Skip to content
bgplookup.io

September 4, 2026

Stop Trusting Vendor Domains. Allow-List the ASN.

domain asn swap

A domain is a promise that DNS will point somewhere. An origin ASN is who is announcing that somewhere right now. Security teams still paste hostnames into firewalls and wonder why the AI vendor broke after a CDN cutover. If the product can move addresses without asking you, your unit of trust is the prefix and the ASN — checked live — not the marketing URL.

Build a vendor card that a firewall can use

For each critical vendor — IdP, email, EDR, model API, payments — store:

When finance says “block that country” or IR says “block that ASN,” read the card first. AI vendors often ride the same hyperscaler ASNs as your CRM. A patriotic firewall rule is how you lock the office out of mail.

What “the vendor was hijacked” should look like

The hostname still resolves. The origin ASN is new. RPKI is invalid or the ROA names the old origin. Looking glasses disagree by region. That is a routing incident. A new address inside the same authorized prefix is a Tuesday. Do not page the internet for a Tuesday.

Agents need an egress card too

If your company runs browsers that call models, those calls leave from somewhere. Publish that somewhere internally. If an agent framework spins workers in a mystery region, your allow-list will fight you. Either pin the runtime to known prefixes or stop pretending the firewall understands AI.

Pick one vendor hostname. Resolve it. Look up the address. Save prefix, ASN, and ROA. That is the whole program’s first hour.

FAQ

Vendors refuse to publish prefixes. Now what?

Record what they actually originate this month and review it. Silence is not a reason to trust a domain forever.

Is pinning IPs better than ASNs?

IPs churn faster. ASNs churn slower. Prefixes are the compromise. Use the smallest object that survives a week.

Leave a Reply

Your email address will not be published. Required fields are marked *

BGPLOOKUP.IO ACCOUNT

Sign in or create an account

Continue with an account you already use.

Your provider password is never shared with bgplookup.io.