Business connectivity tools and data
131 tools and public datasets for buying, testing and running business internet connections. Every one was opened and checked, not collected from another list: 122 are free or open source outright, and the remaining 9 need either a free tier or a free account. Nothing here requires a sales conversation before it will show you anything, and nothing here is a quote marketplace, including ours.
- Everything 131
- Coverage 16
- Pricing 4
- Carrier records 2
- Speed tests 10
- Latency & loss 7
- Outages 8
- Routing & peering 18
- DNS & TLS 17
- Packet capture 2
- Monitoring 5
- Planning 13
- Data centres 5
- Voice & numbering 10
- Registries 14
Every entry opens for when to reach for it and what to watch out for. The first in each section is already open.
Serviceability and coverage
Who can actually deliver service to a specific building, and what is physically in the ground or in the air near it. Start here before you talk to any provider, because every quote conversation goes better when you already know what is available.
FCC National Broadband MapType a US street address and get the fixed and mobile providers that have filed availability at that specific structure, filterable by business or residential location type, technology and speed threshold. It is the authoritative federal answer to who can serve a building, at location level rather than census block level.
When to reach for it. First stop before any US site survey or multi-site sourcing exercise, and the free source that distinguishes business serviceable locations from residential ones at a single address. Use it to pressure test a carrier's claim that a location is or is not on-net.
Know before you rely on it. Availability is provider reported, so a location can show as served while the carrier still quotes construction. The published vintage also lags by a couple of quarters, so it is never a current view. Treat it as the starting hypothesis and use the FCC challenge process when it is wrong.
FCC Broadband Data Collection bulk data downloadsBulk export of the national availability dataset by state, by provider and by challenge status, plus provider summary tables, so you can analyse availability without clicking through the map. This is what you use when the question covers hundreds or thousands of sites rather than one.
When to reach for it. When you need to score a whole portfolio of locations for fiber availability, build an internal serviceability screen, or produce a defensible coverage analysis with an audit trail back to federal filings.
Know before you rely on it. Correcting a common overstatement: the public API is not open. It returns 401 without credentials and needs a free FCC account plus a token. The bulk files themselves are ungated, but records are keyed to Fabric Location IDs, and joining those back to addresses needs a licensed Fabric copy, so the free files are best used at aggregate or provider level.
FCC Broadband Funding MapAddress level lookup of which federal broadband subsidy programs have obligated money to build at a location, and which provider took the obligation. Covers FCC funds alongside NTIA, Rural Utilities Service, Treasury and Appalachian Regional Commission programs in one place.
When to reach for it. When a site has no fiber today and you need to know whether a subsidised build is already committed there before signing a long term circuit or funding construction yourself. Also the fastest way to see who is obligated to serve a rural site and under which program.
Know before you rely on it. An obligation is a commitment with a deadline, not a live circuit. Check the program's build milestones before assuming service is imminent, and expect the same reporting lag that affects the availability map.
Census GeocoderFree, keyless US address geocoder that returns coordinates plus the full census geography hierarchy for the matched address, including block, tract, county and place. It also accepts batch files of addresses.
When to reach for it. When you have a list of business sites and need clean coordinates plus census keys to join against FCC availability data. This is the piece most homegrown serviceability pipelines get wrong by reaching for a rate limited commercial geocoder instead.
Know before you rely on it. Matches against TIGER address ranges, so it interpolates along a street segment rather than returning a rooftop point. New construction and rural addresses miss more often than urban ones, which matters because a wrong block means a wrong availability answer.
FCC Area API and Block APITwo keyless REST endpoints that convert a latitude and longitude into the census block FIPS code plus the FCC's own market area identifiers. It is the glue between a site coordinate and every FCC dataset indexed by block or by market area.
When to reach for it. When you are scripting a serviceability pipeline and need to turn site coordinates into the block or market keys that FCC availability, licensing and auction data are filed under. No key, no signup, returns JSON immediately.
Know before you rely on it. Coordinates in, geography out. It does not geocode street addresses, so pair it with the Census Geocoder. It returns multiple candidate blocks when a point sits near a boundary.
FCC Antenna Structure Registration searchAuthoritative federal register of registered antenna structures, searchable by coordinate and radius, by city and state, or by owner. Returns structure location, height and owner for towers near a site.
When to reach for it. When you are assessing fixed wireless or licensed microwave as a primary or diverse path and need to know what structures exist within line of sight of a building, and who owns them. Far better evidence than a crowdsourced coverage map when you have to justify a design.
Know before you rely on it. Blocks automated requests, so it is a browser tool rather than something you can script. Only structures that require registration appear, so rooftops, short poles and many small cell sites are absent. It tells you a structure exists, not that any carrier has capacity on it.
TeleGeography Submarine Cable MapInteractive map and open JSON API of commercial submarine cable systems worldwide, with routes, landing points, ready for service status and owners. The underlying GeoJSON and per cable JSON are fetchable directly with no key.
When to reach for it. When designing or diligencing international connectivity: which cable systems land in a country, how many genuinely diverse paths exist between two regions, and whether a proposed circuit shares a cable with its supposed backup.
Know before you rely on it. Route geometry is illustrative rather than survey grade, and it covers subsea only. It will not tell you the terrestrial backhaul from a landing station to your site, and it does not publish live cable fault status.
ITU Interactive Transmission MapGlobal map of terrestrial transmission infrastructure from the ITU, showing fibre optic and microwave backbone routes by operational, under construction and planned status, layered with submarine cables and distance to node buffers. It is the closest thing to a public worldwide backbone map.
When to reach for it. When scoping connectivity in a country with no national broadband map and you need to know whether backbone fibre reaches a region at all, or whether a site sits within a plausible distance of a network node.
Know before you rely on it. Data is contributed by operators and regulators through a request for information process, so completeness varies sharply by country and the absence of a route is not evidence there is no route. A login exists for additional ITU member visualizations but it does not cover the core transmission layers.
Ofcom Broadband and Mobile CheckerThe UK regulator's own postcode level checker showing which broadband services are present at a location and, separately, mobile coverage by operator. Regulator run, so it reports what is there rather than what someone wants to sell you.
When to reach for it. For UK sites, when you want an independent read on available technologies at a postcode before talking to any provider, or when a supplier's own checker and reality disagree.
Know before you rely on it. Postcode granularity and explicitly predicted rather than measured. UK postcodes can span buildings with different fibre outcomes, and no data vintage is shown anywhere on the page. Confirm at address level with the wholesale access network before committing.
Openreach Full Fibre availability checkerAddress level availability check against the UK's main wholesale access network, returning not just whether Full Fibre is orderable but where the address sits in the build programme. Openreach sells only to communication providers, so the result is a statement of what is physically available rather than an offer.
When to reach for it. The address level follow up to the Ofcom postcode checker, and the fix for its main weakness. Use it when a UK site needs a definite yes or no on fibre, or when you need to know whether waiting for a scheduled build beats paying for a leased line now.
Know before you rely on it. Covers the Openreach footprint only, so it misses Virgin Media O2 and the UK altnet builders, and a site with no Openreach fibre may still have an alternative network. Build status dates are plans, not commitments.
ISED National Broadband Internet Service Availability MapCanada's official broadband availability map, showing retail service availability by speed tier and government funded build areas, gathered by Innovation, Science and Economic Development Canada with the CRTC from provider surveys.
When to reach for it. For Canadian sites, the rough equivalent of the FCC map: check which speed tiers are available in an area and whether a funded build is planned there before assuming a rural branch cannot be served.
Know before you rely on it. Correcting a common granularity claim: the published data is aggregated to hexagon cells, not premises, and ISED states accuracy generally within 250 metres. It reflects retail speed tiers, so it will not confirm business grade or symmetric service at a specific address. The page carries a stale template date stamp that is not the data vintage.
nbn address checkAddress lookup against Australia's wholesale national network showing connection status and access technology at a premises, with a distinct business path. Because nbn sells only to retail providers, the result states what is physically available rather than making an offer.
When to reach for it. For Australian sites, when you need the underlying access technology at an address, which determines achievable speed and symmetry, before comparing retail service provider quotes.
Know before you rely on it. A marketing signup module sits on the same page and the privacy notice indicates a looked up address can be linked to your details if you subscribe. Run the address check and skip the subscribe box.
Starlink Availability MapOperator map showing where the service is available or coming soon, with a second layer for typical speeds and latency by region. Address searchable and viewable without entering personal details.
When to reach for it. When evaluating low earth orbit satellite as a backup path or as primary connectivity for a remote site with no terrestrial option, and you need to know whether the cell is open before designing around it.
Know before you rely on it. This is the operator's own map, so availability and performance are vendor published and unaudited, unlike every regulator source above. Regional capacity changes and a sales call to action sits next to the address box. Use it to rule a site in or out, not as evidence in a design document.
FCC Study Area Boundaries map and shapefileAn address-searchable map of the certified study area boundaries of every incumbent local exchange carrier in the United States, with the same data offered as a shapefile and as census block overlap tables. It answers whose incumbent territory a given site sits in, which determines who owns the copper and fibre in that ground, whose tariff applies, and which state commission you escalate to.
When to reach for it. Before you request quotes for a site, when you want to know the incumbent behind the last mile rather than guess from the brand on the truck. The block overlap tables are the way to tag a whole multi-site address list by serving incumbent in one pass instead of one lookup at a time.
Know before you rely on it. www.fcc.gov returns HTTP 403 to curl and to fetch tools even with a browser user agent string. That is edge bot blocking, not a paywall or a login, and it is why the first pass mis-rejected several FCC resources. Open it in a browser. The boundaries are what carriers and state commissions certified on a recertification cycle, so the vintage lags reality after a territory sale, and it maps incumbent territory only, never competitive or fibre provider footprint.
FCC Internet Access Services ReportsThe FCC's twice yearly report on internet access connections in the United States, collected through Form 477, published as a report plus data tables and census tract maps of residential fixed connections and provider counts. This is the subscription and connection side of Form 477, which is a different series from the availability reporting that was retired.
When to reach for it. When you need a citable federal figure for how many providers and connections exist in a geography, for a market study, a board paper or a filing, rather than a marketing claim about competition in a service area.
Know before you rely on it. This is a subscription and connection census, not a serviceability lookup. It will not tell you whether a specific address can be served. Use the National Broadband Map for that.
OpenCelliDCommunity contributed database of cell towers with a browsable world map, per country and per operator statistics, cell lookup by MCC, MNC, LAC and Cell ID, network generation filters, an API and per country CSV exports.
When to reach for it. Fixed wireless and cellular backup site assessment, when you need to know which operators have sectors near a candidate location and on what technology, and you need a source you are licensed to use commercially.
Know before you rely on it. Map, statistics and cell search are open; CSV downloads need a free API access token. Exports cover only the most recent eighteen months, which the site states plainly, so this is a current picture and not a history. The licence is Creative Commons Attribution ShareAlike 4.0: commercial use is allowed, attribution with a link is mandatory, and the share alike condition attaches to anything you derive from it, which is a real constraint if the derivative is a product.
Price benchmarking and tariffs
What a circuit should cost, from public record rather than from a vendor. This is the hardest question to answer for free, and these are the only sources found that answer any part of it honestly. Read them as evidence of what other buyers paid in a market, not as a price you are entitled to.
