IP Dekho Research

Network Research & Threat Intelligence

Summaries of what public sources such as APNIC, RIPE NCC, and Spamhaus show about IPv6 adoption, DNS security, VPN and proxy use, and ISP routing.

Total IPv4 Address Space
4,294,967,296
Google Users on IPv6 (Mar 2026)
50%
Active Routed BGP ASNs
78,410
Regional Internet Registries
5

Research Summaries

June 20266 min read

Internet Security & Threat Trends 2026: A Research Summary

This summary pulls together what public threat-intelligence and abuse-reporting sources describe about automated scanning and credential-stuffing in 2025–2026. The clearest trend is a shift in where attack traffic comes from. Blocking known hosting-provider networks used to stop a large share of scanning and login abuse. Attackers now increasingly route that traffic through residential proxy networks and mobile carrier networks behind Carrier-Grade NAT, so it looks like ordinary household or mobile use. Many of those residential exit points are compromised home devices (routers, IP cameras, NAS boxes) running default passwords or unpatched firmware. The practical result is that IP blocklists and hosting-network blocks catch less than they used to, and defenders need signals beyond the IP address.

  • Traffic is moving to residential IPs: public reporting on credential stuffing and bot abuse describes a steady move from datacenter IP ranges to residential proxy networks, which are much harder to block without affecting real users.
  • Hosting networks still matter: large-scale SSH and service scanning continues to come from rented cloud and VPS servers, so hosting-network signals remain useful even if they’re no longer enough on their own.
  • Mobile CGNAT is a blind spot: many subscribers share each public IP on mobile networks, so blocking one address can lock out large numbers of legitimate users. Attackers exploit exactly that reluctance to block.
June 20266 min read

Global IPv6 Adoption in 2026: A Research Summary

IPv6 crossed a milestone in 2026: on 28 March, more than half of users reaching Google did so over IPv6 (50.10%), according to APNIC. APNIC’s own measurement, which uses a different method, puts worldwide IPv6 capability at around 42%, and the two figures together bracket the likely range. Adoption is very uneven. The Internet Society lists France (73%) and India (72%) among the leaders, while countries such as Italy (17%) and Spain (10%) lag far behind. This summary looks at why adoption varies and at the routing and configuration problems that can make IPv6 connections perform worse than IPv4 even where both are available.

  • A majority milestone: over 50% of Google users reached it over IPv6 by March 2026, though measurements differ by method, and APNIC’s capability figure is lower (about 42%).
  • Mobile networks lead: large mobile operators have moved to IPv6-only cores and translate to IPv4 at the edge (NAT64/464XLAT), which drives much of the growth in countries like India.
  • Enterprise networks lag: corporate networks move more slowly because of legacy applications, firewalls and monitoring that assume IPv4.
July 20266 min read

VPN & Residential Proxy Trends 2026: A Research Summary

This summary looks at two kinds of traffic that hide a user’s real IP address: commercial VPNs and residential proxy networks. They are often lumped together but are used very differently. VPNs are mostly used by people for privacy on public Wi-Fi, to keep browsing from their ISP, or to reach content from another region. Residential proxy networks rent out real household IP addresses, and while some uses are legitimate (ad verification, price monitoring), they are also a favourite tool for scraping, scalping and credential stuffing, because traffic from a home IP is hard to block. This summary covers how residential proxy pools are built, why they matter to anyone running a login or checkout, and the signals administrators can use to spot them.

  • Different tools, different users: commercial VPN traffic comes from a relatively small set of datacenter IP ranges that are easy to identify; residential proxy traffic comes from millions of ordinary home connections.
  • Proxy pools are often built through apps: many residential proxy networks recruit IPs through bandwidth-sharing SDKs bundled with free apps and browser extensions, sometimes with little meaningful consent from the device owner.
  • Bots rely on residential IPs to beat purchase limits: scalping and inventory-hoarding bots rotate through residential addresses so each purchase appears to come from a different household.
May 20266 min read

DNS Security Trends 2026: A Research Summary

The Domain Name System (DNS) underpins almost everything online, and much of it still runs without the protections that exist for it. The DNS root and most top-level domains are signed with DNSSEC, but signing at the level of individual domains remains low, especially for .com. Email authentication has improved, driven by Google and Yahoo requiring SPF, DKIM and DMARC for bulk senders since 2024, but many domains still publish no DMARC policy or one that only monitors. This summary explains what those gaps expose domains to — cache poisoning, spoofed email, slow failover — and what domain owners can do about each one.

  • DNSSEC is signed at the top, rarely below: the root zone and most TLDs are signed, but only a small share of second-level domains are, so most lookups still can’t be validated end to end.
  • Email authentication is uneven: bulk-sender requirements pushed many large senders to adopt DMARC, but a policy of “p=none” only reports spoofing — it doesn’t stop it.
  • Long TTLs slow recovery: records cached for a day or more mean a changed IP or failover can take that long to reach every user.
July 20266 min read

ISP Routing & Peering in 2026: A Research Summary

The route your traffic takes between networks affects speed and reliability as much as your connection does. This summary looks at how large transit carriers, internet exchanges and content networks interconnect, why BGP route leaks and hijacks still cause outages, and how RPKI is being used to prevent them. It also covers the growing share of traffic that never touches the traditional transit “backbone” because content delivery networks now connect directly to consumer ISPs.

  • Route leaks and hijacks still happen: misconfigured or malicious BGP announcements continue to cause outages and misrouted traffic, as covered in our explainer on how BGP works.
  • RPKI adoption is growing but incomplete: more networks sign their routes and filter invalid ones, but networks that don’t validate can still spread bad routes. Current coverage is published on NIST’s RPKI Monitor.
  • Content moves closer to users: large CDNs and cloud providers peer directly with ISPs and place caches inside ISP networks, so much everyday traffic stays local.

Frequently Asked Questions

Find detailed answers to common inquiries about IP addressing, autonomous system mapping, BGP routing anomalies, and domain zone security protocols.

Get New Research by Email

Join the IP Dekho newsletter to hear when we publish new reports and guides. You can unsubscribe at any time.