bgpmap

How this tool works

Methodology & terminology

This looking-glass is built to be cited. Every result is a snapshot you can link to, and this page explains exactly how that snapshot is produced — so you can trust it, or check it yourself.

Where the data comes from

Paths come from RIPE RIS, the RIPE NCC's Routing Information Service. Instead of one router's view, a query aggregates what hundreds of public peers across dozens of route collectors are seeing, retrieved through the RIPEstat looking-glass. Every result states its source, the number of peers and collectors it rests on, and the UTC timestamp of the data.

The red line: Most Observed AS-PATH

There is no single “best path” on the global internet. Each router picks its own according to local policy, and two routers inside the same network can disagree. So the red line here is not a best path. It is the Most Observed AS-PATH: the exact complete path that the largest number of peers actually reported. It is a real path present in the data, not a route stitched together from individually popular hops.

How paths are normalized

When a network repeats its own AS number to make a path look longer (AS prepending), the repeats are collapsed so the graph stays readable — but the prepend count is kept in the stored snapshot. Paths containing AS23456 (AS_TRANS), the placeholder older routers use in place of 32-bit AS numbers, are flagged rather than quietly dropped.

AS names

AS names come from RIPEstat. The graph shows a short organization name for readability; the full registered name, including the NIC handle where one exists, appears in the Evidence panel and is kept in the snapshot.

RPKI origin validation

The RPKI state — valid, invalid, or unknown — is the Route Origin Validation result from RIPEstat, comparing the observed origin AS against the prefix's published ROAs. invalid is reported with its reason: a mismatched ASN, or a prefix longer than the ROA's maximum length. Every result links back to RIPEstat so you can confirm it independently.

Multiple origins (MOAS)

If more than one AS is seen originating the same prefix, the result is flagged MOAS. That happens legitimately with anycast, multi-homed networks, and migrations — and it is also the signature of a hijack. The tool reports the condition and leaves the judgement to you.

Nothing is hidden

When a hostname resolves to several addresses, or an AS announces many prefixes, all of them are listed; the tool never silently picks one. A network announcing thousands of prefixes gets a paged, filterable list rather than a truncated one, and the page states the total. Busy graphs omit the rarest edges for legibility, and when that happens the result says how many were left out and what the peer threshold was. The complete raw upstream response behind every snapshot is stored unchanged and is reachable at /api/v1/snapshot/{id}?view=raw.

Limits worth knowing

RIS data is near-real-time, with a short processing delay. Low-visibility announcements that few peers see may not appear at all. A looking-glass shows the control plane — what is announced — which is not always the same as the data plane, where the packets actually go.

Data: RIPE RIS, retrieved through RIPEstat.