USAC E-Rate open data, FRN Line Items and FRN StatusPublishes every line item of every E-Rate funding request as open data, with download and upload speed, technology, contract length, monthly recurring cost and one time cost. Joining it on the funding request number to the companion FRN Status dataset adds the winning service provider name, the number of bids received, the contract expiry date and, for construction projects, an average cost per foot of plant. Schools and libraries buy ordinary commercial dedicated internet, lit fibre and dark fibre, so this is a public record of what buyers in the same markets actually contracted for.
When to reach for it. When a quote lands and you have no independent read on whether it is sane. Filter to your state, your speed and fibre as the technology, and you get a distribution of monthly recurring cost for comparable circuits, who won them, and how many carriers bid. It is the only free, current, address-adjacent source of real contracted circuit pricing in the United States.
Know before you rely on it. These are prices contracted by eligible entities under a federal discount programme, so read them as a market reference rather than a rate you can demand. Use the pre-discount cost fields, not the funding commitment fields, because the commitment is the subsidy and the pre-discount figure is what the provider charged. Some records carry pricing confidentiality and are withheld. Note also that funding_year and state are text columns in the API, so filters need quoted values or the query returns a type mismatch.
FCC Electronic Tariff Filing System, public accessThe FCC's archive of interstate tariffs. Browse by incumbent or non-incumbent carrier, or search by carrier, date range and filing type, then open the filed pages that set out the rates, terms and conditions a carrier is actually bound to. Alongside the access services tariffs sit special construction tariffs, which is where the terms behind a build charge live.
When to reach for it. When you need the binding text behind an interstate access or special construction charge rather than a salesperson's paraphrase, when you are assembling a billing dispute, or when you want to see exactly what a carrier changed and on what date.
Know before you rely on it. Interstate only. Intrastate tariffs live at the state commissions and there is no national index of those. The carrier list is not curated: it contains defunct entities under legacy names and a handful of obvious test records, so browse rather than trust a name match. Most importantly, much of what large carriers sell today is detariffed, so do not expect current business data services pricing to be in here.
BLS Producer Price Index, business internet access and private line serviceThe official United States price index for what wired telecommunications carriers charge, published monthly and broken out to product level, with a series specifically for business internet access services and a separate one for private line telephone service. A free keyless public API returns the whole time series.
When to reach for it. Contract renewal and escalator arguments. When a carrier proposes an annual uplift or refuses to move at renewal, this is the neutral federal series showing what transaction prices in that exact product actually did, split for business rather than residential, and it is a much harder thing to wave away than an anecdote about another site.
Know before you rely on it. It is an index, not a price. It tells you the direction and pace of change in the market, never what a circuit should cost, so it settles an escalator argument and not a sourcing decision. The series landing page renders its table in JavaScript, so the API is the reliable route in.
FCC Urban Rate Survey dataAn annual FCC survey of fixed voice and broadband rates offered in urban areas, published as Excel results with a methodology paper for each year, alongside the benchmark calculators built from them.
When to reach for it. Sanity checking a quote for a small site on commodity broadband or a plain business line, when you want an official read on whether a price sits in the normal range for an urban market. It is a floor reference for the bottom of your estate, not a benchmark for the circuits that matter most.
Know before you rely on it. This is a rescue and a correction at the same time. The first pass rejected it as gated on 403 responses; the URL had simply moved and it opens normally in a browser. But the first pass also hoped it was the missing procurement price benchmark, and having read it, it is not. The overview says consumers in urban areas. It says nothing about dedicated internet access, Ethernet, wavelengths or MPLS, and nothing about rural markets. Present it as a consumer and small site reference and never as a business circuit benchmark. The E-Rate open data entry is the one that actually fills that gap.
Carrier records and vetting
Whether the company on the other end of a quote is a real carrier, what it is authorised to sell and where. Worth ten minutes before signing a three-year term with a name you have not dealt with before.
FCC Robocall Mitigation DatabaseThe mandatory register of voice service providers, gateway providers and non-gateway intermediate providers operating in the United States. Each listing gives the FCC Registration Number, legal name, previous business names, other trading names, address, STIR/SHAKEN implementation status, which provider roles the filer performs, and a downloadable copy of the robocall mitigation plan it filed.
When to reach for it. Vetting a SIP trunk, UCaaS or wholesale voice vendor before you sign. Other carriers may lawfully refuse traffic from a provider that is not listed here, so absence is a commercial risk rather than a technicality, and the previous business names and trading name columns are what expose a reseller that has rebranded away from a bad history.
Know before you rely on it. It is a ServiceNow single page app, so the table and the bulk CSV need a real browser and direct export URLs fail for scripts. Filers self-certify, so a STIR/SHAKEN status here is an assertion and not an audit finding. The listings also carry named individuals' work contact details, which is public but is still contact data.
FCC Form 499 Filer DatabaseSearchable register of every entity filing FCC Form 499, filterable by legal or trade name, filer ID, registration number, operational status, state of service and principal communications type, with incumbent local exchange carrier, competitive access provider or CLEC, interexchange carrier, interconnected VoIP, local reseller, shared tenant service provider and satellite among the selectable types. Records give the filer ID, legal name and trading names, primary address, the jurisdictions the filer says it serves, its officers and its designated agent for service of process.
When to reach for it. When a carrier or reseller you have not bought from before puts a quote in front of you and you need to know what kind of entity it actually is, what it has traded as before, where it is registered to sell, and who you serve notice on if it fails.
Know before you rely on it. This is a rescue of a first pass error. It was rejected as gated because every request returned access denied. The cause is edge bot blocking on apps.fcc.gov, not a login or a fee, and it is worth being precise here: a browser user agent string on curl is not enough, it still returns 403. Only a real browser works. Because automated clients are blocked, use the Excel dump rather than scraping. Note also that the item labelled Information About Your Carrier on the FCC's own index points at this same application, and so does the label Telecommunications Provider Locator.
Speed, throughput and quality testing
Proving what a circuit actually delivers, and proving it in a form somebody else will accept. The useful tests are the ones that measure latency and loss while the link is loaded, not just a single download number.
Cloudflare Speed TestA browser test that reports download, upload, latency, jitter and packet loss, and separates unloaded latency from latency measured during download and during upload. It scores the connection for streaming, gaming and video calling, and names the server location and the autonomous system your traffic left through.
When to reach for it. The fastest way to show a non-engineer that a circuit is fine at idle and falls apart under load. It is also the quickest single page capture of loss and jitter when someone reports bad voice or video quality.
Know before you rely on it. The page warns a run can consume a couple of hundred megabytes. Browser results include the Wi-Fi or LAN segment you test from, so cable in before you quote the numbers, and note your IP is shared with Cloudflare when you start.
Waveform Bufferbloat TestMeasures idle latency, then measures it again while saturating download and upload, and grades the difference. It explains its own method and grading and translates the result into whether real-time applications will hold up.
When to reach for it. When users complain that calls stutter while someone uploads a large file but every speed test comes back clean. This produces a shareable grade for the exact failure buyers describe as slow internet when the throughput number looks fine.
Know before you rely on it. Ungated, but the host is a retailer selling cellular signal boosters and antennas, so the surrounding page is commerce. Automated fetches are refused, so run it from a real browser, and test over Ethernet since Wi-Fi will cap the saturation the test needs.
M-Lab Speed Test (NDT)Measurement Lab's NDT test reports download, upload, latency and TCP retransmission from an independently operated measurement platform. Every result is published and the parsed dataset is queryable in BigQuery, so you can look at how a network has performed over time rather than at one moment.
When to reach for it. When you need a third party nobody in the dispute controls, or when you want historical evidence about an ISP's performance in a market rather than a single test you ran today. The retransmission figure is useful for pointing at loss when throughput alone is not persuasive.
Know before you rely on it. You must agree to a data policy that includes retention and publication of your IP address, which some enterprises will not accept from a corporate circuit. Single-stream NDT can understate very high capacity links.
networkQuality (built into macOS)A responsiveness test built into every recent Mac: type networkQuality in Terminal and it measures maximum capacity in both directions plus a round-trips-per-minute score, which is latency measured while the link is working rather than idle. It implements the IETF responsiveness methodology, can bind to an interface, and emits machine readable output.
When to reach for it. The zero-install way to get a defensible loaded-latency number from any Mac in the office, including before and after a router or queue management change. Its server side is published, so you can run the same test against a host inside your own network.
Know before you rely on it. Ships only with Apple operating systems, so it is not a cross-platform answer, and it uses real data on the connection under test. The responsiveness score is not something most carrier front line staff will recognise, so pair it with an mtr or an iperf3 run.
LibreSpeedAn open source HTML5 speed test you can host yourself, measuring download, upload, ping and jitter, with PHP, Node and multi-server backends and an official Go command line client that outputs CSV or JSON. Running your own instance lets you test to a server inside your network or inside your data centre.
When to reach for it. When you need to separate the LAN, the firewall and the circuit: put an instance on the LAN and one on the far side of the WAN, and the pair of results tells you which segment is the problem. It is also the right answer when policy forbids sending test telemetry to a third party, provided you host it yourself.
Know before you rely on it. Accuracy depends on the server you host it on and the path to it, so a badly placed instance measures your own hosting rather than your circuit. The public demo is not telemetry free: its privacy policy says it stores test ID, results, IP address, ISP, approximate location and user agent, so the privacy argument applies only to a self-hosted instance.
Speedtest TrackerA self-hosted application that drives a speed test on a schedule and keeps the history, so you accumulate a record of what a circuit actually delivered rather than what it delivered the one time you looked. It charts results, sends threshold alerts by mail, webhook or Apprise, exports to CSV and writes to SQLite, MySQL, Postgres, InfluxDB or Prometheus.
When to reach for it. The most useful thing to deploy the day a site starts complaining, because an SLA credit case is built from a time series, not from one bad test. Point it at a branch site and let it run before you open the ticket.
Know before you rely on it. The application is MIT licensed but the engine it drives is Ookla's Speedtest CLI, whose licence covers personal, non-commercial use on a single computer, so check that before standardising on it across business sites, or point it at a self-hosted LibreSpeed instead. A container on a busy host or a Wi-Fi connected mini PC will log its own limitations as circuit problems, and scheduled full-rate tests consume real bandwidth on the circuit you are measuring.
iperf3The reference tool for measuring achievable TCP, UDP and SCTP throughput between two hosts you control, with per-interval reporting, parallel streams, reverse mode and JSON output. UDP mode reports jitter and datagram loss, which is what a carrier will ask for when a browser screenshot is not enough.
When to reach for it. When you have to prove a circuit does or does not carry its contracted rate end to end. It is also the tool most carriers name when they schedule a test window against their own test head.
Know before you rely on it. Needs an iperf3 server at the far end and endpoint hosts capable of line rate, so a weak test PC can look like a weak circuit. Results are only as good as the host tuning behind them.
iperf2A separately maintained line, not a legacy version, with measurement features iperf3 does not have: one-way delay, trip-time measurement, TCP bounceback responsiveness testing, latency histograms and isochronous UDP traffic patterns. It runs on Linux, Windows, macOS, Android and embedded targets.
When to reach for it. When throughput alone will not settle the argument and you need directional latency evidence, for example showing that the upstream path adds delay while the downstream path is clean. Also for emulating a constant-rate voice or video stream rather than a bulk transfer.
