Pulse — RPKI-invalid route
Routes that fail RPKI validation (origin ASN doesn't match the prefix's ROA, or prefix is longer than max-length).
What is RPKI-invalid route?
An RPKI-invalid route is a prefix whose origin ASN does not match the Route Origin Authorization (ROA) published by the legitimate holder, or whose length exceeds the ROA max-length. RPKI-invalid routes should be dropped by validating routers; their presence flags a misconfiguration or a possible origin hijack.
Geographic distribution
Flagged events
Showing 200 most recent of 7,197 · last 24hFrequently Asked Questions
What is a BGP RPKI-invalid route?
An RPKI-invalid route is a prefix whose origin ASN does not match the Route Origin Authorization (ROA) published by the legitimate holder, or whose length exceeds the ROA max-length. RPKI-invalid routes should be dropped by validating routers; their presence flags a misconfiguration or a possible origin hijack.
Where does this data come from?
Every event is detected from live BGP updates collected across 23 RIPE RIS route collectors worldwide, ingested into a ClickHouse time-series store and re-evaluated every few minutes. No third-party feed is resold; the analysis is original to WorldIP.io.
How often is the RPKI-invalid route feed updated?
The feed recomputes roughly every 5 minutes; it was last refreshed at 2026-09-01 21:35 UTC.
How do I subscribe to RPKI-invalid route events?
Subscribe to the Atom feed at /pulse/bgp/rpki.atom or poll the JSON endpoint at /api/pulse/bgp/rpki.