AS187
Operated by DNSCAST-AS - DNScast.
Summary
- // analyst note
- AS187 (DNScast) and AS42 (WoodyNet) are the same operator (PCH); AS187 is the anycast-DNS stub and AS42 its sole upstream. AS-rank/customer cone not meaningful (single-upstream stub, no downstreams). RIPEstat rpki-validation was skipped (no prefix supplied), but bgp.he.net/bgp.tools confirm full ROA coverage.
- // security note
- NEUTRAL/DATED: no notable public abuse signal against AS187 as a source ASN as of 2026-06-18 — no Spamhaus/AbuseIPDB/CIDR-Report listing, no BGP hijack/leak/RPKI-invalid (Likely; live blocklist tools not directly queried).
About this ASN.
AS187 is a low-numbered, ARIN-registered Autonomous System carrying the AS name DNSCAST-AS and branded "DNScast," the anycast DNS stub network operated by Packet Clearing House (PCH), the Berkeley, California nonprofit that runs critical Internet infrastructure. The ARIN registry records the registrant under OrgId WOODY-2 (org name "DNScast," Berkeley, CA), with the administrative, technical, and abuse contact being Bill Woodcock (PCH's Secretary General, based at The Presidio of San Francisco); his individual mailbox and direct line are in the ARIN RDAP record. The key triage point is that AS187 is a pure anycast-DNS stub, not a transit carrier: it announces 17 IPv4 prefixes (drawn from the 72.42.112.0–72.42.127.0 range, roughly 4,608 addresses) and 17 IPv6 prefixes (the 2620:171:d00::/40 family plus 2001:dd8:7::/48), all of which carry valid RPKI ROAs with zero invalids, and it sits behind a single upstream — AS42 (WoodyNet, Inc.), itself a PCH-affiliated network. That single-upstream coupling makes AS187 and AS42 a tightly bound organisational pair rather than independently peering networks; PCH's overall open peering policy at pch.net/peering applies to the PCH network family, but AS187 itself does not peer in the conventional sense. The prefixes serve PCH's anycast DNS secondaries for Internet-critical infrastructure — ccTLD and root-letter nameservers, in-addr.arpa/ip6.arpa, and related zones — across PCH's global anycast footprint. No notable public abuse signal was found against AS187 as a source ASN as of June 2026; the only notable security event in the operator's record is the 2018–2019 DNSpionage/Sea Turtle campaign, in which PCH was a registrar-compromise *victim*, not a threat actor.
- Operator
- DNScast / Packet Clearing House (PCH); ARIN ASName DNSCAST-AS, OrgId WOODY-2 (registrant org "DNScast," Berkeley, CA 94709); admin/tech/abuse contact Bill Woodcock (PCH Secretary General) [Confirmed] — https://rdap.arin.net/registry/autnum/187, https://bgp.tools/as/187, https://ipinfo.io/AS187
- Country / RIR
- US, ARIN [Confirmed] — https://rdap.arin.net/registry/autnum/187
- Allocated
- 2009-07-22 — ARIN RDAP autnum-level registration date (last changed 2012-03-20) [Confirmed] — ARIN RDAP autnum top-level events
- Org status
- active holder. Packet Clearing House — US 501(c)(3) nonprofit (and self-described intergovernmental treaty organization) headquartered in Berkeley, CA; leadership Bill Woodcock (Secretary General), who is also the abuse/tech contact; his individual contact details are in the ARIN RDAP record [Confirmed for nonprofit status, Berkeley HQ, and Woodcock; treaty-organization status is PCH self-description] — https://en.wikipedia.org/wiki/Packet_Clearing_House, https://www.pch.net/about, https://rdap.arin.net/registry/autnum/187
Security/abuse context (NEUTRAL, DATED)