Know before you rely on it. One-way delay is only meaningful if both endpoints have synchronised clocks. Most people who say iperf mean iperf3, so name the version explicitly in a ticket. The project page refuses some automated requests even though it loads normally in a browser.
iPerf3 Server ListA maintained directory of public iperf3 servers worldwide, each entry giving the host or IP, the correct port range, flags for reverse, UDP and IPv6 support, port speed, city, continent and operator. The whole list exports to JSON, CSV and XLSX.
When to reach for it. When you need a far-end iperf3 target and you do not have a second site to stand one up in. Also when you want to test toward a specific city or a specific upstream network to show that the problem follows one direction of the path.
Know before you rely on it. These are volunteer and operator-donated servers on shared infrastructure, so a slow result may be the server or the path to it rather than your circuit. Test two or three targets before drawing a conclusion, and do not point sustained load at someone else's donated box.
Flent (FLExible Network Tester)Wraps netperf, iperf, ping and irtt into repeatable composite test runs and plots the results, most notably the RRUL test that loads the link in both directions at once while measuring latency throughout. It produces the standard chart of download, upload and latency together and stores raw JSON alongside the images.
When to reach for it. When you need a defensible, repeatable measurement of behaviour under bidirectional load, for example proving that a link meets its rate but destroys latency while doing it. Also the right tool for before and after evidence when a queue management change is applied.
Know before you rely on it. Requires netperf built with the demo option, a timestamping ping, and matplotlib for plots, so setup is more involved than a single binary. In practice you run it from Linux or macOS against a netperf server you control.
Path, latency and packet loss diagnosis
When the circuit is up but something is wrong, these are the tools that locate the fault and attribute it. Run them from both ends before you open a ticket, because a one-way traceroute is the most common reason a carrier ticket goes nowhere.
mtrCombines traceroute and ping into one continuously updating view, showing loss percentage plus last, average, best, worst and standard deviation of round trip time for every hop on the path. It is the standard first look when someone says the link feels slow.
When to reach for it. Run it in both directions between the two sites before you open a ticket. A carrier NOC will usually ask for an mtr from each end, and a one-way mtr is the most common reason a ticket stalls.
Know before you rely on it. Loss shown at a middle hop is frequently ICMP rate limiting on that router rather than real loss. Only loss that persists to the final hop counts, and asymmetric routing means the return path may not be what you see. Cite the repository: the old bitwizard.nl page still ranks well but is largely obsolete.
GlobalpingRuns ping, traceroute, mtr, dig and curl from a community-run probe network spread across countries, cities and networks, and returns the raw command output plus parsed statistics. Web UI, CLI, REST API and chat integrations, with no account required for normal use.
When to reach for it. When you have to show how your site or circuit looks from somewhere you are not, for example proving a remote office's complaint is a regional path problem rather than a fault at the host. It is also the quickest way to test from a named network or country when a carrier claims the issue is local to you.
Know before you rely on it. Probes are community and sponsor hosted, so a single probe's result reflects that volunteer's connection as much as the path. Free limits are generous but they exist, and you are testing toward your target rather than from your own office, so it complements rather than replaces an on-site test.
irtt (Isochronous Round-Trip Tester)Sends UDP packets at fixed intervals and reports round trip time, one-way delay, instantaneous packet delay variation, packet loss separated into upstream and downstream, and out-of-order and duplicate packets, with JSON output. Packet sizes and intervals can be set to imitate a voice stream.
When to reach for it. The tool to reach for when the complaint is VoIP or video quality rather than throughput, because it measures the traffic pattern those applications actually generate. The upstream and downstream loss split is the detail that ends most arguments about whose side the loss is on.
Know before you rely on it. Needs an irtt server at the far end, and one-way delay figures require synchronised clocks on both hosts. It measures a low-rate stream, so it says nothing about capacity.
PingPlotterContinuously traces the path to a target and graphs latency, jitter and packet loss per hop over time, so you can see which hop the degradation starts at and when it happens. Desktop editions for Windows and macOS plus a hosted version for watching several sites.
When to reach for it. When the argument is about whose network is at fault. Per-hop history over hours is what separates a last mile problem from a transit problem, and the vendor builds its output around handing evidence to an ISP.
Know before you rely on it. The free version is one connection with no remote collection and is positioned for home networks, so anything real is paid, and trials are time limited. Per-hop loss can be an artefact of routers rate limiting ICMP responses, so read the graph as a whole rather than blaming one hop.
SmokePingLong-running latency and packet loss measurement that stores results in RRDtool and draws the graphs showing median round trip time, the spread of individual probes as smoke, and dropped packets in red. Multiple probe types and a master and slave model let one install watch many targets from many vantage points.
When to reach for it. When you need months of latency and loss history for a circuit, a peer or a remote site, and you need the graph that makes intermittent evening congestion visible at a glance. It is still the graph most transit and ISP engineers read fastest.
Know before you rely on it. The homepage is a mid-2000s page whose newest news item is ancient, so judge the project by its repository rather than the site. Releases are slow even though the repository saw commits this year, and setup is Perl and RRDtool, so it is a build rather than a click.
perfSONARA measurement framework rather than a single test: its scheduler runs repeatable throughput, one-way latency, round trip, path and DNS tests between instrumented endpoints and stores results in a uniform format for graphing and comparison. Throughput runs on iperf3, iperf2 or nuttcp, one-way latency on owping or twping.
When to reach for it. When the problem only shows up on long fat paths or between specific site pairs and you need scheduled, repeatable, directional measurement rather than someone running a test by hand. Many deployed instances accept open testing, so you can measure against a well-run reference host.
Know before you rely on it. This is infrastructure to deploy and operate, not a page to open. It assumes you can put a dedicated host at each end and that clock discipline exists for the one-way latency numbers to mean anything.
Fastly DebugLoading the page returns a live report on your own connection as an edge network sees it: your public IP with AS number and geography, your DNS resolver's IP and network, and TCP-level characteristics of your connection to the nearest point of presence including round trip time, congestion window and retransmit counts.
When to reach for it. When a user reports a site is slow and you need to establish whether the problem is their access circuit, their resolver or the path to the edge. The retransmit and congestion window figures are the fastest evidence of a lossy last mile, and it names the point of presence you actually landed on.
Know before you rely on it. The RTT and retransmit figures describe the path to one specific CDN's network, not the internet generally. The client IP and resolver identification are useful regardless of which CDN a site uses.
Outage detection and attribution
Independent evidence that something is broken and whose fault it is. Use at least two of these before you put anything in writing, because crowd reports and vendor dashboards fail in opposite directions.
Cloudflare Radar Outage CenterTwo live tables, one of observed internet outages and one of automatically detected traffic anomalies, scoped by location or ASN with start time, duration and where known a cause. Rows link to the underlying traffic graph and the set exports to CSV.
When to reach for it. When a site or carrier looks broken in one country or on one network and you need third party evidence with a timestamp. Fastest way to separate a real provider outage from something inside your own building.
Know before you rely on it. The view defaults to a short recent window, so widen the date range before concluding nothing happened. Detection derives from Cloudflare traffic share, so small networks may never register, and cause fields are frequently blank on new events. Blocks automated requests, so use a browser or the Radar API.
IODA (Internet Outage Detection and Analysis)Detects macroscopic outages by correlating three independent signals: BGP reachability, active probing of responsive hosts, and traffic at a network telescope. You can drill from country to region to individual ASN and see which of the three signals dropped and exactly when.
When to reach for it. When you need to prove an outage happened on a specific ISP and defend the finding, because agreement across three unrelated measurement methods is far harder to argue with than a single vendor dashboard.
Know before you rely on it. Built for macroscopic, network wide events. It will not see one circuit or one building going down. Academic project with no support commitment or uptime guarantee.
ThousandEyes Internet Outages MapPublic map of outages detected by a large commercial agent network, separated into ISP, public cloud, application provider and edge service categories rather than lumped together, refreshing every few minutes. It is paired with written post incident analyses that name the failure mode of major events.
When to reach for it. When an application is down for your users and you need to know whether the fault sits with the transit provider, the cloud region or the SaaS vendor. The written analyses are also the quickest way to brief a non technical stakeholder after a big event.
Know before you rely on it. This is the shop window for a paid platform and the page is wrapped in login, demo and trial calls to action, though nothing is gated. Coverage skews to consumer SaaS and cloud brands rather than business access circuits, so it is better for cloud and application attribution than for proving a local circuit fault.
DowndetectorAggregates user submitted problem reports per provider and per service into a rolling chart, a breakdown of which service is being reported broken, and a list of the worst affected cities. Covers major carriers and business ISPs alongside SaaS and cloud services.
When to reach for it. The first thirty seconds of an incident, to check whether the rest of the metro is reporting the same thing before you open a ticket. Treat it as a signal, then confirm with Cloudflare Radar, IODA or RIPEstat before you put anything in writing.
Know before you rely on it. Crowd sourced, not measured. Report volume tracks brand popularity, so a large consumer carrier always looks noisier than a regional business fiber provider, and a quiet graph does not mean your circuit is fine. Useless for attributing a fault to a specific route or facility.
Internet Society Pulse Internet ShutdownsTracks deliberate national and regional internet shutdowns and platform blocking, with start time, live running duration, country, trigger, which services are blocked, and a confirmed, acknowledged or unconfirmed verification status. Includes a global map, an ongoing list and multi year trend analysis with a published methodology.
When to reach for it. Before you commit to a site, supplier or remote team in a country with a shutdown history, and during an event when you need to explain to management that the outage is political rather than technical and therefore has no engineering ETA.
Know before you rely on it. Covers intentional shutdowns and platform blocking only, so it will never show a commercial provider failure. The ongoing count is inflated by long running censorship baselines rather than new incidents, and several entries carry an unconfirmed status. A cookie consent banner appears on load.
outages@outages.org mailing listOperator run mailing list where network engineers post planned and unplanned outages: fiber cuts, carrier maintenance, DDoS events and provider incidents, sometimes before an official status page acknowledges anything. A companion discussion list carries troubleshooting and post mortem threads, and both archives are public.
When to reach for it. Search the archive when you suspect a carrier wide problem and want to see whether another operator has already named it. Treat a hit as a bonus, not a primary detection channel.
Know before you rely on it. Correcting the common description of this as a firehose: it is not. Real traffic runs at a few threads a month, so it will usually be silent at the moment your circuit drops, and reports are unverified peer claims rather than measurements. Archives are readable without joining. The old puck.nether.net listinfo URL returns 404.
FCC DIRS Communications Status ReportsDuring a declared disaster the FCC activates its Disaster Information Reporting System and publishes a daily public status report aggregating what carriers filed: cell sites out of service, wireline and cable subscribers without service, and broadcast and emergency call centre status, broken down by affected county. Past Response Efforts is the archive index of every activation.
When to reach for it. When a storm, wildfire or regional disaster hits a site you operate or are about to sign for, and you need an authoritative county level read on how much local communications infrastructure is down and how quickly it is being restored. It is the only source here backed by mandatory carrier reporting to a regulator.
Know before you rely on it. Distinct from NORS, whose filings are presumed confidential with no public lookup. US only, and reports exist only while DIRS is activated for a declared event, so there is nothing live to check on an ordinary day. Figures are aggregated by county across all reporting providers, so you cannot see a named carrier's status, and reports are documents rather than a queryable dataset.
StatusGatorAggregates vendor status pages into one view. The public per service directory gives an up or down verdict sourced from the vendor's own status page, when it was last checked, a rolling health chart and user submitted reports. With an account you assemble a board of the services you care about, with notifications and integrations.
