.xxx

TLD SLA Compliance Monitoring

TLD SLA Compliance Metrics

Spec 10

DNS

Period Availability RTT Compliance RTT p50 RTT p95 Checks TSLAC
24h 100% 100% 9.0ms 55ms 528
7d 100% 100% 7.0ms 313ms 2880
30d 100% 100% 5.0ms 513ms 16392

DNSSEC Validation Metrics

Registry Agreement Spec 6

DNSSEC is required by the Registry Agreement (Specification 6) but is not part of the Spec 10 SLA. We monitor DNSSEC validation independently.

Period Validation Rate RTT p50 RTT p95 Checks Status
24h 100% 32ms 36ms 88
7d 99.79% 32ms 79ms 480
30d 99.81% 32ms 50ms 2680

Unlike Spec 10 services, DNSSEC has no formal availability SLA. Thresholds shown are operational guidelines.

Current Check Status

Reported by Any53 Probes
Type AF RTT Last Check Source Details Status TSLAC
DNS v4 12ms 16 minutes ago local NSID: Auth_Host2.Toronto_Node1 OK
DNS v6 12ms 16 minutes ago local NSID: Auth_Host1.Toronto_Node1 OK
DNSSEC v4 30ms 1 hour, 22 minutes ago local Key: 21709 OK
DNSSEC v6 30ms 1 hour, 22 minutes ago local Key: 21709 OK

Nameservers

12 IPs tested
Hostname IP Address AF ASN RPKI Status
a.nic.xxx 37.209.192.10 v4 AS12008
a.nic.xxx 2001:dcd:1::10 v6
b.nic.xxx 37.209.194.10 v4 AS12008
b.nic.xxx 2001:dcd:2::10 v6
c.nic.xxx 37.209.196.10 v4 AS12008
c.nic.xxx 2001:dcd:3::10 v6
x.nic.xxx 156.154.172.82 v4 AS12008
x.nic.xxx 2610:a1:1074::1:82 v6 AS12008
y.nic.xxx 156.154.173.82 v4 AS12008
y.nic.xxx 2610:a1:1075::1:82 v6 AS12008
z.nic.xxx 156.154.174.82 v4 AS12008
z.nic.xxx 2610:a1:1076::1:82 v6 AS12008

Per ICANN Spec 10, we test all delegated nameserver IPs independently.

Test With Your Computer

DNS

dig @a.nic.xxx xxx. SOA +dnssec +nsid Query SOA with DNSSEC validation and NSID
drill -D xxx. SOA @a.nic.xxx Alternative using drill with DNSSEC trace

Registry Information

Active
TLD .xxx
Operator ICM Registry LLC

ICANN SLA Requirements

Per ICANN Registry Agreement Specification 10:

DNS SLA UDP RTT ≤ 500ms for 95% of queries. Availability: 99% (max 432 min/month downtime).

API Access

JSON API

Access .xxx compliance metrics programmatically via our REST API.

Quick Start

GET /any53/api/v1/compliance/xxx/
curl -H "X-API-Key: ${YOUR_API_KEY}" \
  "https://www.any53.com/any53/api/v1/compliance/xxx/"

Example Response

{
  "tld": "xxx",
  "display_name": ".xxx",
  "operator": "ICM Registry LLC",
  "updated_at": "2026-01-31T12:00:00Z",
  "dns": {
    "availability_24h": 99.99,
    "rtt_p50_ms": 12,
    "rtt_p95_ms": 42,
    "sla_threshold_ms": 500
  },
  "servers": {
    "rdap_url": "https://rdap.nic.xxx/"
  },
  "spec10_compliant": true
}

Generate API Key

Get a free API key to start making requests. Provide an email to upgrade to the verified tier (600 requests/hour).

Endpoints

Endpoint Description Tier
GET /compliance/ List all monitored TLDs All
GET /compliance/{tld}/ Current metrics for a TLD All
GET /compliance/{tld}/history/ Historical time-series data Organization
GET /compliance/{tld}/probes/ Per-probe breakdown Organization
POST /compliance/keys/ Generate a new API key No auth

Rate Limits

Tier Rate Limit Features
Anonymous 100/hour Current snapshot, hourly aggregates
Verified 600/hour Current snapshot, hourly aggregates
Organization 6000/hour Historical data, per-minute resolution, per-probe breakdown