record survives every transfer and every new name on the paperwork. Buyers read it to test the story a broker tells, operators read it to understand a neighbour, analysts read it to date an incident. Three patterns come up over and over: a long dark gap, a parade of origins, and a block that suddenly dissolves into /24s. Each has a benign reading and an ugly one. Where the records live is its own post; this one is about reading them.
A sample of the routing system, not a recording
Start with what the timeline is made of, because every pattern below inherits its limits. The routing history many tools show, ours included, comes from RIPE NCC's Routing Information Service, a network of route collectors that accept BGP feeds from volunteer networks. As of August 2026 there are about two dozen active collectors, most of them sitting at large internet exchanges and most of those in Europe, taking feeds from roughly eight hundred IPv4 peers of which around three hundred and forty share full tables. RIPE's own analysts describe the result as a sample with an unknown bias, and the bias has a direction: well connected, exchange present networks are over represented, small regional ones under represented.
Two mechanical limits follow. Collectors publish full table dumps every eight hours and raw updates every five minutes, but long range views are downsampled: a full history query through RIPEstat in August 2026 came back in twelve day buckets. And default views filter: RIPEstat drops segments seen by fewer than ten full feed peers as low visibility noise. So the honest phrasing for any absence is that the route was not seen by RIS peers, never that the block was never announced. A short lived announcement can blur into nothing and a localized one can stay invisible at any duration. One more habit worth keeping: RIPEstat, BGPlay and RIS Live all read from the same collectors, so agreement between them is not independent confirmation. The University of Oregon's RouteViews project, collecting separately since 1997, is the independent cross check.
Our report reads this ledger through RIPEstat. The origin history panel shows one row per network and prefix, first seen to last seen, notes an announcement that came and went as several periods, and separates covering aggregates announced for transit from announcements of the block itself, because who moves the traffic is a different fact from who controls the addresses.
Pattern one: the long dark gap
A gap is years in which no collector peer saw anyone originate the space. The benign explanations are ordinary: a holder with more space than need, an enterprise that uses the block internally and never routes it publicly, an allocation held for growth that never came. Address space does not decay when idle, and idleness proves nothing by itself.
The ugly explanation is that dormant space is raw material. Spamhaus's January 2019 explainer on network hijacking describes the playbook: find a range whose registrant is defunct or inattentive, re register the lapsed contact domain, forge the paperwork, and get an ISP to announce it. The canonical case is Bitcanal, a Portuguese company exposed by researcher Ron Guilmette in June 2018 and written up by Doug Madory: years of announcing other people's dormant space and leasing it to spammers, over a hundred Spamhaus listings dating back to 2014, and a cascade of disconnections in July 2018 that ended with its last upstream pulling the plug. Measurement work backs the pattern at scale: a study presented at NDSS in 2015 tracked eighteen months of routing and spam data and flagged more than two thousand suspected malicious hijacks, most lasting under a day, which is exactly the duration a coarse timeline view blurs away.
But a gap that ends abruptly is a question, not a verdict. In January 2021 AS8003, which no collector peer had seen announce anything before, began announcing dormant US Department of Defense space including 11.0.0.0/8, reaching roughly 175 million addresses by April, and the Pentagon confirmed the announcements were authorized. For a buyer the question is timing: a revival that begins just before a sale or lease pitch deserves the questions in why new ranges arrive already blocklisted.
Pattern two: a parade of origins
The second pattern is origins that keep changing. One long tenure followed by a new origin is the routine signature of commerce: Geoff Huston's January 2026 review counts 33 million IPv4 addresses transferred through the registry system in 2025 alone, and about 342 million since the transfer logs began in 2012, and a sale typically ends in a new announcing network. Do not reach for a transfer as the default explanation, though: the same review compared routing changes against the logs and found only about 7 percent of year to year changes in advertised addresses matched a recorded transfer. Leasing explains more of the rest than it used to. A measurement study presented at IMC 2024 inferred that around 4 percent of advertised IPv4 prefixes were leased, and a leased block is usually announced by the lessee's network rather than the registered holder's. The same study found leased prefixes about five times more likely to be announced by a blocklisted network, 1.1 percent against 0.2, a figure that cuts both ways: leasing correlates with blocklisted origins, and roughly 99 percent of leased prefixes were announced by networks with no listing at all.