When to reach for it. When something is broken and you want to rule out suppliers before digging into your own network. One page tells you whether the SaaS, the CDN or the cloud region is already admitting a problem.
Know before you rely on it. The public per service pages are open and need no account. Building your own aggregated board does need one, and the free forever tier is a handful of monitors on a single board, so it suits a critical few rather than a whole vendor stack.
Routing, peering and address intelligence
Who owns an address block, who carries its traffic, and whether the routing behind a circuit is sane. This is the engineer core of the directory, and several entries are also the fastest way to check a carrier's claims during procurement.
bgp.toolsSearch by ASN, prefix, DNS name or MAC address and get near real time BGP data on who originates a prefix, who its upstreams are, which exchanges it is on and how the network is seen in the global table. It is the fastest general purpose answer to who this network is and where its traffic goes.
When to reach for it. First stop when you have an IP, a prefix or an AS number and need the network behind it plus its transit relationships. Cleaner and faster for that question than raw whois.
Know before you rely on it. Monitoring, IRR and RPKI alerting and API access sit behind a paid subscription. Interactive lookups in the browser are free and need no account.
Hurricane Electric BGP ToolkitA free suite of reports over one BGP dataset: prefix and peer reports per ASN, exchange point reports, bogon routes, multi origin route detection, RPKI and ASPA reports, world routing statistics, plus a looking glass and traceroute.
When to reach for it. When you want breadth in one place, particularly exchange participation and the RPKI or ASPA views for a given ASN, or a quick looking glass without hunting down a carrier specific one.
Know before you rely on it. One operator's view of the table. Cross check anything load bearing against a multi-vantage looking glass.
RIPEstatOne query box over a large collection of datasets: enter an IP, prefix, ASN, hostname or country code and get routing history and status, announced prefixes, registry and allocation data and abuse contacts as stacked widgets. Its BGPlay widget replays how a prefix's AS paths changed across a chosen time window.
When to reach for it. Outage forensics and history, when you need a timestamped and citable answer to whether a prefix actually left the global routing table and for how long. It is the neutral third party record to put in front of a carrier claiming nothing happened, and it needs no account.
Know before you rely on it. Visibility is measured at RIS collectors, so it describes the control plane and not whether traffic actually flowed, and results exclude routes seen by fewer than ten full feed peers. The widget heavy UI is slow; the Data API is the faster path, and RIPE states it is offered for non commercial purposes.
RIPE AtlasA global network of hardware and software probes you can direct to run ping, traceroute and DNS measurements from specific countries, ASNs or cities. Built in measurements and the full public results of other people's measurements are free to browse and download.
When to reach for it. When you need to prove how your network looks from somewhere you do not control: reachability from a particular country or eyeball ASN, or path changes over time from many independent vantage points at once.
Know before you rely on it. Browsing and downloading public results needs no account. Running your own custom measurements needs an account and credits, earned by hosting a probe or granted as a starting allowance. The web app is JavaScript rendered, so it looks blank to a simple fetch.
NLNOG RING Looking GlassA single looking glass fed full BGP tables by hundreds of volunteer member networks, so one query shows how a prefix is seen from many independent vantage points simultaneously. Supports exact and longer prefix matching and per peer route display.
When to reach for it. When one carrier's looking glass is not enough and you need to establish whether a routing problem is local to one transit path or globally visible. Far faster than chaining queries across a dozen provider looking glasses.
Know before you rely on it. Peers are volunteer member networks, so the vantage point mix skews toward European and operator community participants rather than an even sample.
University of Oregon Route ViewsThe long running BGP archive, collecting full routing tables from collaborating networks at exchanges worldwide and publishing them as MRT dumps stretching back to the 1990s, alongside live route servers, a looking glass and an API.
When to reach for it. When you need to reconstruct what the routing table genuinely looked like at a specific moment in the past, for an incident postmortem, a contractual dispute or longitudinal research. Nothing else goes back this far.
Know before you rely on it. Separate commercial terms apply if you sell a service built on the data. Working with raw MRT archives requires tooling such as bgpdump or bgpreader; the looking glass is the no setup option.
IRR ExplorerCross checks a prefix or ASN against every mirrored internet routing registry and against RPKI, then reports where the records disagree with what is actually in the global routing table. It flags cases such as a route object existing only in a non authoritative registry, or no route object matching the origin seen in the default free zone.
When to reach for it. Before you ask an upstream why your prefix is being filtered, and when onboarding a transit provider that builds prefix filters from IRR data. It finds the registry mismatch in seconds instead of querying each registry by hand.
Know before you rely on it. The front end is a JavaScript application, so a simple automated fetch sees a blank page even though it renders correctly in a browser. A JSON API is available if you want to script it.
RADb queryMerit's query front end and whois service over the routing registries, mirroring roughly twenty registry sources. Unlike prefix oriented checkers it will return and expand set objects: as-set, route-set, peering-set, filter-set, inet-rtr and mntner, which is what prefix filters are actually built from.
When to reach for it. When you are constructing or auditing a prefix filter and need to see what an as-set actually expands to, or which maintainer owns an object. Pair it with IRR Explorer: RADb tells you what is registered, IRR Explorer tells you whether that matches what is announced.
Know before you rely on it. It reports what is registered, not whether the registration is correct or currently announced. Objects can be years old and still returned.
Team Cymru IP to ASN Mapping ServiceFree bulk IP to ASN resolution over whois, DNS or HTTPS, returning origin ASN, peer ASN, BGP prefix, registry, allocation date and AS name. The bulk netcat mode resolves large address lists in a single connection.
When to reach for it. When you have a log file, a flow export or a firewall block list full of IP addresses and need to know which networks they belong to. Nothing else does this at volume from a shell as cleanly.
Know before you rely on it. Explicitly not a geolocation service: the country code comes from registry records and frequently does not match where an address is used. Individual queries at volume get null routed, so use the bulk mode and aggregate addresses first.
Cloudflare Radar RoutingA live dashboard of global routing table health: total ASes and prefixes split by IPv4 and IPv6, the share of announced prefixes that are RPKI valid, invalid or unknown, announced address space over time, and the largest ASes ranked by customer cone. Every panel carries a data generation timestamp and a citation link.
When to reach for it. When you need a current, citable figure for RPKI adoption or routing table size for a design document or a security argument, and you want it timestamped rather than inferred. It is also the cleanest public ranking of carriers by customer cone.
Know before you rely on it. Blocks automated requests, so scripted access needs the Radar API rather than page scraping. The vantage point is Cloudflare's own view of the routing table.
MANRS ObservatoryScores routing security readiness per country and per ASN across five MANRS actions: filtering, anti spoofing, coordination, IRR routing information and RPKI routing information. It also counts observed incidents, route misoriginations, route leaks and bogon announcements, with a month by month period selector and CSV export.
When to reach for it. Procurement and risk work. When you want an independent, per country and per operator read on whether a carrier's routing hygiene is credible, or need to show a security team how exposed a given market is before you buy transit there.
Know before you rely on it. Anti spoofing readiness has very low coverage, with most ASNs showing no data, so treat that column as unmeasured rather than as a pass. Blocks plain automated fetches, so verify in a browser.
Internet Health ReportQuantifies which other networks a given AS actually depends on to reach the internet, using an AS hegemony score computed from global BGP data, and adds inferred network delay, link congestion and disconnection detection from RIPE Atlas traceroutes. Reports exist per AS, per prefix, per hostname and per country.
When to reach for it. When you need to show concentration risk rather than a topology map: which transit networks a carrier or a country genuinely relies on, and therefore who else has to break for your circuit to break. It answers the diversity question a facility record or a customer cone ranking cannot.
Know before you rely on it. Licensed Creative Commons Attribution NonCommercial ShareAlike, so check terms before republishing. Hegemony is an inferred statistic, not a contract level dependency list, and the front end is JavaScript rendered. Old ihr.iijlab.net links redirect to ihr.live.
GRIP (Global Routing Intelligence Platform)Continuously classifies BGP origin events into MOAS, sub-MOAS, new edge and defcon categories and scores each as suspicious, grey or benign using RPKI validity and reputation tags. Every event names the potential victim AS, potential attacker AS, prefix, start time and duration.
When to reach for it. When you suspect your prefixes are being hijacked, or you need to check whether a route leak explains a sudden reachability or latency change. It answers what a raw looking glass cannot: is this announcement legitimate.
Know before you rely on it. The default view arrives prefiltered to high suspicion events of one type only, so widen the event type and suspicion filters or you will miss most activity. Suspicion scoring is heuristic, so a high score is a lead to investigate, not a confirmed attack. Academic project with no support commitment.
Is BGP Safe Yet?Cloudflare announces a route it has deliberately made RPKI invalid and tests whether your network accepts it, giving a one click yes or no on whether your provider performs route origin validation. It also publishes a running log of major operators that have deployed filtering.
When to reach for it. The fastest way to answer whether your ISP actually filters invalid BGP routes with no BGP knowledge required, and a concrete piece of evidence when pressing a carrier on routing security during procurement.
Know before you rely on it. It tests only the path your browser actually takes out, so a corporate VPN or a resolver in another network will change the result. Run it from the site you are assessing. The operator log is curated by hand and lags for smaller networks.
BGPalerterSelf hosted BGP and RPKI monitor that watches your own prefixes for hijacks, visibility loss, unexpected more specifics, unexpected upstream or downstream ASes, RPKI invalid announcements and expiring ROAs. It reads public BGP feeds directly, so nothing has to be deployed inside your network.
When to reach for it. When you announce your own address space and want to hear about a hijack or a lost ROA from your own alerting rather than from a customer. The practical alternative to paying for a commercial routing monitor.
Know before you rely on it. Correcting the usual claim that this is actively developed: the newest tagged release and the newest commits on the default branch are both about a year old. It still functions because it consumes public route collector feeds rather than a vendor API, and the logic is stable, but treat it as mature and quiet. Only useful if you hold your own ASN and prefixes.
RIPE IPmapGeolocates infrastructure addresses using active latency measurement from RIPE Atlas rather than a commercial database, and exposes the result over an open API that returns the inferred city with the measurement evidence behind it, including the minimum round trip time and the radius the estimate is constrained to.
When to reach for it. When a circuit's addresses geolocate to the wrong city and it is breaking geofenced SaaS, tax or emergency calling assumptions, and you need an independent opinion that is not just another copy of the same commercial database. Also useful for checking where a carrier's router hops actually sit when a traceroute looks implausible.
Know before you rely on it. Aimed at infrastructure addresses, not customer endpoints, and it infers location from latency, so a result carries a distance radius rather than a street address. It will not tell you what a commercial geolocation vendor believes, which is usually what the failing application is using.
IPinfoReturns what a widely consumed geolocation database believes about an address: city, region, country, postal code, timezone, the hosting or carrier organisation with its AS number, reverse hostname and an anycast flag, as plain JSON from a single URL.
When to reach for it. When a new circuit's addresses make SaaS, streaming or content licensing behave as though the office is in another state, and you need to see what the databases think before you can get it fixed. Pair it with RIPE IPmap for an independent measured opinion, and fix the root cause by asking the provider to publish a geofeed.
