TLD SLA Compliance Metrics
Spec 10DNS
| Period | Availability | RTT Compliance | RTT p50 | RTT p95 | Checks | TSLAC |
|---|---|---|---|---|---|---|
| 24h | 100% | 100% | 12ms | 21ms | 390 | |
| 7d | 100% | 100% | 12ms | 74ms | 5798 | |
| 30d | 94.52% | 94.52% | 12ms | 74ms | 7674 |
RDAP
| Period | Availability | RTT Compliance | RTT p50 | RTT p95 | Checks | TSLAC |
|---|---|---|---|---|---|---|
| 24h | 100% | 100% | 10ms | 10ms | 16 | |
| 7d | 100% | 100% | 10ms | 17ms | 228 | |
| 30d | 100% | 100% | 15ms | 34ms | 312 |
EPP *
| Period | Availability | RTT Compliance | RTT p50 | RTT p95 | Checks | TSLAC |
|---|---|---|---|---|---|---|
| 24h | 100% | 100% | 43ms | 46ms | 6 | |
| 7d | 100% | 100% | 44ms | 47ms | 60 | |
| 30d | 100% | 100% | 37ms | 40ms | 80 |
DNSSEC Validation Metrics
Registry Agreement Spec 6DNSSEC is required by the Registry Agreement (Specification 6) but is not part of the Spec 10 SLA. We monitor DNSSEC validation independently.
| Period | Validation Rate | RTT p50 | RTT p95 | Checks | Status |
|---|---|---|---|---|---|
| 24h | 100% | 37ms | 38ms | 22 | |
| 7d | 100% | 37ms | 38ms | 258 | |
| 30d | 100% | 37ms | 38ms | 366 |
Unlike Spec 10 services, DNSSEC has no formal availability SLA. Thresholds shown are operational guidelines.
Current Check Status
Reported by Any53 Probes| Type | AF | RTT | Last Check | Source | Details | Status | TSLAC |
|---|---|---|---|---|---|---|---|
DNS
|
v4 | 18ms | 15 hours, 32 minutes ago | local | NSID: nnn1-usnyc-2a | OK | |
DNS
|
v6 | 19ms | 15 hours, 32 minutes ago | local | NSID: nnn1-usnyc-2c | OK | |
DNSSEC
|
v4 | 38ms | 15 hours, 22 minutes ago | local | Key: 37331 | OK | |
DNSSEC
|
v6 | 38ms | 15 hours, 22 minutes ago | local | Key: 37331 | OK | |
EPP *
|
v4 | 44ms | 18 hours, 54 minutes ago | local | Tudor EPP (Mock) v2.0 | OK | |
EPP *
|
v6 | 41ms | 18 hours, 54 minutes ago | local | Tudor EPP (Mock) v2.0 | OK | |
RDAP
|
v4 | 9.8ms | 1 hour, 8 minutes ago | local | TLS 1.3 | OK | |
RDAP
|
v6 | 9.9ms | 1 hour, 8 minutes ago | local | TLS 1.3 | OK |
RDAP HTTPS Timing
9.9ms total
DNS Lookup
—
TCP Connect
1.0ms
TLS Handshake
6.0ms
Time to First Byte
9.0ms
TLS 1.3 / TLS_AES_128_GCM_SHA256
Nameservers
26 IPs tested| Hostname | IP Address | AF | Status |
|---|---|---|---|
a.gtld-servers.net |
192.5.6.30 |
v4 | |
a.gtld-servers.net |
2001:503:a83e::2:30 |
v6 | |
b.gtld-servers.net |
192.33.14.30 |
v4 | |
b.gtld-servers.net |
2001:503:231d::2:30 |
v6 | |
c.gtld-servers.net |
192.26.92.30 |
v4 | |
c.gtld-servers.net |
2001:503:83eb::30 |
v6 | |
d.gtld-servers.net |
192.31.80.30 |
v4 | |
d.gtld-servers.net |
2001:500:856e::30 |
v6 | |
e.gtld-servers.net |
192.12.94.30 |
v4 | |
e.gtld-servers.net |
2001:502:1ca1::30 |
v6 | |
f.gtld-servers.net |
192.35.51.30 |
v4 | |
f.gtld-servers.net |
2001:503:d414::30 |
v6 | |
g.gtld-servers.net |
192.42.93.30 |
v4 | |
g.gtld-servers.net |
2001:503:eea3::30 |
v6 | |
h.gtld-servers.net |
192.54.112.30 |
v4 | |
h.gtld-servers.net |
2001:502:8cc::30 |
v6 | |
i.gtld-servers.net |
192.43.172.30 |
v4 | |
i.gtld-servers.net |
2001:503:39c1::30 |
v6 | |
j.gtld-servers.net |
192.48.79.30 |
v4 | |
j.gtld-servers.net |
2001:502:7094::30 |
v6 | |
k.gtld-servers.net |
192.52.178.30 |
v4 | |
k.gtld-servers.net |
2001:503:d2d::30 |
v6 | |
l.gtld-servers.net |
192.41.162.30 |
v4 | |
l.gtld-servers.net |
2001:500:d937::30 |
v6 | |
m.gtld-servers.net |
192.55.83.30 |
v4 | |
m.gtld-servers.net |
2001:501:b1f9::30 |
v6 |
Per ICANN Spec 10, we test all delegated nameserver IPs independently.
