viabandwidth

Product documentation

What the Network Evidence Report contains

One address block, $299, delivered as a branded PDF within five business days. Seven sections, listed here in full, with what each contains and what it cannot tell you.

Want to see it before you buy? View sample (fictional company, for demonstration only)

Read this before you buy

This is point-in-time analysis. It is not routing history.

We hold no BGP time series, so this report cannot tell you:

  • when a block was first announced
  • whether its origin network has changed
  • whether it has ever been hijacked
  • any announcement or origin chronology

What it does give you is what the block looks like now, examined at address level: who holds the pieces, what actually resolves, and where the registry, the delegation records and the observed naming disagree. If you need routing history, this is not the product, and we would rather you knew that here than after paying.

The deliverable

A block, examined address by address

The subject is a CIDR block, not a company. You can bring a prefix we have never listed an operator for. That is what separates this from the operator products: they look at an organisation, this looks down into one network.

An analyst researches it from our own address-level records rather than the published summaries, and writes it up. Five business days, delivered to your account library.

Contents

The seven sections, in full

01

Block identity and registry position

What the block is and where it sits: the exact CIDR examined, which registry holds the record, the registered holder, the country on record, and the block's position in the address hierarchy including its parent and any children.

Example evidence — 203.0.113.0/24 · RIPE · registered holder “Example Networks B.V.” · sits inside 203.0.112.0/22 · two more-specifics observed

Always present.

02

Sub-allocation and delegation map

Who holds the pieces inside the block on paper: registry-recorded reassignments, the organisations each is recorded to, their sizes and ranges, and how much of the block those records actually account for.

Example evidence — Nine recorded sub-assignments covering 61% of the block · largest is a /26 to a hosting company · 39% carries no assignment record

Conditional. Coverage is uneven between registries. Where nothing is recorded we say so, and that absence is itself informative: a heavily used block with no recorded assignments reads differently from one carefully documented.

03

Routing structure, current state

How the block is routed right now: whether it is announced, which network originates it, the more-specifics announced inside it, and how finely the routing is subdivided.

Example evidence — Announced by AS64500 · three more-specifics, all /26 · the remainder is not separately announced

Always present, and explicitly current-state only. See the limitation below.

04

Per-IP resolution census and occupancy map

The block read address by address rather than as a summary: how many individual addresses resolve, where the dense, sparse and empty regions are, how large the contiguous unused stretches are, and whether naming looks bulk-generated or individually assigned.

Example evidence — 142 of 256 addresses resolve · the lower half is densely named with sequential host records · .128 to .191 is entirely unnamed · the top /26 names under a different parent domain

Always present. “No address in this block resolves” is a complete and useful finding, not a failure. This is computed from underlying per-address records and cannot be reconstructed from any summary we publish.

05

Registered versus delegated versus observed naming

The three records compared: who the registry says holds the block, who it has been delegated to on paper, and whose naming the addresses actually carry — plus what the naming convention says about how the space is run.

Example evidence — All resolving addresses in the lower half name under one hosting company's domain, which is not the registered holder in section 01 · the upper /26 names under a third party again

Conditional on addresses resolving. The divergence is the most valuable output here: a block registered to one party, delegated to a second and named by a third is a finding no summary product produces.

06

Analyst read on this block

What the block appears to be and how it appears to be used: single tenant, multi-tenant, infrastructure, dormant or mixed; where the three records disagree; what to verify and with whom; and what evidence would change the reading.

Example evidence — “Registered to a Dutch entity, delegated in nine pieces, and named almost entirely by one hosting operator. Confirm who you would actually be contracting with.”

Always present. A judgment, labelled as one. No score, no rating, no ranking, and no “health” figure.

07

Provenance and limits

Every source named with its vintage, the observation dates behind the census, what was searched and not found, and the limits below printed in full.

Example evidence — Sources, dates, and the explicit list of what this report does not establish

Always present.

How it differs

Against the free prefix lookup

Our free prefix lookup gives you the summary for a block: whether it is announced, its coverage percentage, cluster counts, a handful of sample hostnames. That stays free, and it appears inside this report as baseline evidence.

What you are paying for is everything the summary cannot contain: the delegation records, the address-by-address census and occupancy map, the comparison between registered, delegated and observed naming, and a written read on what it all means. If a report could be assembled from the free lookup, we would not sell it.

Before you buy

We check there is a report worth writing

If we hold nothing for the block or any parent, the order is refused before you are charged. Beyond that, an analyst confirms there is real content to write: a block with no delegation records and no resolving addresses cannot support this report, and will not be sold one. Where that only becomes clear after payment, you are refunded in full.

Limitations

What it does not tell you

  • Registry records describe paper, not practice. The registered holder and the party actually operating the block can be different, and organisation names collide.
  • Reassignment coverage is uneven between registries, and reflects what the holder chose to register rather than how the space is really used.
  • Reverse DNS is evidence of naming, not of traffic, ownership or occupancy. An address can be in heavy use with no name, or named and idle.
  • Observations are dated. Address space is reassigned and renamed, and the report states when it was measured.
  • Nothing here establishes that space is unused, available, transferable, or authorised for any transaction.
  • If the block cannot support a useful report, we say so and refund rather than deliver a thin one.

Order a report on any block we hold.

Enter the CIDR or an address inside it. If we cannot research it, you are told before any charge.