The global Internet infrastructure community gathered in Mumbai, India, from September 4 to 10, 2026, for the APNIC 62 conference. Bringing together network operators, researchers, and technical experts from across the Asia Pacific region, the event served as a vital forum for discussing operational experiences, emerging technologies, and ongoing challenges in modern Internet operations. Among the technical sessions, a prominent highlight was the Cooperation Special Interest Group (SIG) session titled "Behind the pin: The reality of IP geolocation." Chaired by Joy Chan, the session featured a panel of experts including Sid Mathur, Shailesh Gupta, and Dhruv Dhody, who examined the persistent hurdles of determining the geographic location of IP addresses, the function of geofeeds and Regional Internet Registry (RIR) data, and the search for more accurate and privacy-preserving methodologies.
Geolocation has a long operational history on the Internet. Traditionally, RIR Whois and Registration Data Access Protocol (RDAP) services, alongside joint RIR statistics files, have provided authoritative data regarding the entities that hold IP address resources. However, this information is frequently misinterpreted as indicating the physical location where IP resources are deployed, when it actually records where they are legally registered. While Whois and RDAP have long supported specific registrations for IPv4 and IPv6 resources—permitting resource holders to assign different ISO 3166 two-letter economy codes to particular prefixes or address ranges—true geolocation relies on supplementary mechanisms. These include RFC 8805, which provides a standard format for publishing geographic data, and RFC 9632, which establishes a discovery mechanism for that information.
AIORI IP Geolocation and Geofeed Analytics
During the session, Anand Raje presented findings from the Advanced Internet Operations Research in India (AIORI) project, focusing on the measurement, validation, and analysis of IP geolocation data. The project is actively developing an IP geolocation, geofeed search, and analytics platform designed to merge active measurement data with published location information. A central theme of the presentation was that IP geolocation should consistently be treated as evidence rather than absolute certainty. Although an IP address can frequently be linked to an economy, region, or city, it does not inherently identify a specific individual, device, or precise physical location. The overall accuracy relies heavily on the underlying data source and the degree of confidence assigned to it.
Raje noted that geolocation data supports a wide spectrum of operational and business decisions, ranging from content delivery and traffic engineering to fraud detection, regulatory compliance, sanctions screening, and public safety. As the real-world impact of these decisions grows, the cost of geolocation errors increases proportionally. The presentation argued that no single technique can reliably determine location on its own. Instead, effective systems must combine multiple signals, including registry and routing data, active measurements, machine learning models, operator-published geofeeds, and client-provided information. The overall quality of geolocation ultimately depends on how skillfully these disparate signals are combined and validated.
To bolster this research infrastructure, AIORI has deployed approximately 500 geolocated measurement anchors across India, alongside an anycast testbed spanning more than 10 locations. This infrastructure provides independent empirical evidence for assessing geolocation accuracy. Despite these advancements, the presentation drew attention to low geofeed adoption rates within the APNIC region, which remain significantly below European levels. Most published geofeed prefixes continue to originate outside the Asia Pacific region. Furthermore, an analysis of existing geofeed data revealed a wide variation in geographic precision; while many records offer city-level insights, relatively few provide street-level detail, reflecting both the inherent limits of IP geolocation and deliberate efforts to protect user privacy.
IP Geolocation IAB Workshop Report
Expanding on the broader standards landscape, Dhruv Dhody presented findings from an Internet Architecture Board (IAB) workshop held in late 2025. The workshop offered a comprehensive overview of the Internet Engineering Task Force (IETF) perspective on the problem space, detailing current mechanisms and remaining technical gaps. As Dhody emphasized during his presentation, IP addresses were never originally designed to carry geographic meaning, yet geolocating them has become a deeply ingrained practice underpinning numerous functions of the modern web.
IP addresses function primarily as geography-neutral identifiers intended to provide unique addressing within Internet Protocol networks. Carried within packets, these identifiers are routed across networks using protocols such as Border Gateway Protocol (BGP), Open Shortest Path First (OSPF), and Intermediate System to Intermediate System (IS-IS). Over time, however, they have become closely tied to real-world inquiries regarding the geographic origin and destination of data traffic. Governments, commercial enterprises, researchers, and end users increasingly expect precise visibility into traffic locations. Consequently, existing geolocation approaches face mounting pressure as network connectivity grows increasingly dynamic. Technologies such as Low Earth Orbit (LEO) satellite networks, multinational mobile providers, and highly distributed service architectures complicate location mapping, often causing users to roam across networks while application sessions remain active. Concurrently, regulatory, commercial, and societal demands for location data continue to escalate, mandating that future geolocation architectures enhance accuracy while safeguarding user privacy.
