Dear Patrik, Thanks for this report. We are aware of this issue. At the start of 2025, we began renumbering the IPv6 prefix containing these name servers. We presented our reasons and plan in our updates to the DNS WG during RIPE 90 and RIPE 91. The renumbering required coordination with various parties, including all the ccTLDs to whom RIPE NCC provides secondary DNS service. Most parties managed to update the address records. However, these 4 ccTLDs did not manage to update the glue records, despite all our frequent and vigorous efforts to reach them by email, phone and regional contacts. We also opened requests with IANA to update the glue records, but without approval from the ccTLD contacts, the requests cannot be processed. Ultimately the ccTLDs are responsible for maintaining the correct glue records in the root zone. Each one of these ccTLDs has at least one other working IPv6 glue record, as well as several working IPv4 glue records, so DNS resolvers are able to follow the delegation and resolve names. Regards, Anand Buddhdev RIPE NCC On 15/08/2026 17:10, Patrik Wallstrom via dns-wg wrote:
Hi,
In a recent run of my gonemaster analysis of all the TLDs, I just discovered that four ccTLDs has stale glue in the root for the RIPE nameservers,
https://gonemaster.evilbit.de/analysis/tags/ OUT_OF_BAILIWICK_ADDR_MISMATCH?search=OUT_OF_BAILIWICK_ADDR_MISMATCH
It's for the ccTLDs ne, ps, sd, and tj, which as the nameservers [ne|ps| sd|tj].cctld.authdns.ripe.net that all have old glue. I have not seen this before, but also I have just updated the testcase specification for this specifically, as the root does not always give all the glue from the root.
Just a heads up to whoever manages this glue.
/ Patrik