Test With Your Computer
DNS
dig @a.gtld-servers.net net. SOA +dnssec +nsid
Query SOA with DNSSEC validation and NSID
drill -D net. SOA @a.gtld-servers.net
Alternative using drill with DNSSEC trace
RDAP
curl -sS "https://rdap.verisign.com/net/v1/domain/nic.net" | jq .
Fetch RDAP JSON (positive lookup)
curl -I -sS "https://rdap.verisign.com/net/v1/domain/nic.net"
Headers only (check TLS, timing)
Open in Browser
View RDAP response directly
Registry Information
ActiveICANN SLA Requirements
Per ICANN Registry Agreement Specification 10:
DNS SLA
UDP RTT ≤ 500ms for 95% of queries.
Availability: 99% (max 432 min/month downtime).
RDAP SLA
RTT ≤ 4000ms for 95% of queries.
Availability: 98% (max 864 min/month downtime).
EPP SLA
RTT ≤ 4000ms for 95% of commands (Spec 10 §5).
Availability: 98% (max 864 min/month downtime).
(Demo mode)
API Access
JSON APIAccess .net compliance metrics programmatically via our REST API.
Quick Start
GET
/any53/api/v1/compliance/net/
curl -H "X-API-Key: ${YOUR_API_KEY}" \
"https://www.any53.com/any53/api/v1/compliance/net/"
Example Response
{
"tld": "net",
"display_name": ".net",
"operator": "VeriSign, Inc.",
"updated_at": "2026-01-31T12:00:00Z",
"dns": {
"availability_24h": 99.99,
"rtt_p50_ms": 12,
"rtt_p95_ms": 42,
"sla_threshold_ms": 500
},
"rdds": {
"protocol": "RDAP",
"availability_24h": 99.95,
"rtt_p50_ms": 180,
"rtt_p95_ms": 412,
"sla_threshold_ms": 4000
},
"servers": {
"rdap_url": "https://rdap.verisign.com/net/v1/",
"whois_host": "whois.verisign-grs.com"
},
"spec10_compliant": true
}
Generate API Key
Get a free API key to start making requests. Provide an email to upgrade to the verified tier (600 requests/hour).
Save this key now! It cannot be retrieved later.
Tier:
Rate limit: /hour
Endpoints
| Endpoint | Description | Tier |
|---|---|---|
GET /compliance/ |
List all monitored TLDs | All |
GET /compliance/{tld}/ |
Current metrics for a TLD | All |
GET /compliance/{tld}/history/ |
Historical time-series data | Organization |
GET /compliance/{tld}/probes/ |
Per-probe breakdown | Organization |
POST /compliance/keys/ |
Generate a new API key | No auth |
Rate Limits
| Tier | Rate Limit | Features |
|---|---|---|
| Anonymous | 100/hour | Current snapshot, hourly aggregates |
| Verified | 600/hour | Current snapshot, hourly aggregates |
| Organization | 6000/hour | Historical data, per-minute resolution, per-probe breakdown |