Self-Published Geofeeds: The Role of RIRs

Addressing the mechanics of self-published data, Sid Mathur spoke during both the Cooperation SIG panel and Tech Session 2, discussing the geofeed publication and discovery frameworks defined in RFC 8805 and RFC 9632. He also demonstrated how artificial intelligence tools can enhance data quality by identifying inconsistencies and proofreading published geofeed datasets. Mathur proposed that RIRs occupy a unique and advantageous position within the geolocation ecosystem because they already operate the authoritative registration systems used to identify resource holders. Rather than inventing entirely new administrative processes, he argued that existing registry frameworks could provide a trusted foundation for geolocation publication. This approach builds directly upon familiar operator workflows, establishes a verifiable chain of trust through RFC 9632, and presents a high-leverage opportunity to drive industry-wide awareness and adoption.
Mathur’s data underscored striking regional disparities in geofeed adoption. Examining a sample of geolocation records associated with Whois-discoverable networks, he found that 75.5% of successful geofeed publishers operated within the RIPE NCC region, compared to 21.6% in the ARIN region and just 3.0% in the APNIC region. To bridge this divide, Mathur called for more consistent, uniform support across all RIRs, pointing to RFC 9877—co-authored by APNIC and ARIN and published in October 2025—as an existing mechanism capable of simplifying deployment. His primary recommendation was straightforward: integrate geofeed publication as a seamless, one-click function within member portals and registry dashboards. He noted that an informal APNIC community survey identified uncertainty regarding registry assistance as a primary barrier to wider adoption.
Providing an ISP perspective on the same challenges, Shailesh Gupta focused on the operational hurdles created by the ecosystem of major geolocation providers. These commercial entities typically combine RIR registration records and self-published geofeeds with their own proprietary datasets and methodologies. Consequently, organizations seeking to correct geolocation errors often find themselves navigating complex, fragmented reporting and remediation workflows across multiple downstream providers, compounding the administrative burden.
Gupta emphasized that geofeeds should be understood as a best-effort mechanism whose accuracy is susceptible to diverse factors, including data sources, update frequencies, VPN usage, and evolving network deployment practices. In many instances, geolocation information is intentionally kept approximate for privacy reasons, identifying only a state or city rather than exact coordinates. In other cases, inaccuracies emerge simply because network assignments and usage patterns shift dynamically over time. While an ISO 3166 country code is frequently reliable, accuracy tends to degrade at state and sub-regional levels, falling off further at city, suburb, and street levels as network management practices diverge from geographic boundaries.
Furthermore, Gupta highlighted the persistent complication of place-name ambiguity. Names such as Frankfurt or Kendal can refer to multiple distinct locations globally, generating data-quality issues that cannot always be resolved merely by updating a geofeed. The root problem often lies in how a third-party geolocation provider interprets place names and maps them against underlying network data. For multinational providers, parent economy codes may fail to reflect the actual location where a service is delivered, and differing response times and compliance obligations among vendors further complicate the landscape.
IP Geolocation as a Data Provider
Offering the perspective of a commercial data integrator, Luna, product owner for GeoIP services at MaxMind, detailed how third-party providers approach the challenge. Self-published geofeeds and RIR registration records constitute only one category of information utilized by organizations like MaxMind to determine the real-world usage of IP resources. MaxMind integrates a diverse array of data inputs, including BGP relationships, network usage patterns, browser-derived signals, and other operational telemetry, meaning location determinations rely on a synthesis of signals rather than a single authoritative source.
This methodology introduces a fundamental question: what constitutes the true ground truth for geolocation? The appropriate answer can vary widely depending on the stakeholder, as end users, content providers, and ISPs often maintain differing expectations of what a location query actually implies. Consequently, distinct geolocation systems may yield divergent answers derived from identical underlying data. Luna also pointed out significant regional asymmetries in data volume and quality, noting that the United States and Europe generate the highest volumes of geolocation data and customer feedback, prompting commercial providers to concentrate greater resources there. Conversely, lower adoption of geofeeds across parts of Asia Pacific, Africa, and Latin America can impact the consistency of geolocation outcomes in those areas. Nonetheless, she highlighted ongoing improvements in engagement channels for network operators in the Asia Pacific region, outlining practical steps ISPs can take to enhance data quality and streamline updates over time.
Looking Ahead
The sessions at APNIC 62 collectively underscored that IP geolocation is no longer a straightforward mapping exercise. As Internet infrastructure grows increasingly distributed through cloud services, mobile networks, anycast deployments, and satellite connectivity, achieving accurate location determination demands a multi-faceted approach incorporating authoritative registration records, self-published geofeeds, empirical measurement data, and commercial datasets.
Participants reached a broad consensus that the geolocation ecosystem requires enhanced transparency, verifiability, and cross-sector collaboration. Broader geofeed adoption, more rigorous data quality processes, and clearer remediation mechanisms for correcting errors are essential to improving accuracy and reinforcing trust while respecting user privacy. Ultimately, the discussions reinforced that IP geolocation must be regarded as a confidence-based assessment rather than an absolute source of truth, with future progress depending on a careful balance between operational, commercial, regulatory, and privacy imperatives.
Leave a Reply