Back to blog
dns Published: AEU DNS Newsroom

Why Parts of the Internet Become Unreachable, And How Network Operators Can Spot It

Why Parts of the Internet Become Unreachable, And How Network Operators Can Spot It

New research redefines Internet connectivity, showing partial reachability is common and often mistaken for outages, with important lessons for DNS reliability and user privacy.

For many of us, the Internet seems like a single, unified network that either works or doesn't. But new research presented at the ACM NINeS 2026 conference challenges that assumption, showing that connectivity is often patchy and conditional. The study introduces a fresh way to think about the Internet's core, not based on who owns the infrastructure, but on where data can actually flow. It reveals that large portions of the network are in states of 'partial reachability,' where some connections work while others fail, and that these states are more common than complete outages.

The researchers define two key operational states that describe this imperfect connectivity. A peninsula is a network that remains mostly connected to the Internet core but has partial, persistent connectivity issues, like a piece of land still attached to the mainland but with a narrow, unreliable path. An island is a set of networks that become completely cut off from the core, partitioned away like a distant island. These concepts help explain patterns that network operators and measurement platforms have observed for years but never quantified.

One of the most striking findings is that peninsulas are much more frequent than traditional outages. Looking at long‑running datasets from RIPE Atlas (a global network of measurement devices) and DNS root server queries, the team found that peninsula‑related effects can be between five and almost ten times larger than the events operators typically treat as real incidents. In other words, many of the 'anomalies' that engineers investigate are not full outages but structured patterns of partial reachability. This confusion can waste time and resources chasing symptoms instead of root causes.

Another important insight involves the distribution of these events. While nearly half of all peninsula events are short‑lived routing hiccups, almost 90% of the time spent in peninsula states comes from a small number of long‑lasting events, roughly 7% of the total. These stubborn cases are often tied to persistent policy decisions, commercial arrangements, or structural network conditions. For end users, this means the most frustrating, long‑term connectivity problems are likely coming from a handful of deep‑seated issues, not the frequent but quick glitches.

To carry out the research at Internet scale, the scientists used two complementary measurement systems. Trinocular, which regularly probes about five million IPv4 /24 networks from six globally spread sites, provided a broad view. RIPE Atlas, with its approximately 13,000 vantage points, offered fine‑grained sensitivity to directional routing behavior by probing the DNS root servers, the foundational servers that translate domain names into IP addresses. Combining these allowed the team to observe connectivity patterns both from edge networks toward the core and from the core back to the edges.

Based on these data streams, they developed algorithms that reliably detect peninsulas and islands over three years of measurements. Even more encouraging, they showed that accurate detection is possible with as few as three carefully chosen measurement points, lowering the barrier for operators who lack extensive resources. Their method was validated against CAIDA Ark data, achieving a recall of around 0.94 and precision between 0.42 and 0.82 depending on the event category, confirming the real‑world relevance of the findings.

For network operators, embracing peninsula‑aware thinking can bring significant practical benefits. Many teams already know that asymmetric routing, filtering, or routing inconsistencies can degrade certain paths without causing a full outage. By integrating peninsula and island indicators into monitoring dashboards, operators can avoid misreading partial reachability as complete failure, saving cycles that would otherwise be wasted on dead‑end debugging. It also improves measurement hygiene: filtering out peninsula effects from DNS root monitoring streams, for example, gives a clearer picture of genuine operational events, especially those touching root server behavior or wide‑area routing issues.

The approach also adds value for Border Gateway Protocol (BGP), the system that exchanges routing information between networks, and peering teams. Persistent peninsulas often mirror underlying peering policies, filtering asymmetries, or de‑peering incidents that affect only subsets of paths. These signals can serve as early warnings of commercial or policy shifts by upstream providers or neighboring networks.

Beyond daily operations, a connectivity‑based definition of the Internet core informs broader discussions on Internet governance. It shows that no single country or organization can unilaterally claim or operate 'the' Internet core, a finding that adds depth to debates about sovereignty, routing fragmentation, and national Internet initiatives. While government actions can still create islands or peninsulas, they cannot centralize control of the global core.

There is plenty of room for future work. IPv6, the next‑generation Internet addressing scheme, introduces different topological dynamics, raising the question of whether peninsula patterns behave differently across address families. Researchers also see opportunities to combine peninsula detection with BGP update streams, Resource Public Key Infrastructure (RPKI), a security framework that prevents route hijacking, and geolocation data to produce semi‑automated root‑cause labels. Ultimately, embedding peninsula‑aware metrics directly into routing controllers and Service Level Objective (SLO) monitoring systems could speed up response to long‑lived partial events.

Finally, the study advocates for shared, regularly refreshed ground‑truth datasets. Community‑maintained benchmarks spanning RIPE Atlas, CAIDA Ark, and other platforms would allow operators and researchers to validate and compare detection methods much more effectively, fostering a more resilient Internet.

For everyday users, partial reachability events can translate into websites that load intermittently, streaming services that buffer, or DNS lookups that fail on some devices but not others. While you can't fix global routing, you can reduce your exposure by choosing a privacy‑first encrypted DNS service such as AEU DNS, which resolves domain names via encrypted channels (DNS over HTTPS or TLS) and avoids many common points of interference. This helps ensure your queries reach the right servers, even when your Internet provider's default DNS is affected by partial reachability, and keeps your browsing private from prying eyes.

Terms explained

peninsula
A network that is mostly connected to the Internet but has persistent, partial connectivity problems, like a land bridge that gets shaky.
island
A group of networks that become completely cut off from the rest of the Internet, like remote islands with no ferry service.
BGP (Border Gateway Protocol)
The behind-the-scenes system that networks use to decide the best path for your data to travel across the Internet.
RIPE Atlas
A global network of small measurement devices that volunteer hosts run to help researchers map how well the Internet is connected.
DNS root server
One of the key servers that act as the Internet's address book, telling your device where to find the main directories of websites.
RPKI (Resource Public Key Infrastructure)
A security system that helps prevent bad actors from hijacking internet routes and misdirecting traffic.

How to protect yourself

  1. Switch to a private, encrypted DNS service like AEU DNS on your devices to reduce the risk of connection failures caused by partial reachability events.
  2. Keep your router's firmware updated, as manufacturers often include fixes for routing or DNS-related issues that affect connectivity.
  3. If you manage a website, use a reliable monitoring service to check your site's reachability from multiple global locations, so you can spot partial outages early.
  4. When experiencing sporadic internet issues, try a different DNS resolver, a simple change in your device or router settings can bypass your ISP's affected infrastructure.
  5. For sensitive tasks like online banking, consider using a reputable VPN, which can route your traffic through stable, encrypted tunnels, avoiding local network disruptions.

Source: blog.apnic.net

Get private, encrypted DNS