<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Why No IPv6 Blog</title>
    <link>https://whynoipv6.com/blog</link>
    <description>Write-ups from the crawl data: adoption numbers, notable changes, and methodology.</description>
    <language>en</language>
    <lastBuildDate>Wed, 12 Aug 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://whynoipv6.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>IPv6 DNS is now the law. Well, a best practice.</title>
      <link>https://whynoipv6.com/blog/two-ipv6-nameservers</link>
      <guid isPermaLink="true">https://whynoipv6.com/blog/two-ipv6-nameservers</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <description>The IETF has replaced its DNS transport guidance from 2004. Every zone MUST use two IPv6-reachable nameservers. One in five of the top million uses none.</description>
      <content:encoded><![CDATA[<p>Since 2004, the guidance for DNS over IPv6 has been <a href="https://www.rfc-editor.org/info/rfc3901" target="_blank" rel="noopener">RFC 3901</a>. It was written to make sure early IPv6 deployments did not break DNS for IPv4 users. Its replacement addresses the opposite problem: DNS that still cannot be reached over IPv6. The new requirement says:</p>
<blockquote>
<p>To prevent DNS name space partitioning, at least two IPv4-reachable and
two IPv6-reachable name servers MUST be configured for a zone. A single
name server that is reachable over both IPv4 and IPv6 counts once per
address family.</p>
</blockquote>
<p>This is not about the website or its mail server. It is about the zone's authoritative DNS. Each zone needs at least two nameservers reachable over IPv4 and two reachable over IPv6. Dual-stack servers count toward both requirements.</p>
<p>The MUST comes from <a href="https://www.rfc-editor.org/rfc/rfc10001.html" target="_blank" rel="noopener">RFC 10001</a>, by Momoka Yamamoto and Tobias Fiebig. A suitably round number for the occasion. The RFC is a Best Current Practice and replaces RFC 3901 as BCP 91. Same category, new guidance. RFC 3901 is now obsolete.</p>
<p>We measure this every day for the Tranco top million. Here is the compliance report the internet did not ask for.</p>
<h2>The scoreboard</h2>
<p>These numbers are a snapshot from the publication date. We track 988,163 zones. <strong>Of those, 204,942 have no IPv6-capable nameservers.</strong> That is 20.7%. They are not one server short of the requirement. They have none.</p>
<p>The requirement is two servers. During the previous 24 hours, our crawler graded 969,109 zones against that requirement:</p>
<ul>
<li><strong>78.1%</strong> meet it, with AAAA records on two or more nameservers</li>
<li><strong>20.9%</strong> have no IPv6 nameservers</li>
<li><strong>1.0%</strong> have exactly one</li>
</ul>
<p>The last number is the interesting one. Almost nobody deploys IPv6 DNS halfway. DNS operators tend to enable IPv6 across their nameservers or not at all. The top 1,000 domains do better, but 14.3% still fail to meet the requirement.</p>
<h2>Naming names, since that is what we do here</h2>
<p>The zero-server club includes some familiar names. <a href="/domains/akamai.net">akamai.net</a> is in it at rank 14. Akamai sells content delivery services. <a href="/domains/twitter.com">twitter.com</a>, <a href="/domains/x.com">x.com</a>, and their URL shortener <a href="/domains/t.co">t.co</a> are also in it. So are <a href="/domains/samsung.com">samsung.com</a> and <a href="/domains/playstation.net">playstation.net</a>.</p>
<p>Another 21,117 zones serve their websites over IPv6 while keeping their DNS on IPv4 only. <a href="/domains/europa.eu">europa.eu</a> leads that list at rank 115. The European Union has an official IPv6 strategy, but its own zone has no IPv6 nameservers. <a href="/domains/un.org">un.org</a> appears a few hundred ranks later, so this is not just a regional problem. <a href="/domains/hp.com">hp.com</a>, <a href="/domains/intel.com">intel.com</a>, and <a href="/domains/cornell.edu">cornell.edu</a> are on the list too. These sites pass the IPv6 check a visitor can see, but fail the DNS check their resolver performs first.</p>
<h2>Who controls this?</h2>
<p>The domain owner rarely configures this directly. IPv6 support usually depends on the company that operates the nameservers. Here is the table for DNS operators serving at least 5,000 domains in the top million:</p>
<table>
<thead>
<tr>
<th>DNS operator</th>
<th>zones</th>
<th>with at least one IPv6 nameserver</th>
</tr>
</thead>
<tbody>
<tr>
<td>Cloudflare</td>
<td>364,065</td>
<td>100.0%</td>
</tr>
<tr>
<td>Amazon Route 53</td>
<td>87,573</td>
<td>100.0%</td>
</tr>
<tr>
<td>GoDaddy</td>
<td>41,676</td>
<td>97.3%</td>
</tr>
<tr>
<td>Alibaba Cloud DNS</td>
<td>16,207</td>
<td>99.9%</td>
</tr>
<tr>
<td>Akamai Edge DNS</td>
<td>13,364</td>
<td>99.0%</td>
</tr>
<tr>
<td>Google Cloud DNS</td>
<td>12,306</td>
<td>100.0%</td>
</tr>
<tr>
<td>Microsoft Azure DNS</td>
<td>10,778</td>
<td>100.0%</td>
</tr>
<tr>
<td>Namecheap</td>
<td>10,413</td>
<td>99.8%</td>
</tr>
<tr>
<td>Tencent DNSPod</td>
<td>6,458</td>
<td>86.7%</td>
</tr>
<tr>
<td>OVHcloud</td>
<td>6,456</td>
<td>98.9%</td>
</tr>
<tr>
<td>Network Solutions</td>
<td>5,343</td>
<td>0.0%</td>
</tr>
</tbody>
</table>
