How this tool works
Methodology & terminology
This looking-glass is built to be cited. Every result is a snapshot you can link to, and this page explains exactly how that snapshot is produced — so you can trust it, or check it yourself.
Where the data comes from
Paths come from RIPE RIS, the RIPE NCC's Routing Information Service. Instead of one router's view, a query aggregates what hundreds of public peers across dozens of route collectors are seeing, retrieved through the RIPEstat looking-glass. Every result states its source, the number of peers and collectors it rests on, and the UTC timestamp of the data.
The red line: Most Observed AS-PATH
There is no single “best path” on the global internet. Each router picks its own according to local policy, and two routers inside the same network can disagree. So the red line here is not a best path. It is the Most Observed AS-PATH: the exact complete path that the largest number of peers actually reported. It is a real path present in the data, not a route stitched together from individually popular hops.
How paths are normalized
When a network repeats its own AS number to make a path look longer (AS prepending), the
repeats are collapsed so the graph stays readable — but the prepend count is kept in
the stored snapshot. Paths containing AS23456 (AS_TRANS), the placeholder
older routers use in place of 32-bit AS numbers, are flagged rather than quietly dropped.
AS names
AS names come from RIPEstat. The graph shows a short organization name for readability; the full registered name, including the NIC handle where one exists, appears in the Evidence panel and is kept in the snapshot.
RPKI origin validation
The RPKI state — valid, invalid, or unknown — is the Route Origin Validation
result from RIPEstat, comparing the observed origin AS against the prefix's published
ROAs. invalid is reported with its reason: a mismatched ASN, or a prefix
longer than the ROA's maximum length. Every result links back to RIPEstat so you can
confirm it independently.
Multiple origins (MOAS)
If more than one AS is seen originating the same prefix, the result is flagged MOAS. That happens legitimately with anycast, multi-homed networks, and migrations — and it is also the signature of a hijack. The tool reports the condition and leaves the judgement to you.
Nothing is hidden
When a hostname resolves to several addresses, or an AS announces many prefixes, all of
them are listed; the tool never silently picks one. A network announcing thousands of
prefixes gets a paged, filterable list rather than a truncated one, and the page states
the total. Busy graphs omit the rarest edges for legibility, and when that happens the
result says how many were left out and what the peer threshold was. The complete raw
upstream response behind every snapshot is stored unchanged and is reachable at
/api/v1/snapshot/{id}?view=raw.
Limits worth knowing
RIS data is near-real-time, with a short processing delay. Low-visibility announcements that few peers see may not appear at all. A looking-glass shows the control plane — what is announced — which is not always the same as the data plane, where the packets actually go.
Data: RIPE RIS, retrieved through RIPEstat.