Back to blog
dns Published: AEU DNS Newsroom

ASPA: The new RPKI object that catches route leaks

ASPA: The new RPKI object that catches route leaks

APNIC has deployed support for ASPAs, letting network operators validate BGP paths and catch route leaks. A new webinar explains how it works.

ASPA, or Autonomous System Provider Authorization, is a new object within the Resource Public Key Infrastructure (RPKI) that helps network operators check the path that internet traffic takes between networks. In July, APNIC deployed support for ASPA objects in MyAPNIC and the APNIC Registry API, so APNIC members can now publish their upstream provider relationships directly through APNIC's services. This move adds an important layer to routing security, allowing internet service providers and other network operators to detect route leaks and forged-path attacks.

To understand why ASPA matters, it helps to know how routing security works today. The internet is made up of tens of thousands of independent networks, called Autonomous Systems (ASes), which exchange routing information using the Border Gateway Protocol (BGP). BGP was designed decades ago with little built-in security, so a malicious or misconfigured network can announce routes it does not own, causing traffic to be hijacked or sent along unintended paths. The RPKI was created to fix part of this by letting network operators publish cryptographically signed statements about which IP address blocks they are authorized to announce. These statements are called Route Origin Authorizations (ROAs). When a network receives a BGP announcement, it can perform Route Origin Validation (ROV) to check whether the announcing AS is authorized to originate that prefix. ROV has significantly improved confidence in route origins.

However, ROV only checks the first hop of the route, the origin. It does not verify the full path that routing information takes across the internet. An attacker can still craft a BGP announcement with a valid origin but a forged AS path, causing traffic to flow through an unauthorized network. That is where ASPA comes in. ASPA allows an AS to publish a list of its authorized provider relationships, meaning the upstream networks it is allowed to use to reach the rest of the internet. Other operators can then validate the AS path of a BGP announcement against these ASPA records, identifying route leaks (where a network accidentally or deliberately announces a route through a provider it is not authorized to use) and forged-path attacks (where an attacker deliberately constructs a misleading path). This provides a complementary layer to ROV, improving confidence in routing information received from other networks.

APNIC has made it easier for its members to participate. Since July, APNIC members can publish their ASPA objects using MyAPNIC, APNIC's member services portal, or through the APNIC Registry API for automated updates. APNIC also provides DASH, a dashboard that can monitor ASPA status, helping operators see whether their ASPAs are valid and being used correctly by other networks. The APNIC Academy is hosting a webinar on 30 September 2026 from 15:00 to 16:00 UTC+10 to help members and the wider community understand ASPAs and their operational use. The webinar will cover why routing security matters and introduce RPKI, explain the difference between ROV and path validation, describe what ASPAs are and how they work, show how ASPAs build on ROAs, illustrate how ASPA validation helps identify route leaks and forged-path attacks, and discuss deployment considerations, current adoption trends, and available tools for ASPA creation and validation. It will also cover how APNIC's DASH can be used to monitor ASPA status. The session is aimed at anyone responsible for network operations, routing, peering, internet infrastructure, or security.

This webinar follows APNIC Academy's earlier webinar titled 'Strengthen your network security with APNIC products and tools' and is part of APNIC's ongoing work to help members make effective use of APNIC products and services to improve the security and resilience of their networks. As ASPA adoption grows, it is becoming an important addition to routing security deployments and operational best practices.

For everyday internet users, secure routing might seem like a background technical detail, but it directly affects the reliability and privacy of all online services, including the Domain Name System (DNS) that translates website names into addresses. A route leak or hijack can redirect DNS queries to an attacker's server, potentially allowing them to see or alter your internet traffic. Using a private, encrypted DNS resolver like AEU DNS adds a layer of protection by encrypting your DNS queries (via DoH or DoT), so even if a route is misdirected, your DNS traffic cannot be read or modified. Combined with wider adoption of routing security measures like ASPA, this helps keep the internet safer for everyone.

Terms explained

ASPA
Autonomous System Provider Authorization, a cryptographically signed record that states which internet providers an organization is allowed to use to reach the rest of the internet.
RPKI
Resource Public Key Infrastructure, a system that lets network operators securely prove which internet address blocks they are allowed to announce.
BGP
Border Gateway Protocol, the protocol that networks use to exchange routing information and figure out how to send traffic across the internet.
AS path
The list of autonomous system numbers that a piece of traffic passes through; ASPA checks this list against authorized relationships.
Route leak
When a network announces a route through a provider it is not authorized to use, causing traffic to take an unintended path.
ROA
Route Origin Authorization, an RPKI record that says which network is allowed to announce a specific block of internet addresses.
ROV
Route Origin Validation, the process of checking a BGP announcement against ROAs to confirm the origin is authorized.

How to protect yourself

  1. If you run a website or manage a network, ask your internet service provider or hosting company whether they use RPKI and ASPA to validate internet routes, and choose providers that do.
  2. Turn on encrypted DNS (DoH or DoT) on your devices or browser, for example by using a privacy-first resolver like AEU DNS, so your DNS queries stay private even if a network path is misdirected.
  3. Keep your router and devices updated with the latest firmware and software, as newer versions often include better routing security features and fixes.
  4. Monitor your own network for signs of unexpected redirects or connectivity changes, and report suspicious routing announcements to your provider.
Get private, encrypted DNS