The signature worth worrying about differs in shape, not just in count. Researchers profiling serial hijackers at IMC 2019 found that they originate many prefixes in brief, intermittent episodes, where legitimate origins persist for months or years, and flagged roughly nine hundred ASes with that profile; a 2024 replication found the profile mostly still holds, while cautioning that legitimate multi origin announcements have grown common enough to cause false positives. Read churn against the story you were told. A seller who says they have held the space quietly since 2016 should have a timeline that shows their network, or their upstream, and nobody else. Five strangers in four years is not disqualifying, but every one of them is a question, and hijacked or transferred is the procedure for the worst reading.
Pattern three: the block dissolves into /24s
The third pattern is a block that falls apart. An aggregate announced whole for a decade starts appearing as separately announced /24s. The split alone means little: by the end of 2025, prefixes between /22 and /24 made up 84 percent of the IPv4 routing table, and more specifics have hovered around half of all entries for years. Geoff Huston's taxonomy sorts them into hole punching, traffic engineering and inert overlays, and finds real operational purpose in the first two. The /24 itself is a floor with a paper trail: RFC 7454 records the operational convention, documented by the RIPE community, that IPv4 prefixes longer than /24 are generally neither announced nor accepted. RIPE NCC's case study of the 2008 YouTube hijack shows the floor in action: when YouTube countered the hijack of 208.65.153.0/24 with two /25s, the /25s reached 21 RIS peers where the /24 reached 105.
What carries information is who announces the pieces and when, not the split itself. The same origin announcing its own /24s is usually traffic engineering, though a holder carving space ahead of a lease looks identical until the origins change. Different origins appearing under one aggregate mean the space is being parceled out, and the market does that legitimately at scale: about a quarter of all recorded transfers since 2012 carved a larger block into smaller pieces, and one leasing marketplace's tracked pool grew from under a million addresses in early 2022 to over nine million by 2025. A /16 dissolving into /24s announced by strangers after a quiet decade reads differently from the same split at a recorded transfer, and for a buyer, checking a subnet's history before you buy is the checklist this pattern feeds.
Reading routing against the paper record
Routing history earns its keep when you read it against the paper record, because nothing obliges the two to agree. A registry transfer is a dated public event, but the transfer date and the routing change do not have to coincide: a buyer may announce before the registry processes the paperwork, long after it, or never, and a gap between the dates is normal rather than suspicious. Route objects in the IRR assert that some network intends to originate a prefix, and they go stale by design; RFC 7682 documents why they rarely get cleaned up, and since January 2020 the RIPE NCC has been removing non authoritative objects that stay in conflict with a published ROA for two weeks. IRR route objects explained covers that ledger. RPKI is the strictest of the three: a ROA, whose current profile is RFC 9582 from May 2024, names one authorized origin per ROA, a prefix can carry several, and origin validation checks exactly that and nothing else, no path, per RFC 6811. What happens when a prefix goes RPKI invalid covers the consequences.
The reading that matters is agreement. A timeline whose origin changes line up with a recorded transfer, a fresh ROA and a new route object is a block with a paper trail. A timeline whose changes match nothing on paper is a block where somebody is routing what the record says they should not, or where the record has not caught up, and which of those it is becomes the whole question.
What the timeline cannot settle
Carry the limits in the same pocket as the patterns. Absence is the big one: the view is a sample read through filters, so a clean timeline is not proof of a clean past. Granularity is the second: long range views arrive in multi day buckets, so a weekend of trouble can round to nothing. Scope is the third: on an ASN report the announced prefix list covers roughly the last two weeks, so a prefix a network dropped a month ago is absent from that list even though the prefix's own history still shows the announcement. Our reports keep the visibility filter low so that marginal announcements survive, and they still cannot show what no collector peer saw.
And the patterns do not grade themselves. The confirmed tag vocabulary includes frequent origin change and dormant space revived for established cases, but tags are sparse, they usually sit on the announcing network rather than on the prefix, and absence of a tag is never a finding of innocence. There are also no dated blocklist records to line up against a gap: blocklist feeds are read in the present, so the timeline cannot tell you whether the space was listed during the years it sat dark. The reading is yours to do; the record just makes it possible.
When a range's story matters, look it up on the front page before you rely on it: the origin history panel shows the networks RIS peers have seen originate the space, first seen to last seen, beside the registry's verbatim status, the enclosing blocks, the RPKI state and any confirmed tags. A pattern in the timeline is a question. The rest of the report is where you take it.