09/24/2026 | Press release | Distributed by Public on 09/24/2026 00:07
Cooperation SIG Chair Joy Chan with panellists Sid Mathur, Shailesh Gupta, and Dhruv Dhody.
APNIC 62, held in Mumbai, India, from 4 to 10 September 2026, brought together network operators, researchers, and Internet infrastructure experts from across the Asia Pacific region to discuss operational experience, emerging technologies, and ongoing challenges in Internet operations.
This post covers the Behind the pin: The reality of IP geolocation - Cooperation SIG session, which examined the challenges of determining the geographic location of IP addresses, the role of geofeeds and RIR registration data, the perspectives of network operators and commercial geolocation providers, and the ongoing search for more accurate and privacy-preserving approaches to geolocation.
Geolocation has a long history. The Regional Internet Registry (RIR) Whois and Registration Data Access Protocol (RDAP) services, together with the joint RIR statistics files, provide authoritative information about the entities that hold IP address resources. However, this information is often misunderstood as indicating where IP resources are used, when it actually records where they are registered.
Whois and RDAP have long supported more specific registrations for IPv4 and IPv6 resources. These allow resource holders to assign different ISO 3166 two-letter economy codes to specific prefixes or address ranges within their holdings.
True geolocation relies on additional mechanisms. These include the RFC 8805 format for publishing geographic data and RFC 9632, which provides a standard way to discover that information.
AIORI IP geolocation and geofeed analytics
Anand Raje presented work from the Advanced Internet Operations Research in India (AIORI) project on measuring, validating, and analysing IP geolocation data. The project is developing an IP geolocation, geofeed search, and analytics platform that combines measurement data with published location information.
A central theme was that IP geolocation should be treated as evidence, not certainty. While an IP address can often be linked to an economy, region, or city, it does not necessarily identify a person, device, or exact physical location. Accuracy depends on the data source and how much confidence can be placed in it.
Anand noted that geolocation data supports decisions ranging from content delivery and traffic engineering to fraud detection, compliance, sanctions screening, and public safety. As the impact of these decisions increases, so does the cost of geolocation errors.
The presentation argued that no single technique can reliably determine location. Effective systems combine multiple signals, including registry and routing data, active measurements, machine learning, operator-published geofeeds, and client-provided information. Geolocation quality depends on how these signals are combined and validated.
To support this work, AIORI has deployed around 500 geolocated measurement anchors across India and an anycast testbed spanning more than 10 locations. This infrastructure provides independent evidence for assessing geolocation accuracy.
Another focus was geofeed adoption. Anand Raje observed that deployment in the APNIC region remains well below European levels. Most published geofeed prefixes currently originate outside the Asia Pacific region.
Analysis of geofeed data showed wide variation in geographic precision. Many records provide city-level information, while relatively few include street-level detail. This reflects both the limits of geolocation and efforts to protect user privacy.
The presentation asked three questions of the community:
These questions reinforced a broader theme of the session - the need for greater transparency, accountability, and trust in geolocation systems.
IP geolocation IAB workshop report
Dhruv Dhody presented findings from the Internet Architecture Board (IAB) workshop held in late 2025. The workshop provides a useful overview of the Internet Engineering Task Force (IETF) perspective on the problem space, current mechanisms, and remaining gaps.
As the presentation noted: "IP addresses were not designed to carry geographic meaning … but geolocating IP addresses is a widespread practice that has become ingrained into many functions of the web and Internet today."
IP addresses are geography-neutral identifiers whose primary purpose is to provide unique addressing within Internet Protocol networks.
These identifiers are carried in packets and routed using protocols such as Border Gateway Protocol (BGP), Open Shortest Path First (OSPF), and Intermediate System to Intermediate System (IS-IS). Over time, however, they have become closely associated with real-world questions about location. Governments, businesses, researchers, and users increasingly want to know where traffic originates and where it is destined in a geographic sense.
There is growing pressure to improve geolocation technologies. Existing approaches are under increasing strain as Internet connectivity becomes more dynamic.
Low Earth Orbit (LEO) satellite networks, multinational mobile providers, and highly distributed service architectures all make location mapping more difficult. In many cases, users move between networks while application sessions remain active.
At the same time, regulatory, commercial, and social demands for location information continue to increase. Future geolocation systems will need to improve accuracy while protecting user privacy.
Self-published geofeeds: The role of RIRs
Sid Mathur spoke on the Cooperation SIG panel and later in Tech Session 2 (AI), where he discussed the geofeed publication and discovery mechanisms defined in RFC 8805 and RFC 9632. He also demonstrated how AI tools can improve data quality by identifying inconsistencies and helping proofread published geofeed data.