Know before you rely on it. Commercial vendor. The unauthenticated endpoint still works but returns limited data, is capped, and the vendor's own documentation says it may be discontinued in favour of an account based free tier. Any geolocation database is an opinion, not a fact, and different applications consult different vendors, so one clean answer here does not prove the problem is fixed.
CAIDA AS RankRanks autonomous systems and organisations by customer cone, the set of networks, prefixes and addresses reachable through a network's own customers rather than through its peers or upstreams. Free web lookup by ASN, organisation, country or name, with GraphQL and REST APIs that need no key. Built from RouteViews and RIPE RIS BGP data plus registry WHOIS and CAIDA's AS to organisation mapping.
When to reach for it. When you want to size a carrier's real transit reach before signing, or test a tier 1 or global backbone claim in a proposal. Look up the ASN, read the customer cone, compare it against the other bidders. Also useful for deciding which of two upstreams puts more of the internet on net.
Know before you rely on it. The snapshot lags the calendar and the lag is longer than the monthly cadence implies. As of late July 2026 the newest snapshot is dated 2026-04-01 and no May or June snapshot has appeared. Treat the customer cone as a recent quarter picture, not today's routing table. Data is offered under CAIDA's acceptable use agreement, so attribute it if you republish figures.
DNS, mail, web and TLS
The services that break first when a circuit, an address block or a firewall changes underneath them. Nearly every reported outage that turns out not to be the circuit turns out to be one of these.
Internet.nlRuns three deep conformance tests, one for a website, one for a mail domain and one for your own connection, covering IPv6, DNSSEC, HTTPS and TLS configuration, CAA, security headers, RPKI route authorisation, and on the mail side SPF, DKIM, DMARC, STARTTLS and DANE. Every failed check links to the standard it came from.
When to reach for it. The single best starting point when you inherit a domain and need to know what is actually wrong across DNS, mail and web in one pass. Nothing else free covers DANE, transport security and route authorisation in the same report.
Know before you rely on it. Run by a Dutch internet standards foundation, so some guidance reflects Dutch government policy, though the underlying checks are RFC based and apply anywhere. Available as a container if you want to run it internally.
ZonemasterRuns a full delegation and zone health test: parent-side NS and DS consistency, nameserver reachability over IPv4 and IPv6, SOA and TTL sanity, and DNSSEC chain validity. It is the test suite two national registries built to decide whether a delegation is actually correct.
When to reach for it. When a domain resolves for some people and not others, or before you cut over nameservers. It catches parent-child mismatches and half-broken secondaries that a single dig will not show you.
Know before you rely on it. The web UI is a JavaScript app. There is also a CLI and a self-hostable backend if you want to run the same tests inside your own environment.
DNSVizDraws the complete DNSSEC authentication chain for a name as a graph, from the root trust anchor down through every DS and DNSKEY to the record you asked about, and flags every break in it. It keeps historical analyses so you can see when a zone broke.
When to reach for it. When DNSSEC validation is failing and you need to see exactly which link in the chain is bad. Reading a signed dig dump by hand is miserable; this shows you the broken edge in one picture.
Know before you rely on it. The footer carries a copyright line ending more than a decade ago, which makes the site look abandoned. It is not: the analysis loaded had been generated the previous day and the options panel implements recent DNSSEC RFCs.
Dig Web InterfaceRuns dig against many public resolvers at once and shows the real command output side by side, with a compare mode that highlights where the answers differ. Covers the full record type list including DNSSEC types and CAA, with trace, stats and DNSSEC validation toggles.
When to reach for it. This is the honest answer to the propagation question. When a record change has landed on some resolvers and not others, querying an explicit list of resolvers and diffing the answers tells you what a marketing-styled propagation map only implies.
Know before you rely on it. Carries advertising, with an option to disable it, and imposes a challenge after roughly a hundred lookups a day. Run by an individual on donations, so treat it as a convenience rather than something to script against.
Google Public DNS query tool and DoH JSON APIGives you a resolver-side view of any record: a browser form and a plain JSON endpoint that returns the answer plus the DNSSEC AD flag and the upstream server it consulted. Because it is JSON over HTTPS you can script it from curl anywhere without a resolver library.
When to reach for it. When you need to know what a validating public resolver sees, not what your local resolver cached. It is also the fastest way to check a record from a locked-down host where dig is not installed and outbound port 53 is filtered.
Know before you rely on it. Send the dns-json accept header when scripting. One resolver's view only, so use Dig Web Interface when you need to compare several.
test-ipv6.comRuns a battery of browser-side connectivity tests against IPv4-only, IPv6-only and dual stack names, checks whether your resolver can reach IPv6-only authoritative servers, and separately tests large packets to expose path MTU discovery problems and filtered ICMPv6. It reports the service provider seen on each address family.
When to reach for it. The moment a provider claims a circuit is IPv6 enabled, and any time an application works over IPv4 but stalls or hangs over IPv6. The large packet tests are the fastest way to catch a tunnel or firewall that is silently dropping the ICMPv6 messages path MTU discovery depends on.
Know before you rely on it. It measures the whole chain from browser to internet, so a bad result may be the client, the LAN, the firewall or the circuit, in that order of likelihood. Run it from a wired host with no VPN before you take the result to a carrier. Maintained by an individual and the code has been quiet for a while, though the tests work.
Learn and Test DMARCYou send a real message to their tester address and it visualises the entire receiving-side evaluation: the SMTP connection, the SPF check, every DKIM signature, and how DMARC alignment is computed from each. It separates the authentication result from the alignment result, which is the distinction nearly every other tool blurs.
When to reach for it. When DMARC is failing and you cannot work out why, especially the classic case where SPF passes but does not align because the envelope sender and the header From are different domains. Also the best thing to hand a colleague who does not yet understand DMARC.
Know before you rely on it. Requires you to actually send mail from the system under test, so it will not help from a host that cannot reach port 25 outbound. Sponsored by a DMARC monitoring vendor whose product is promoted on the page, and the full visual explanation needs a desktop browser.
Mailhardener toolsA set of validators that check mail records against the text of their RFCs, including several almost nobody else offers free: MTA-STS policy and DNS validation, SMTP TLS Reporting, BIMI and DANE TLSA. Also covers MX, SPF, DKIM and DMARC inspection plus generators and a DNS record splitter for over-long TXT values.
When to reach for it. Reach here the moment MTA-STS, TLS-RPT or DANE is involved. Generic mail lookup sites will not tell you your MTA-STS policy file is unreachable or malformed; this will.
Know before you rely on it. Made by a commercial mail monitoring vendor, though the tools need no account and return complete results. Navigate from the tools index rather than guessing URLs, since constructed slugs return 404.
MultiRBLQueries a very large set of DNS blacklists, whitelists and informational lists for an IP or domain in one shot, and separately runs a forward-confirmed reverse DNS check. It labels informational entries distinctly so you do not mistake them for blocks.
When to reach for it. When outbound mail from a business circuit is being rejected and you need to know whether the sending IP is actually listed anywhere, or whether the real problem is that its PTR does not forward-confirm. Especially relevant after an ISP reassigns your static block.
Know before you rely on it. Plain, dense interface, and it aggregates lists of wildly varying quality. Treat a hit as a pointer, then confirm and pursue delisting at the list operator itself, never here. Run by one person on donations.
Microsoft Message Header AnalyzerPaste raw message headers and it parses them into a readable table, reconstructing the delivery path hop by hop with the delay introduced at each one, and breaking out the authentication and anti-spam headers that mail systems stamp.
When to reach for it. When mail is arriving but arriving late and you need to prove which hop is adding the delay, particularly on a path that crosses a hosted Exchange tenant. It is also the quickest way to read the authentication results header a receiver actually stamped.
Know before you rely on it. Hosted on a generic cloud hostname rather than a product domain, so bookmark the GitHub project as your durable reference. It also ships as an Outlook add-in; the hosted page needs no install.
SwaksA scriptable SMTP client that lets you drive a mail transaction by hand: pick the transport, force STARTTLS, supply authentication, and watch the full protocol dialogue. It speaks SMTP, ESMTP and LMTP over UNIX sockets, IPv4, IPv6 or a spawned process.
When to reach for it. When you need to prove whether a mail server accepts a connection, negotiates TLS and authenticates, from a specific source address. Nothing web-based can test outbound SMTP from inside your own network the way this does, which is exactly what you need when an ISP is silently blocking port 25.
Know before you rely on it. Mature and slow moving, so do not expect new features. Note that swaks.org is not the project site and has nothing to do with SMTP.
Qualys SSL Labs SSL Server TestPerforms a deep analysis of a public TLS server's configuration and returns a letter grade plus the full detail: protocol and cipher support, certificate chain and trust problems, key exchange strength, and known protocol vulnerabilities. It also simulates a range of real client platforms.
When to reach for it. The canonical answer to whether a TLS configuration is acceptable, and the one auditors and customers will cite back at you. The client simulation section tells you which older devices will fail to connect after you disable a protocol.
Know before you rely on it. Results are published to a public board unless you tick the do-not-show option before scanning. Concurrency is capped per source, so do not batch scans against it, and the criteria version string is deliberately stable rather than an indicator of staleness.
testssl.shA single shell script that tests any TLS or STARTTLS service on any port for protocol and cipher support, certificate problems and known cryptographic flaws. No dependencies beyond bash and openssl, with JSON, CSV and HTML output and a published container image.
When to reach for it. When the target is not reachable from the public internet, or is not a web server. This is how you test TLS on an internal mail server, an LDAP endpoint or a management interface that a hosted scanner can never reach, and the results never leave your machine.
Know before you rely on it. Two branches are published. Take the stable tarball unless you specifically need a check that only exists in the development snapshot.
SSLMate Cert SpotterSearches the Certificate Transparency logs for every certificate issued for a domain and its subdomains, returning the issuer, the full alternative name list, validity dates and revocation status as structured JSON over a documented API.
When to reach for it. When you need to enumerate every hostname a certificate has been issued for, confirm a renewal actually got logged, or spot a certificate nobody on your team requested. This is the reliable one to automate against for certificate inventory and expiry checks.
Know before you rely on it. The unauthenticated API is rate limited and a free API key raises the limit. Continuous monitoring and alerting on new issuance is the paid product, but the search itself is not gated. Chosen here over crt.sh, whose public instance returned gateway errors on both attempts during this review.
whatsmydns.netResolves a chosen record type for a hostname against dozens of public resolvers around the world at once and shows each resolver's answer side by side, with location and operator, so you can see how far a change has actually spread and which networks are still serving the old answer.
When to reach for it. During a cutover, when an A, MX or NS record has changed and you need to know whether the old answer is still live somewhere, or when one office resolves a name correctly and another does not and you need to show which resolvers disagree.
Know before you rely on it. It reports what public resolvers currently hold, which is a cache state, not authoritative truth. For the authoritative view and for DNSSEC chain problems, use the delegation and DNSSEC tools already on the list.
Spamhaus IP and Domain Reputation CheckerQueries Spamhaus's own blocklists for a single IP, domain, ASN, SBL reference, email address or hash and reports whether it is listed and why, with the route to request removal. This is the operator of the lists themselves, so the verdict here is the one that decides whether mail is being blocked.
When to reach for it. When business mail from a newly provisioned circuit or a freshly assigned address block starts bouncing, and you need to know whether the sending address is listed at the list most receivers consult, or whether an address block a provider just handed you carries someone else's history.
