.nrw

TLD SLA Compliance Monitoring

TLD SLA Compliance Metrics

Spec 10

DNS

Period Availability RTT Compliance RTT p50 RTT p95 Checks TSLAC
24h 100% 100% 32ms 1806ms 400
7d 100% 100% 29ms 1839ms 2160
30d 100% 100% 29ms 1868ms 12016

RDAP

Period Availability RTT Compliance RTT p50 RTT p95 Checks TSLAC
24h 95.00% 90.00% 334ms 2334ms 20
7d 100% 100% 332ms 506ms 120
30d 100% 99.70% 368ms 680ms 672

DNSSEC Validation Metrics

Registry Agreement Spec 6

DNSSEC is required by the Registry Agreement (Specification 6) but is not part of the Spec 10 SLA. We monitor DNSSEC validation independently.

Period Validation Rate RTT p50 RTT p95 Checks Status
24h 100% 116ms 118ms 30
7d 100% 119ms 146ms 150
30d 95.81% 188ms 442ms 836

Unlike Spec 10 services, DNSSEC has no formal availability SLA. Thresholds shown are operational guidelines.

Current Check Status

Reported by Any53 Probes
Type AF RTT Last Check Source Details Status TSLAC
DNS v4 12ms 1 minute ago local NSID: dns2.cator1 OK
DNS v6 1.6ms 55 days, 13 hours ago local NSID: dns1.uschi1 OK
DNSSEC v4 5000ms 52 minutes ago local FAIL
DNSSEC v6 117ms 52 minutes ago local Key: 61012 OK
RDAP v4 303ms 3 hours, 57 minutes ago local TLS 1.3 OK
RDAP v6 316ms 3 hours, 57 minutes ago local TLS 1.3 OK

RDAP HTTPS Timing

316ms total
DNS Lookup
TCP Connect
103ms
TLS Handshake
106ms
Time to First Byte
315ms

TLS 1.3 / TLS_AES_128_GCM_SHA256

Nameservers

8 IPs tested
Hostname IP Address AF ASN RPKI Status
anycast10.irondns.net 195.253.64.12 v4 AS8561
anycast23.irondns.net 195.253.65.11 v4 AS50611
anycast24.irondns.net 195.253.65.12 v4 AS50611
anycast9.irondns.net 195.253.64.11 v4 AS8561
ari.alpha.tldns.godaddy 37.209.192.2 v4
ari.beta.tldns.godaddy 37.209.194.2 v4
ari.delta.tldns.godaddy 37.209.198.2 v4
ari.gamma.tldns.godaddy 37.209.196.2 v4

Per ICANN Spec 10, we test all delegated nameserver IPs independently.

Test With Your Computer

DNS

dig @anycast10.irondns.net nrw. SOA +dnssec +nsid Query SOA with DNSSEC validation and NSID
drill -D nrw. SOA @anycast10.irondns.net Alternative using drill with DNSSEC trace

RDAP

curl -sS "https://rdap.nic.nrw/domain/nic.nrw" | jq . Fetch RDAP JSON (positive lookup)
curl -I -sS "https://rdap.nic.nrw/domain/nic.nrw" Headers only (check TLS, timing)
Open in Browser View RDAP response directly

Registry Information

Active
TLD .nrw
Operator Minds + Machines GmbH
RDAP Server https://rdap.nic.nrw/ RDAP Client

ICANN SLA Requirements

Per ICANN Registry Agreement Specification 10:

DNS SLA UDP RTT ≤ 500ms for 95% of queries. Availability: 99% (max 432 min/month downtime).
RDAP SLA RTT ≤ 4000ms for 95% of queries. Availability: 98% (max 864 min/month downtime).

API Access

JSON API

Access .nrw compliance metrics programmatically via our REST API.

Quick Start

GET /any53/api/v1/compliance/nrw/
curl -H "X-API-Key: ${YOUR_API_KEY}" \
  "https://www.any53.com/any53/api/v1/compliance/nrw/"

Example Response

{
  "tld": "nrw",
  "display_name": ".nrw",
  "operator": "Minds + Machines GmbH",
  "updated_at": "2026-01-31T12:00:00Z",
  "dns": {
    "availability_24h": 99.99,
    "rtt_p50_ms": 12,
    "rtt_p95_ms": 42,
    "sla_threshold_ms": 500
  },
  "rdds": {
    "protocol": "RDAP",
    "availability_24h": 99.95,
    "rtt_p50_ms": 180,
    "rtt_p95_ms": 412,
    "sla_threshold_ms": 4000
  },
  "servers": {
    "rdap_url": "https://rdap.nic.nrw/"
  },
  "spec10_compliant": true
}

Generate API Key

Get a free API key to start making requests. Provide an email to upgrade to the verified tier (600 requests/hour).

Endpoints

Endpoint Description Tier
GET /compliance/ List all monitored TLDs All
GET /compliance/{tld}/ Current metrics for a TLD All
GET /compliance/{tld}/history/ Historical time-series data Organization
GET /compliance/{tld}/probes/ Per-probe breakdown Organization
POST /compliance/keys/ Generate a new API key No auth

Rate Limits

Tier Rate Limit Features
Anonymous 100/hour Current snapshot, hourly aggregates
Verified 600/hour Current snapshot, hourly aggregates
Organization 6000/hour Historical data, per-minute resolution, per-probe breakdown