Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025 Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Cloud & Infrastructure Networking & CDN APNIC

APNIC adds ASPA support to RPKI for BGP path validation

APNIC now lets members publish signed upstream provider lists to detect route leaks and hijacks.

APNIC adds ASPA support to RPKI for BGP path validation
panumas nikhomkhai · Pexels

APNIC has integrated Autonomous System Provider Authorization (ASPA) into its Resource Public Key Infrastructure (RPKI) platform, giving network operators a new tool to verify BGP path integrity. ASPA objects allow an Autonomous System (AS) to publish a cryptographically signed list of its authorized upstream providers, which can then be used to detect route leaks and certain types of BGP hijacks that Route Origin Authorizations (ROAs) alone cannot prevent. Support is now live in MyAPNIC and the APNIC Registry API, making it available to all APNIC members immediately.

Background

Background: The Border Gateway Protocol (BGP) is the routing protocol that directs traffic between autonomous systems on the public internet. RPKI, which includes ROAs, helps validate route origins but does not address path manipulation. ASPA extends RPKI by allowing networks to assert and verify provider-customer relationships along the AS path, adding a layer of path validation to the existing origin validation framework.

How ASPA works

ASPA objects are published in the RPKI alongside ROAs. When a network receives a BGP announcement, it can download ASPA records and check whether each AS in the path is authorized to propagate the route according to the published provider-customer relationships. If an AS path violates these relationships—for example, if a route moves from a provider to a customer and then back to a provider—the route is marked as ASPA-invalid and can be rejected or deprioritized.

The validation process does not require every AS along the path to perform ASPA checks. Even if upstream networks do not validate, downstream operators can still detect and reject invalid routes. This partial adoption model lowers the barrier to entry while still improving overall routing security.

Security benefits

ASPA addresses two key weaknesses in BGP security. First, it mitigates route leaks, where a network mistakenly propagates a route to an unintended peer. By validating the direction of route propagation against published provider lists, ASPA can detect and block these leaks before they propagate widely.

Second, ASPA makes certain BGP hijacks harder to execute. Attackers attempting to forge a route must either manipulate the AS path to appear consistent with ASPA records—which increases path length and reduces routing preference—or risk detection by networks performing ASPA validation. While not a complete defense against all hijacking techniques, ASPA raises the difficulty and reduces the attractiveness of such attacks.

Adoption and implementation

APNIC’s deployment is part of a broader effort across the Regional Internet Registries (RIRs). The RIPE NCC and ARIN have already added ASPA support, and all five RIRs are expected to offer it by the end of 2026. This alignment is critical for a technology whose effectiveness depends on global adoption.

Software support for ASPA is already available in open-source routing platforms like BIRD and OpenBGPD, and several commercial vendors are either shipping or developing implementations. However, public internet validation rates remain low, as most networks have not yet begun publishing ASPA objects or enabling validation in their routers. As more operators adopt the standard, validation coverage is expected to improve.

What to watch

Network operators should monitor ASPA adoption among their peers and transit providers. Early adopters can begin publishing ASPA objects through their RIR portals and configuring their routers to perform validation. While full protection requires widespread participation, even partial adoption can reduce exposure to route leaks and hijacks. Operators may also want to track software updates from their routing platform vendors to ensure ASPA support is available and enabled.

For professionals

For professionals: ASPA validation can be implemented incrementally without disrupting existing routing. Operators should start by publishing their own ASPA objects and enabling validation in their edge routers. Over time, as more networks adopt the standard, the collective security benefits will grow. Monitoring tools that track ASPA-invalid routes can help identify misconfigurations or potential attacks early.

Companies mentioned

APNIC ARIN RIPE NCC

Discussion · coming soon

Be the first to join the thread when community discussion launches.