Know before you rely on it. The site puts a bot verification interstitial in front of the lookup. It clears on its own after a few seconds in a normal browser, but scripted access will not get through, and the page will look broken for a moment.
Let's DebugDiagnoses why a Let's Encrypt certificate will not issue for a given domain. It runs tests aimed specifically at the ACME issuance path: basic DNS setup, nameserver problems, DNSSEC failures and resolver timeouts, rate limits, network reachability, CA policy issues, bad or unreachable HTTP redirects and common web server misconfigurations. Web form plus an API, and the checker itself is open source.
When to reach for it. On a freshly provisioned circuit where certificate issuance fails and you cannot tell whether the cause is the firewall, a CAA record, a redirect or the resolver. It names the specific failure instead of leaving you to guess.
Know before you rely on it. Reachability is inconsistent. The host did not answer at all from two separate networks tested during this review, including mine, while serving normally from a third. Confirm it loads from your own network before you rely on the link.
Packet capture and protocol analysis
When the measurement tools disagree with the users, capture the traffic. This is the layer where you stop arguing about what the network is doing and read what it actually did, and it is what a carrier escalation team will ask for once the obvious tests come back clean.
WiresharkThe standard graphical packet analyser: capture live traffic or open a capture file and decode it against thousands of protocol dissectors, follow a TCP stream, filter on any field, and use the built in expert info and throughput, round trip time and retransmission graphs to see what the conversation actually did.
When to reach for it. When throughput and latency tools have not settled it, or when the failure is application shaped: TLS handshakes that stall, SIP calls that set up and drop, DNS answers that never arrive, MTU black holes, or a firewall silently resetting sessions. It is also the tool that turns a carrier's assertion into evidence, because a capture from both sides of a circuit shows exactly which side stopped sending.
Know before you rely on it. Capturing production traffic has real privacy and policy implications, so get authorisation before you tap. You need a span port, a tap or a capture on the endpoint itself, since a switch will not show you traffic between other ports. For unattended or remote capture use its bundled command line tools rather than the GUI, and analyse large files on a machine with memory to spare.
tcpdump and libpcapThe command line packet capture tool and the portable capture library nearly everything else is built on. It captures to a file with a BPF filter expression, rotates files by size or time, and prints decoded packets on the terminal.
When to reach for it. The right way to capture from a router, firewall, appliance or headless server where you cannot install a GUI, and the safe way to grab evidence during a live incident with a filter narrow enough not to fill the disk. Capture with this, then analyse the file in Wireshark.
Know before you rely on it. A wrong filter costs you the incident, so write and test the filter expression before you need it, and always cap the file size or duration. Same authorisation and privacy considerations as any capture.
Monitoring you run yourself
Continuous visibility you own, which is the only kind that is still there when the vendor dashboard is the thing that is down. Host it somewhere other than the site it watches.
Uptime KumaSelf hosted uptime monitor covering HTTP and HTTPS, keyword and JSON query checks, TCP port, ping, DNS record, WebSocket, push and container monitors, with public status pages mappable to your own domains and a long list of notification integrations.
When to reach for it. When you want honest uptime numbers on your own circuits and services without handing a vendor your endpoint list or paying per monitor. Run an instance per site and you can prove which location actually lost connectivity.
Know before you rely on it. MIT licensed and self hosted, so the availability of the monitor is your problem. A monitor sitting inside the network it watches cannot report on that network's own outage, so host it elsewhere and ideally have two instances watch each other.
UptimeRobotHosted external monitoring for HTTP and HTTPS, ping, TCP port, keyword, DNS record change, SSL and domain expiry, cron job execution and response time degradation, with alerting by email, SMS and mobile app. Public status pages and integrations are included on the free plan.
When to reach for it. When you need an outside view of whether your office or branch circuits are reachable and you do not want to run infrastructure to get it. The free plan is large enough to cover every site in a small multi location business.
Know before you rely on it. An account is required, though there is no sales call, demo request or gated form. The free plan polls at a multi-minute interval, so brief flaps are missed and it will not give you the second level timing you would want to support an SLA credit claim. Faster intervals are paid.
LibreNMSFull network management system that autodiscovers your topology via CDP, LLDP, FDP, OSPF, BGP, SNMP and ARP, then polls interfaces for traffic, errors and availability and alerts on them. Includes an API, distributed polling and port based bandwidth billing.
When to reach for it. When you have more than a handful of switches, routers or firewalls and need to know which interface is saturated or erroring before users call. The bandwidth billing feature is genuinely useful for checking a burstable circuit invoice against your own port counters.
Know before you rely on it. Self hosted, needs a real server and SNMP access to your devices, and there is no hosted service from the project itself. It monitors equipment you control, so it stops at your demarc and tells you nothing about your provider's network beyond it.
ntopngTraffic analysis probe that gives real time top talkers, per host historical timeseries and layer 7 application breakdown across hundreds of protocols, from a mirrored or spanned interface. It answers what is actually consuming a circuit, by host and by application, rather than just how much.
When to reach for it. When the circuit is up but slow and you need to name what is eating it, or when you have to justify a bandwidth upgrade with evidence about which applications and hosts drive the peak.
Know before you rely on it. Important correction to how this is usually described. The GPLv3 community edition covers real time visibility, top talkers, layer 7 detection, per host timeseries and alerting, but the vendor's own edition comparison places NetFlow and sFlow statistics, historical reports and extended SNMP in the paid tiers, and collecting flows from routers generally requires a separate paid probe. Treat the free edition as a span port tool, not a flow collector.
ObkioContinuous synthetic network performance monitoring built around site to site paths. Lightweight software agents at each end measure latency, jitter, packet loss and quality of service between them continuously, with visual traceroutes, SNMP device monitoring and application performance monitoring alongside.
When to reach for it. When the carrier says the circuit is clean and the users say calls are breaking up. Two agents at either end of the path produce continuous timestamped evidence for the path itself, which is what a provider will actually act on, and you get it without deploying your own monitoring stack.
Know before you rely on it. The free plan is capped at two software agents, which is one monitored path, not a fleet. Signup is required before you can see the product, and after the trial the account drops to the free plan with any extra agents disabled.
Capacity planning and design
The arithmetic to do before you order the circuit, and the documents to cite when the delivered service does not behave the way the quote implied.
Visual Subnet CalculatorTakes a parent network in CIDR notation and lets you recursively divide and rejoin it into a complete subnet plan, showing address range, netmask, usable IPs and hosts per subnet in one table. The whole split encodes into a bookmarkable URL, so an address plan can be sent to a colleague as a link.
When to reach for it. When you are carving a block into unequal site, VLAN and point-to-point subnets and need to see the entire plan at once. Ordinary subnet calculators answer one prefix at a time and cannot show you where you have wasted space.
Know before you rely on it. IPv4 only, and it is a planning aid rather than a record. Once the plan is real it belongs in an address management system.
WintelGuy Network Throughput CalculatorEstimates achievable TCP throughput from link bandwidth, round-trip time, packet loss, MTU and TCP receive window, then turns that into a file transfer time. It reports bandwidth-delay product and the minimum window needed to fill the pipe, and separates throughput limited by loss from throughput limited by window size.
When to reach for it. When someone bought a gigabit circuit and a single transfer runs at a fraction of it. This is the calculation that proves the limit is latency and window size rather than the circuit, and it sizes what a long-haul or replication link will really deliver before you order it.
Know before you rely on it. A theoretical model, not a measurement, and the loss-limited figure uses the Mathis formula. Feed it real round trip time and loss from the actual path or the answer is decorative.
WintelGuy WAN Latency CalculatorBuilds a latency budget for a point-to-point WAN link from physical distance, a fibre route adjustment for the fact that fibre does not run straight, local loop length, speed of light in fibre and per-hop equipment delay. Outputs expected round-trip time.
When to reach for it. Before you order a circuit between two sites, or when a provider's quoted latency looks optimistic. It separates propagation delay you cannot fix from equipment delay you can, which is the argument you need when a carrier blames the application.
Know before you rely on it. You supply the distance yourself, so use real fibre route mileage if you have it, because straight-line distance flatters the result. The page notes real application latency will run higher once protocol overhead, queuing and retransmissions are included.
RFC 6349, Framework for TCP Throughput TestingDefines the standard methodology for proving what TCP throughput a managed IP circuit actually delivers: find the path MTU, establish baseline round trip time and bottleneck bandwidth, compute the bandwidth-delay product, size socket buffers to at least that, then measure. It defines Transfer Time Ratio, TCP Efficiency Percentage and Buffer Delay Percentage as the reporting metrics.
When to reach for it. When a carrier says the circuit tests clean at layer 2 and your transfers still crawl. This is the document that says a layer 2 or layer 3 test is not evidence of user-visible throughput, and it gives you a named, citable procedure to demand instead.
Know before you rely on it. Informational rather than standards track, so a carrier is not obliged to test this way, and it is a methodology document rather than a tool you run. The maths is physics and has not aged.
Uptime.is SLA and Uptime CalculatorConverts an availability percentage into allowed downtime across daily, weekly, monthly, quarterly and yearly windows. Beyond the simple mode there are flexible, compare and reverse modes, and the flexible mode lets you define the measurement window per weekday instead of assuming continuous operation.
When to reach for it. When a carrier quotes an availability figure in an SLA and you need to know what it actually permits. The flexible mode is the one that matters for business connectivity, because it lets you model an SLA measured only against the hours the site is trading.
Know before you rely on it. Presets are a starting point only. Read the contract for how the carrier defines a qualifying outage and its measurement window, since that usually matters more than the percentage.
Microsoft Teams network preparation and bandwidth requirementsPublishes per-endpoint bandwidth requirements for audio, video and screen sharing at minimum, recommended and best-performance tiers, separately for one-to-one and meeting scenarios, plus a per-viewer figure for large events without an eCDN. It also covers split-tunnel VPN, QoS, NAT pool sizing, session persistence and Wi-Fi band planning.
When to reach for it. Sizing a circuit for an office where video conferencing is the real load, or justifying why the VPN concentrator is the problem rather than the circuit. It is the vendor's own published figure, which is what a procurement discussion needs.
Know before you rely on it. Platform specific, and figures are per endpoint, so a user on both a laptop and a phone counts twice. The Network Planner it points to runs inside the admin centre and requires tenant administrator access, so it is not something a reader can just open.
Zoom system requirements and bandwidthThe vendor's own published bandwidth requirements, given separately for one-to-one and group video at each quality tier including high definition, with distinct up and down figures, plus screen sharing with and without a video thumbnail and audio-only VoIP.
When to reach for it. The counterpart to the Teams figures, and the one that matters when this is the platform actually in use. Group calling has asymmetric up and down requirements, which is the detail that decides whether an asymmetric access product is acceptable at a branch.
Know before you rely on it. Vendor figures, and the platform adapts to available bandwidth, so these are targets for good experience rather than hard floors.
RIPE-690, IPv6 prefix assignment for end-usersThe community best current operational practice on how large an IPv6 prefix to hand a customer site and whether it should be persistent, with the reasoning behind the common sizes, why longer prefixes are strongly discouraged, and how to number the operator-to-customer link.
When to reach for it. When you are designing an IPv6 address plan across multiple sites, or when a provider offers you a prefix and you need to know whether it is big enough and stable enough to build on. Renumbering later is the expensive outcome this document exists to prevent.
Know before you rely on it. Written from the operator's point of view and now several years old. Confirmed still in published status and not superseded, but treat the sizing guidance as the durable part.