Sid suggested RIRs occupy a unique position in the geolocation ecosystem because they already operate the authoritative registration systems used to identify resource holders. Rather than creating new processes, he argued that the existing registry framework could provide a trusted foundation for geolocation publication. Geofeed publication builds on workflows operators already understand, creates a verifiable chain of trust through RFC 9632, and represents a high-leverage opportunity to increase awareness and adoption.
His data also highlighted significant differences in geofeed adoption between regions. Using a sample of geolocation records associated with Whois-discoverable networks, he found that 75.5% of successful geofeed publishers were in the RIPE NCC region, compared with 21.6% in the ARIN region and 3.0% in the APNIC region.
To help address this gap, Sid called for more consistent support from all RIRs. He pointed to RFC 9877, co-authored by APNIC and ARIN and published in October 2025, as an existing mechanism that could simplify deployment. His main recommendation was straightforward: Make geofeed publication a one-click function within Member portals and registry dashboards. He noted that an informal APNIC community survey found that uncertainty about how registries could help was one of the main barriers to adoption.
IP geolocation
Shailesh Gupta presented an ISP perspective on the problem space. He highlighted the role of six major geolocation providers that combine RIR data and geofeed information with their own datasets and methodologies.
As a result, organizations that need to correct geolocation errors often face multiple reporting and remediation processes. Challenges already exist within self-published geofeeds and RIR registration data. Additional processing by downstream providers can further increase complexity.
One point Shailesh emphasized was that geofeeds should be viewed as a best-effort mechanism. Their accuracy is influenced by many factors, including data sources, update cycles, VPN usage, and changing network deployment practices.
In many cases, geolocation information is intentionally approximate. For privacy reasons, location data may identify only a state or city rather than a precise location. In other cases, the information may be inaccurate because network assignments and usage patterns change over time.
An ISO 3166 CC can often be considered reasonably reliable. Accuracy generally decreases at state and sub-regional levels and falls further at the city, suburb, and street levels as network management practices become more complex and less closely aligned with geographic boundaries.
Shailesh highlighted another challenge during the AI session: Place-name ambiguity. Names such as Frankfurt or Kendal can refer to multiple locations. Frankfurt alone may refer to several distinct places in Germany, while Kendal exists in Indonesia, South Africa, Canada, Jamaica, and England.
This creates data-quality issues that cannot always be resolved by updating a geofeed. The underlying problem may instead be how a geolocation provider interprets place names and maps them to network data.
The issue becomes even more complex for multinational providers, where the parent economy code may not accurately reflect where a service is delivered. When third-party geolocation providers are involved, correction processes, reporting mechanisms, and response times can vary significantly. Compliance obligations and accountability also remain unresolved.
IP geolocation as a data provider
Luna, product owner for GeoIP services at MaxMind, provided the perspective of a third-party data integrator.
Self-published geolocation data and RIR registration records represent only one category of information used by organizations such as MaxMind to determine where IP resources are being used. MaxMind combines multiple data sources, including BGP relationships, network usage patterns, browser-derived signals, and other operational datasets. Location determinations are therefore based on a combination of inputs rather than a single authoritative source.
This raises an important question: what constitutes the ground truth for geolocation?
The answer may vary depending on the stakeholder. End users, content providers, and ISPs may all have different expectations about what the question 'where is this IP address?' actually means. As a result, different geolocation systems may produce different answers from the same underlying data.
Luna also noted significant regional differences in both the volume and quality of geolocation data. The United States and Europe generate the largest volumes of geolocation data and account for most customer feedback and data-quality interactions. As a result, commercial geolocation providers tend to focus greater attention on those regions.
By contrast, adoption of geofeeds and related mechanisms remains lower across parts of Asia Pacific, Africa, and Latin America. This can affect the quality and consistency of geolocation outcomes in those regions.
However, Luna highlighted improvements in the ways network operators can engage with MaxMind. She outlined practical approaches that Asia Pacific ISPs can use to improve data quality, streamline updates, and increase geolocation accuracy over time.
Looking ahead
The session highlighted that IP geolocation is no longer a simple mapping problem. As Internet infrastructure becomes more distributed through cloud services, mobile networks, anycast deployments, and satellite connectivity, determining location accurately now requires multiple sources of data. These include authoritative registration records, self-published geofeeds, measurement-based evidence, and commercial datasets.
Speakers broadly agreed that the geolocation ecosystem needs greater transparency, verifiability, and collaboration. Wider geofeed adoption, stronger data quality processes, and clearer mechanisms for correcting errors could improve accuracy and trust while helping to protect user privacy.
The discussion also reinforced that geolocation should be viewed as a confidence-based assessment rather than a source of absolute truth. Future progress will depend on balancing operational, commercial, regulatory, and privacy requirements. It will also require location data to remain explainable, contestable, and fit for purpose.
Watch the full session recording:
The views expressed by the authors of this blog are their own and do not necessarily reflect the views of APNIC. Please note a Code of Conduct applies to this blog.