please have a read of the remark below. We sort of feel he Hakan has a point here. Did we miss something ? If not, then I will change the procedures to reflect this remark. Hakan has a very valid point here, but I don't agree with all he's saying: I can't see why at least two reverse servers should be reachable from the whole of Internet. It must be enough that they are equally reachable as the actual network they are reverse serving for, or? If a network doesn't have NSFnet connectivity (that is what we are talking about, and should be mentioned in your document!), there is no need for anyone at NSF to lookup the reverse zone for that network either. If a network doesn't have any external connectivity, there is no need for it's in-addr.arpa nameservers to be reachable from all of the Internet. Whether or not a network has NSFnet connectivity is irrelevant in the current context, so this should *not* be mentioned in the document: if a network has RIPE connectivity, then its in-addr.arpa nameservers *must* be reachable from all RIPE networks; in this context it should be noted that there is a root server which can be reached from all RIPE networks, so there is no need for NSFnet connectivity to make nameservers on "RIPE-only" networks work. However, it would be *desirable* if at least one of the in-addr.arpa of a "RIPE-only* network would be reachable from all of the Internet, so including NSFnet. Therefore I would suggest to change item 3 into: 3) If a network has or is going to have any external connectivity, it is strongly recommended that it has at least one reverse nameserver that can be reached from all of the Internet. Piet