IANA Differentiated Services Field Codepoints registryThe authoritative list of DSCP codepoints, giving each name with its binary and decimal value and the RFC that defines it, split into the three assignment pools. It also documents the ECN bits in the same field.
When to reach for it. When you are writing a QoS marking plan and need the codepoint values to be right and citable, or when a carrier's class map does not match what your edge is marking. Vendor documentation frequently paraphrases this and occasionally paraphrases it wrong.
Know before you rely on it. A registry, not a design guide. It tells you what the codepoints are, not which classes your traffic belongs in, so pair it with the relevant RFC and your carrier's own class-of-service mapping.
NetBoxOpen source source-of-truth platform that models IP address space, prefixes and VLANs alongside racks, devices, cabling, power, circuits and VPNs, with a UI and programmable APIs. It is where a growing address plan and circuit inventory lives once a spreadsheet stops working.
When to reach for it. When you are planning addressing and circuits across more than a handful of sites and need one authoritative record that both the design and the automation read from. Also the practical way to track carrier circuit IDs, terminations and cross-connects per site.
Know before you rely on it. Self-hosted software, not a web calculator, so there is real setup effort, and it documents infrastructure rather than talking to devices. The netbox.dev domain redirects to the commercial sponsor's site, so link the Apache licensed repository directly.
cloudping.infoMeasures HTTP latency from your own browser to endpoints across dozens of cloud regions from several providers in a single pass. The result is latency from where you actually are, not from a probe somewhere else.
When to reach for it. When you are choosing which cloud region to host in for a given office or plant, or sanity-checking a latency claim before committing to a region. Run it from the site in question rather than from headquarters, since that is the whole point of a browser-side measurement.
Know before you rely on it. HTTP ping from a browser, so it includes TLS and browser overhead and is not equivalent to ICMP round trip time. Treat it as comparative rather than absolute, and note that one major provider was showing as unavailable when checked.
WonderNetwork Global Ping StatisticsA live matrix of measured ping times between cities worldwide, each figure an average of repeated pings, with the city list configurable so you can build the exact matrix you need. Drilling into a city pair gives a timestamped history with average, minimum, maximum and median deviation.
When to reach for it. When you need a real-world latency figure between two metros for a WAN design or an SLA conversation and you have no circuit to measure yet. Compare it against a theoretical propagation figure from the latency calculator to see how much of the budget the carrier's routing is eating.
Know before you rely on it. Measured between the operator's own servers, so it reflects their transit paths rather than the path your circuit will take, and some pairs show no data where probes are blocked. The site asks you not to scrape it and offers a downloadable day of data instead.
ipcalcCommand line IPv4 and IPv6 address calculator. Prints network address, broadcast, usable host range, netmask, prefix length and address count for a block, with per field flags so a script can pull one value instead of parsing a report. Deaggregates arbitrary ranges into CIDR blocks, and adds geographic lookup when built against libGeoIP.
When to reach for it. Carving an assigned block into site subnets, checking the handoff prefix a provider proposed against how many usable hosts you actually get, or doing address arithmetic inside a provisioning or IPAM script where you need one clean value on stdout.
Know before you rely on it. No tagged release since 1.0.3 even though master has moved on, so a distribution package may lag the repository. Builds with Meson and Ninja. It replaced the original ipcalc in Fedora, so on that platform you may already have it. Licensed GPL v2.
Data centres, interconnect and cloud on-ramps
Which carriers are lit in a building, which exchange is worth joining, and where you have to be physically located to reach a given cloud. The cloud vendors publish better facility-to-carrier cross references than most colocation directories do.
PeeringDBThe industry's self maintained register of who interconnects where. Each network record carries its ASN, traffic profile, peering policy, the exchanges it is present on and the facilities it occupies, and each exchange, facility, carrier and campus record lists its participants, with a fully open read API.
When to reach for it. When the site in question is a data centre or carrier hotel and the real question is which carriers you can cross connect to without a build. It answers who is on-net in this building in seconds, which no government dataset does, and it is the fastest sanity check on a carrier's claim to serve a facility.
Know before you rely on it. Entirely self reported by facility operators and networks, so absence is weak evidence and carrier lists skew toward operators that care about peering. A listed carrier may still have no spare capacity to your suite. Browsing and advanced search work logged out, but some filters need an account and large result sets are truncated.
IXPDBA live database of internet exchange points assembled automatically from the exchanges' own management systems, covering connected networks, port capacity, actual traffic utilisation, switch architecture and routing security status, with a per record last updated stamp and a free API.
When to reach for it. When PeeringDB tells you a network is present at an exchange but you need to know how big and how busy that exchange actually is before committing to it. It is the traffic and utilisation layer PeeringDB deliberately does not carry.
Know before you rely on it. Coverage depends on the exchange feeding data in, so smaller and less automated exchanges are thinner here than in PeeringDB. Use both.
Azure ExpressRoute locations and connectivity providersLists every peering location with the exact colocation facility it sits in, the cloud regions reachable locally from it, whether direct high capacity ports are supported, and the full carrier list that can deliver a circuit into that facility. Separate tables cover exchange providers, satellite operators and system integrators.
When to reach for it. The single most useful public cross-reference of colocation facility to carrier list. Even when this cloud is not the destination, it tells you which carriers are lit in a named building, which is exactly the question when you are choosing a site or shortlisting providers to quote.
Know before you rely on it. Carrier lists reflect this vendor's partnerships, so a carrier absent here may still serve the building for ordinary transport. Facility naming is the vendor's own, so cross-check against PeeringDB before you rely on it commercially.
AWS Direct Connect LocationsLists every Direct Connect location worldwide by geography, naming the specific data centre and city, the associated region, available port speeds and MACsec support. It also flags campus settings where a standard cross-connect from a neighbouring building reaches the same on-ramp.
When to reach for it. When you are picking where to land a private circuit to this cloud, or checking whether the colocation facility you already occupy is itself an on-ramp before you pay for transport to another one.
Know before you rely on it. Lists locations, speeds and MACsec but not which carriers serve each one. It points to a separate partner list rather than naming carriers per facility, so cross-reference PeeringDB or the Azure locations table for that.
Google Cloud Dedicated Interconnect colocation facilitiesLists the colocation facilities where you can order a dedicated interconnect, giving metro area, a metro availability zone identifier, the named facility and operator, which locations count as low-latency for a given region, and supported link speeds with MACsec flags. Many facility names link straight through to their PeeringDB entries.
When to reach for it. Designing a redundant on-ramp, where you need two facilities in different metro availability zones rather than two circuits into the same building. The zone identifiers are the detail that makes a design actually resilient rather than nominally redundant.
Know before you rely on it. The vendor does not publish which carriers are present and explicitly tells you to ask the facility operator or check PeeringDB. Note the URL: the old cloud.google.com path redirects to the docs host, so link the docs host directly.
Voice, VoIP and numbering
Sizing voice, defending its quality budget, and finding out who actually carries a number. For measuring live call quality, use irtt from the path diagnosis section, because it generates the traffic pattern voice actually produces.
Erlang B Calculator (Westbay Engineers)Solves the Erlang B relationship between busy hour traffic in Erlangs, blocking probability and number of lines: supply any two and it returns the third. This is the standard maths for sizing a trunk group or a SIP channel count.
When to reach for it. When you have to decide how many concurrent voice paths to buy and do not want to guess. Pair the line count it returns with a per-call bandwidth figure to size the circuit that carries the calls.
Know before you rely on it. You need a busy hour traffic figure from your phone system or call records for the answer to mean anything. The web calculator is free and unmetered; the same vendor sells spreadsheet and desktop versions and promotes them on the page.
PlanetCalc VoIP Call BandwidthComputes bandwidth and packets per second for a given codec and number of concurrent calls, with selectable IP version, layer 2 media and the OSI layer you want the answer at, from physical layer up to RTP payload. It prints the formula and the byte-by-byte header overhead it uses.
When to reach for it. When you need a defensible per-call bandwidth number rather than a vendor's rounded one, especially where layer 2 overhead matters, such as sizing a small circuit or a QoS voice queue. Seeing the formula means you can reproduce the result in a spreadsheet and defend it in a design review.
Know before you rely on it. Codec list and overhead assumptions are yours to set correctly. Garbage in still applies.
ITU-T Recommendation G.114, One-way transmission timeThe international standard on one-way transmission delay for voice, with an amendment adding an appendix specifically on one-way delay guidance for Voice over IP and another covering delay variation on unshared access lines. It is the document everyone is implicitly citing when they argue about acceptable voice latency.
When to reach for it. When you need an authoritative delay budget for a voice design, or a citation in a dispute with a carrier, rather than a vendor blog post. Cite the recommendation, not the folklore.
Know before you rely on it. A standards document, not a calculator. Link the recommendation index rather than a single edition, since several earlier editions are marked superseded and the VoIP guidance sits in an amendment rather than the base text.
NANPAThe North American Numbering Plan Administrator's site, publishing area code relief planning and exhaust projections, central office code and thousands-block assignment reports, carrier identification codes, and a machine-readable master area code file.
When to reach for it. When planning a multi-site voice deployment and you need to know whether an area code is heading for an overlay or split, whether a location already requires ten digit dialing, or who is behind a carrier identification or central office code.
Know before you rely on it. The older nationalnanpa.com domain is dead, so old bookmarks fail. Partly gated: real-time available and utilized code reports run through a secure site and detailed relief planning documents need industry access. The published reports, exhaust projections and area code data file are open to anyone.
Local Calling GuideA free, actively maintained front end to LERG-derived numbering data: prefix lookups returning the serving carrier, operating company number, switch CLLI, LATA and rate centre with coordinates, plus rate centre and switch searches, dial plans and dial-around carrier codes. It exposes data that otherwise sits behind a commercial subscription.
When to reach for it. When you need to know which carrier and switch a number block routes to, whether two locations share a rate centre, or which LATA a site sits in for interconnection purposes. The practitioner's shortcut when a full LERG licence cannot be justified.
Know before you rely on it. Community run and donation supported, not an official administrator, so treat it as a convenient view of LERG-derived data rather than the licensed source of record. Effective-date searches work only for US area codes because its other sources do not carry that field.
FCC Intermediate Provider RegistryThe FCC's registry of intermediate providers authorized to carry voice traffic between originating and terminating carriers, published as a queryable dataset with business name, prior names, states served, and regulatory and rural call completion contacts.
When to reach for it. When a SIP trunking or long distance vendor is quoting you and you want to confirm they are registered and see which states they claim to serve. Also the fastest way to find a named regulatory or rural call completion contact when calls to a rural site are failing.
Know before you rely on it. It records that a provider registered and what it claimed, not service quality or whether a specific route is any good. Some rows have empty contact fields.
NANPA public numbering reports, thousands-block and CO codeTwo free public reports from the North American Numbering Plan Administrator. The interactive Thousands-Block Report takes a state, area code and named rate centre and returns every 1,000 number block with its status, the carrier holding it, the service provider it was assigned to, contamination flags and assignment dates, with an XLSX export. The Central Office Code Assignment Records are the bulk companion, giving every NPA-NXX with its operating company number, company name, rate centre, pooled flag and in-service flag, plus separate files listing codes still available.