<p>Four operators round to 100.0%. That is rounding, not perfection: between them, 92 zones out of nearly half a million still have no IPv6 nameserver. If your zone uses one of these operators, IPv6 was probably enabled without you having to ask. Akamai's DNS service for customers reaches 99.0%. Akamai's own akamai.net remains at zero.</p>
<p>Then there is Network Solutions. It operated the .com registry during the 1990s. Today it provides DNS for 5,343 domains in the top million, and not one has an IPv6 nameserver. One operator-level decision leaves the entire group outside the Best Current Practice.</p>
<h2>The trajectory</h2>
<p>During the last ten days, our <a href="/changelog">changelog</a> recorded 1,223 zones gaining their first IPv6 nameserver and 923 losing their last. That is a net gain of 30 zones per day. The previous ten days averaged 48, so treat this as weather rather than climate. At the slower rate, clearing the backlog of 204,942 zones would take about 19 years. At the faster rate, it would take 12. The BCP should still be current by then.</p>
<h2>The advice is eight years old</h2>
<p>Scott Hogg gave operators <a href="https://hoggnet.com/blogs/news/why-you-should-dual-stack-your-dns-nameservers" target="_blank" rel="noopener">the same advice</a> in 2018. Start IPv6 at the internet edge, where public nameservers already sit. Make those servers dual-stack. If the parent zone publishes IPv4 glue for your NS records, publish IPv6 glue alongside it. He concluded that running both protocols on nameservers &quot;is strongly recommended and is a task that is on the critical path to IPv6 deployment.&quot;</p>
<p>What was strongly recommended is now a MUST. The work itself is not new.</p>
<h2>Method, briefly</h2>
<p>We check up to four nameservers per zone and count the NS hosts with AAAA records. The RFC also RECOMMENDS that every hostname in an NS record have both an A and a AAAA record.</p>
<p>The MUST is stricter: the nameservers must actually answer over IPv6. We check whether a server has an IPv6 address, not whether it responds, so the true rate of non-compliance may be higher than our figures. We can also undercount IPv6 support when a zone has more than four nameservers and its IPv6-capable servers fall beyond our limit. Most zones use two or three nameservers, so this error should be small. The full methodology is on the <a href="/faq">FAQ</a>.</p>
<p>Credit where it is due: <a href="https://www.linkedin.com/pulse/rfc-10001-just-made-ipv6-dns-requirement-most-zones-arent-ching-chiao-bblcc/" target="_blank" rel="noopener">Ching Chiao's post</a> highlighted the compliance issue. Its passive DNS measurements found that nearly 40% of the entire namespace could not be resolved over IPv6. That is worse than our result because we only measure the top million domains, where someone is more likely to be paid to maintain the zone.</p>
<p>You can grade your own zone in ten seconds with the <a href="/check">live check</a>. Or use <code>dig AAAA</code> on your NS hostnames and count the answers yourself. You need at least two.</p>
]]></content:encoded>
    </item>
    <item>
      <title>The crawler gets a blog</title>
      <link>https://whynoipv6.com/blog/the-crawler-gets-a-blog</link>
      <guid isPermaLink="true">https://whynoipv6.com/blog/the-crawler-gets-a-blog</guid>
      <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
      <description>The dataset has opinions now. Adoption digests, notable fixes, and whatever the changelog drags in, written up with receipts.</description>
      <content:encoded><![CDATA[<p>Why No IPv6 has crawled the top million domains every day for years and kept the
commentary to one-liners: <a href="/domains">a leaderboard</a>, <a href="/changelog">a changelog</a>,
a rating out of four stars. Some findings don't fit in a table cell. This is
where they go.</p>
<h2>What to expect</h2>
<ul>
<li><strong>Adoption digests.</strong> What moved, what didn't. Mostly what didn't.</li>
<li><strong>Write-ups when a big name changes.</strong> A top-100 domain publishing its first
AAAA record is news. A top-100 domain quietly deleting one is also news, and
considerably funnier.</li>
<li><strong>Country deep dives.</strong> Who leads, who trails, and which national averages
are carried by a single determined ISP.</li>
<li><strong>Methodology notes.</strong> When the crawler learns a new trick, we'll explain
what it checks and why, so the numbers stay arguable on the merits.</li>
</ul>
<p>No release-note filler. If a post exists, the data said something.</p>
<h2>The numbers are frozen on purpose</h2>
<p>Stats in a post are a snapshot from its publish date, and they stay that way.
A sentence someone cites should still be true of the day it was written. The
live figures keep moving on <a href="/metrics">the metrics page</a>, and every post links
back to the pages and the <a href="https://api.whynoipv6.com/docs" target="_blank" rel="noopener">API</a> it was drawn
from, so checking our work is one click.</p>
<h2>Subscribe</h2>
<p>There's an <a href="/blog/rss.xml">RSS feed</a>. No newsletter, no popup. This site
exists to shame people for skipping an open standard; it is not going to skip
the one for syndication.</p>
]]></content:encoded>
    </item>
  </channel>
</rss>