no notable public abuse signal against AS187 as a source ASN found as of 2026-06-18 — no Spamhaus SBL/XBL/PBL/DROP, AbuseIPDB, or CIDR-Report listing; no BGP hijack, route leak, or RPKI-invalid announcement attributed to AS187 [Likely — live blocklist tools not directly queried; based on indexed search + public BGP monitoring]. Operator security history: the 2018–2019 DNSpionage/Sea Turtle campaign hijacked PCH domains via registrar compromise (fraudulent SSL certs, ~four ~1-hour hijack windows) — PCH was the *victim*, not the abuser — https://bgpview.io/asn/187, https://krebsonsecurity.com/2019/02/a-deep-dive-on-the-recent-widespread-dns-hijacking-attacks/, https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-024a
Network & routing
- Network type
- Internet critical infrastructure — anycast DNS secondary / stub AS; carries no transit, announces anycast prefixes only [Confirmed] — https://bgp.tools/as/187, https://ipinfo.io/AS187, https://www.pch.net/services/anycast
- Size
- small — 17 IPv4 prefixes + 17 IPv6 prefixes (34 total). IPv4 footprint ≈ 4,352–4,608 addresses (17 × /24 = 4,352 host addresses; bgp.he.net reports 4,608, implying at least one block wider than /24); example IPv4 block 72.42.112.0–72.42.127.0 — https://bgp.he.net/AS187, https://bgp.tools/as/187
- Routing/peering
- single upstream AS42 (WoodyNet, Inc.), itself PCH-affiliated; the only observed peer is also AS42. No IXP membership identified; no downstream customers (customer cone effectively null). PCH publishes an open peering policy at pch.net/peering for the PCH network family, but AS187 is a stub and does not peer independently [Confirmed for the single upstream/peer; peering policy applies to the PCH family] — https://bgp.he.net/AS187, https://bgp.tools/as/187, https://www.pch.net/about/peering
- RPKI
- fully RPKI-valid — all 34 originated prefixes (17 IPv4 + 17 IPv6) carry valid ROAs, zero invalids; IRR records present across RADB, RIPE, ARIN, and APNIC. (RIPEstat rpki-validation was skipped in the primary fetch because no specific prefix was supplied.)[Confirmed] — https://bgp.he.net/AS187, https://bgp.tools/as/187
- Routing stability
- all observed prefixes continuously announced 2026-06-04 → 2026-06-18 across the full RIPEstat window; AS-overview reports the resource as announced/active as of 2026-06-18 [Confirmed] — RIPEstat as-overview / announced-prefixes (primary input JSON)
- Notable usage
- PCH's anycast DNS secondary infrastructure — nameservers for hundreds of top-level domains (ccTLDs, GOV.cc/MIL.cc), root-letter secondaries, in-addr.arpa/ip6.arpa, IXP domains, and CERT/national-government zones; PCH describes itself as operating one of the largest DNS anycast networks, present in hundreds of locations worldwide [Confirmed for the anycast-DNS role; specific facility/TLD counts are PCH self-reported] — https://www.pch.net/services/anycast, https://www.pch.net/about
- Related ASNs
- AS42 (WoodyNet, Inc. — PCH production-DNS network; sole upstream for AS187), plus other PCH-family ASNs AS3856 and AS715 [Confirmed for AS42 as upstream; AS3856/AS715 PCH-affiliated per source]
- Analyst note
- AS187 (DNScast) and AS42 (WoodyNet) are operationally the same operator (PCH); AS187 is the anycast-DNS stub and AS42 its sole upstream. AS-rank and customer cone are not meaningful here (single-upstream stub, no downstreams). The "endAutnum/startAutnum: 187" in the raw RDAP is the single-ASN record, not a block.
What this network routes.
- 203.119.88.0/23
- 72.42.124.0/24
- 72.42.120.0/24
- 72.42.123.0/24
- 72.42.122.0/24
- 72.42.125.0/24
- 72.42.119.0/24
- 72.42.116.0/24
- 72.42.114.0/24
- 72.42.117.0/24
- 72.42.121.0/24
- 72.42.112.0/24
- 72.42.127.0/24
- 72.42.115.0/24
- 72.42.113.0/24
- 72.42.126.0/24
- 72.42.118.0/24
- 2620:171:d01::/48
- 2001:dd8:7::/48
- 2620:171:d0a::/48
- 2620:171:d0e::/48
- 2620:171:d03::/48
- 2620:171:d09::/48
- 2620:171:d07::/48
- 2620:171:d08::/48
- 2620:171:d0d::/48
- 2620:171:d0f::/48
- 2620:171:d04::/48
- 2620:171:d0c::/48
- 2620:171:d0b::/48
- 2620:171:d05::/48
- 2620:171:d06::/48
- 2620:171:d00::/48
- 2620:171:d02::/48
Who it talks to.
| ASN | Operator | Role |
|---|---|---|
| AS42 | WOODYNET-1 - WoodyNet, Inc. | upstream |