When to reach for it. Sizing a DID range or choosing a rate centre for a new SIP trunk or PRI build, and confirming numbers actually exist in a market before you commit to a cutover date. Also the free way to see which carrier really holds the block a ported number sits in when the losing carrier and the winning carrier are telling you different stories.
Know before you rely on it. This is the correction to the brief's own nomination. The FCC's Telephone Numbering Data reports are current but their finest geography is the area code, so they cannot answer a rate centre question. NANPA can, and it is rebuilt daily. Two traps in the bulk files: the Available files carry only state and NPA-NXX, not rate centre, so the rich field layout applies to the Utilized files, and the current Utilized filenames end in _Public. There is no CLLI, switch type or tandem field anywhere here, and NANPA states its files do not include everything needed for routing and billing.
Ofcom numbering dataThe UK national numbering data as weekly downloads. Which number blocks are free and which are allocated, and to whom, across the geographic 01 and 02 ranges and the 03, 055, 056, 07, 08 and 09 ranges, plus a rolling twelve month record of transfers, plus the administrative code sets that porting and interconnect actually run on: number portability prefix codes, mobile portability codes, communications provider identity codes, carrier pre-selection codes, reseller identification codes, mobile network codes and partial calling line identity codes.
When to reach for it. UK porting and SIP work. Identifying the range holder behind a block before you raise a port, checking whether numbers remain free in a geographic area code, and getting the prefix and provider identity codes the porting process needs. There is no UK equivalent elsewhere and nothing on the existing list covers UK numbering at all.
Know before you rely on it. Ofcom's site sits behind a bot challenge that returns HTTP 403 to scripted fetches. It opens normally in a browser. This is allocation data at block level: it tells you who holds a range, not whether an individual number has been ported.
Clearfly VoIP Bandwidth CalculatorComputes VoIP bandwidth per call and in aggregate from three inputs, and shows the derivation rather than only the answer. It separates codec payload from IP, UDP, RTP and WAN header overhead, reports the result per packet interval, per call and in total, adds an estimate for signalling on top of media, and draws a byte level packet layout so you can see where the overhead lands.
When to reach for it. Sizing a circuit before a VoIP or SIP trunk cutover, or checking a carrier's quoted bandwidth figure against the underlying packet arithmetic when you need to show your working in a dispute.
Know before you rely on it. Published by a SIP trunking carrier. The arithmetic is codec generic, but the page fixes the packetisation interval at 20 ms, so confirm that matches your deployment before relying on the totals.
Cisco: Modify Bandwidth Consumption Calculation for Voice CallsThe canonical vendor reference for per call VoIP bandwidth. It states the header assumptions explicitly, gives the bandwidth formulas and a worked sample calculation, then covers how to change voice payload sizes on Call Manager and on IOS gateways and what voice activity detection and compressed RTP do to the total.
When to reach for it. When you want the formula and the stated header overhead rather than a calculator's answer, or when you need a citable source in a design document or a bandwidth dispute with a carrier.
Know before you rely on it. Cisco centric in the configuration sections. The arithmetic and header assumptions are general; the payload size configuration steps are not. Document ID 7934, last updated December 11, 2023, so it predates nothing that matters here but check codec assumptions against your own platform.
Registries, regulators and standards
The primary sources. Reach for these when a vendor cites a number at you, when you need to know who really holds an address block, or when a contract references a specification you have never read.
ARIN Whois and RDAPThe North American registry lookup for IP blocks, ASNs, organizations and reverse DNS delegations. It auto-detects what you typed and returns the registered holder, allocation type and points of contact including abuse.
When to reach for it. When you need to prove who actually holds the address space behind a circuit, confirm a carrier owns the ASN it claims, or find a real abuse contact for a network causing you grief. The RDAP endpoint is the scriptable version of the same answer.
Know before you rely on it. Covers the US, Canada and parts of the Caribbean only; queries for other regions refer you to another registry. Search needs no account despite the login link, and all requests are subject to the registry's terms of use.
RIPE DatabaseThe registry of record for European, Middle Eastern and Central Asian address space and ASNs, and the home of the route, route6 and as-set objects that express routing policy. Queryable through a web UI or a plain REST API returning JSON or XML.
When to reach for it. When a circuit, transit provider or peer sits in that region, or when you need the routing policy objects behind a prefix rather than just its ownership. Go straight to the REST endpoint for bulk or scripted resource checks.
Know before you rely on it. The web UI is a JavaScript app and will not render for scrapers. If you are scripting, use the REST host, which returns structured data with no browser involved.
RDAP.orgA bootstrap endpoint that works out which registry is authoritative for a domain, IP address or ASN and redirects your query there. It saves you from hardcoding five regional registry endpoints and every domain registry.
When to reach for it. When you are scripting lookups of arbitrary internet resources, or when you have an IP and no idea which region it belongs to and want one URL that always works.
Know before you rely on it. The homepage redirects to a documentation site; the query paths are what you actually use. It is a redirector over published bootstrap data, so its coverage is only as good as what registries publish.
NRO and RIR Delegated StatisticsThe daily bulk files in which every regional registry publishes every IPv4, IPv6 and ASN delegation it holds, with country code, allocation date and status, plus a single combined file. It is the raw data behind almost every address-space report you have ever read.
When to reach for it. When you need address-space data in bulk rather than one lookup at a time: mapping a carrier's full footprint, building a country-level allocation view, or auditing which prefixes a provider actually holds.
Know before you rely on it. These are flat text files you have to parse, and the country code reflects registration rather than where addresses are used. The landing page is partly rotted, with several per-registry links pointing at FTP URLs modern browsers no longer open, so skip the page and go to the HTTPS file paths.
IANA Protocol RegistriesThe authoritative record of protocol parameter values: TCP and UDP service names and port numbers, EtherTypes, ICMP types, BGP path attributes and hundreds more. Each registry is published as browsable HTML plus downloadable CSV, XML and text, with bulk retrieval over rsync.
When to reach for it. When you need to settle what a port number or parameter value actually means and you want the source the RFCs themselves point to rather than a wiki table.
Know before you rely on it. Reference data, not guidance. It tells you what a value means, not whether your firewall should permit it.
RFC EditorThe free, complete archive of every RFC, with status classification, errata and a full index. This is the document set that connectivity contracts, test plans and vendor claims ultimately cite.
When to reach for it. When you need the normative text rather than someone's summary. Reach here the moment a vendor cites an RFC number at you.
Know before you rely on it. The text does not tell you whether a document is still current. Check the Datatracker entry for that.
IETF DatatrackerTracks the lifecycle and current standing of every IETF document: what obsoletes what, what updates what, what is still an expired draft, and which working group owns it. It answers the one question the RFC text itself cannot, which is whether the document is still current.
When to reach for it. Before you rely on an RFC someone quoted at you, and when you need to know whether a protocol a vendor is selling is a ratified standard or an individual draft that lapsed.
Know before you rely on it. Process oriented, so it will tell you a document's standing but not interpret it for you.
RFC 8805, self-published IP geolocation feedsDefines the CSV geofeed format by which a network operator publishes the country, region and city it intends each of its prefixes to be treated as serving, and how consumers of geolocation data retrieve it.
When to reach for it. When a new circuit's addresses geolocate to the wrong city and applications start behaving as though the office moved. This is the document to send the provider, because publishing a geofeed is the actual fix and it is cheap for them to do, whereas asking each geolocation vendor individually is not.
Know before you rely on it. Informational rather than standards track, and publishing a feed only helps once data consumers ingest it, which takes time and is not guaranteed for every vendor an application might use.
ITU-T RecommendationsThe canonical specifications for transmission systems and network performance, free as PDFs. The G series covers transmission systems and media, the Y series covers IP network performance and QoS classes, the P series covers telephone transmission quality.
When to reach for it. When an SLA or an RFP references a standard by number and you need the real definition, for example the physical interface, error performance, one-way delay, IP QoS class and Ethernet service activation specifications. This is the ground you argue from when a circuit misses its contracted performance.
Know before you rely on it. A minority of texts jointly developed with other standards bodies are not free. Search routes through a clumsy workspace application, so it is faster to go directly to the per-recommendation URL pattern.
Mplify (formerly MEF) Technical StandardsThe Carrier Ethernet and related service standards library, free to download. This is where E-Line, E-LAN, E-Tree and E-Access are defined, along with the service attributes that appear on every Ethernet circuit quote.
When to reach for it. When you are comparing Carrier Ethernet quotes and need a neutral definition of a service attribute, or writing an RFP and want to specify a service in terms both carriers already understand. Also the reference for what a certification claim actually covers.
Know before you rely on it. The organisation rebranded and the old mef.net URLs now redirect, so older citations and bookmarks point at the previous domain. The index page states no access terms anywhere, which is why the PDFs are the thing to test.
Broadband Forum Technical ReportsThe free technical report library covering broadband access architecture and device management, including the remote management protocols and data models that define how a carrier provisions and manages the equipment at your site.
When to reach for it. When you need to know what a provider's managed router can actually be configured to do remotely, or when troubleshooting an access architecture and you want the reference model rather than the vendor's diagram.
Know before you rely on it. The library URL redirects into a filtered view and the site returns 403 to some automated fetchers even though it loads normally in a browser. The PDFs themselves sit at predictable paths and download without that friction.
FCC Universal Licensing System bulk dataNightly complete dumps of every FCC wireless license record, including the microwave and common carrier fixed point-to-point files and the antenna structure files. It tells you who is licensed to run a fixed wireless path, on what frequency, from which structure.
When to reach for it. When evaluating fixed wireless for a site and you need to know who already holds licensed spectrum and paths there, or when investigating interference on a licensed microwave link. Far more complete than any commercial wrapper around the same data.
Know before you rely on it. These are large zipped pipe-delimited files you have to parse, not a search interface. The interactive licence search returns 403 to automated requests, though it works normally in a browser.
FCC Electronic Comment Filing SystemThe public docket system holding every comment, petition and ex parte filing in FCC proceedings, with a free JSON API over the same corpus. Carrier positions on copper retirement, special access pricing, pole attachments and network transitions are argued here in the open.
When to reach for it. When you need what a carrier has formally told the regulator rather than what its sales team says. Useful for tracking copper retirement notices affecting a site, or reading a pending rule change before it lands in your contracts.
Know before you rely on it. The web interface sits behind bot protection and returns 403 to automated requests, though it works in a normal browser. The API accepts a free public key.
CableLabs SpecificationsThe published specification library behind DOCSIS, CableLabs PON and the coherent optics work. Each document has a detail page carrying version, publish date, document ID, status, engineering change notices and every prior version, with the PDF downloadable from that page.
When to reach for it. When you need the authoritative text behind a cable business internet handoff, for example what DOCSIS 4.0 actually requires of upstream and downstream behaviour before you accept a carrier's claim about a service tier, or which specification version a vendor's equipment was certified against.
Know before you rely on it. The download control is injected by JavaScript, so a scripted crawl of the library page will not find it. Documents are large, and the specification set assumes you already know the architecture.
Know a tool that belongs here, or found one that has gone dark? Let us know. If you would rather skip the research and have carriers compete for the circuit, request quotes.
The Internet Access Coalition archive
Before this site compared providers, internetaccess.org was the home of the Internet Access Coalition, the 1996-98 industry group that beat per-minute internet access charges at the FCC. We preserve its full site, including the 1997 ETI study, at the original addresses. Start with the story of the coalition, read inside the ETI study, or browse all fourteen preserved pages.