open.com.im › The desk › Sheet 01
Sheet 01 · open data
The Root, by the numbers
One publicly published file sits above every domain on earth. This page parses it — not somebody’s API of it — into 1,438 delegations and 5,914 nameserver hostnames, and then tells you, in the same breath, that the file has moved on without it.
The DNS root zone is the least glamorous important file in computing. It is a plain text zone file, published at internic.net, that names every top-level domain and the servers delegated to answer for it. Everything you have ever typed into a browser resolves by climbing to it. It is entirely public, it is revised roughly twice a day, and almost nobody has ever opened it.
The Root opens it. The distinction that matters here is not that the page shows root-zone data — several services do — but that it parses the zone file itself and then refuses to pretend the parse is current. That second half is the reviewable virtue, and it is rarer than the first.
Delegations
1,438
every name below the dot
Nameserver hosts
5,914
distinct, across 7,628 NS records
DNSSEC-signed
1,350
93.9% of the root
IPv6 glue
1,420
98.7%; 18 delegations without
Zone serial
…8 2702
2026082702, the file’s own
Data file
217,446
bytes, served in 0.52 s
I did not take those from the page’s summary card. I fetched
root/assets/js/root-data.js from the live host at 22:35:17 UTC — 217,446 bytes,
200, 0.52 s — parsed it myself, and counted. The
page’s printed figures and my counts agree to the unit, including the one it does not print:
the 5,914 distinct hostnames are spread across 7,628 delegation records, a mean of 5.3
nameservers per TLD and a median of exactly 6.
Signed, unsigned, and who is not
The register sorts delegations three ways — generic, country code, internationalised — and the split along that seam is the most interesting number on the page, because the page itself does not draw it.
Figure 1
DNSSEC adoption is not one number. It is three.
Delegations by class, signed against unsigned. Counted from root-data.js as served by labs.llc at 22:35:17 UTC, 2026-09-22. Bars share one scale.
Every generic TLD in the zone is signed — 1,039 of 1,039, no exceptions. The unsigned 88 are all country codes or internationalised country codes: .ae, .gb, .im, .qa, .tk, .va and 82 others. The gap is a policy artefact, not an engineering one: signing is a contractual condition of running a gTLD and a sovereign choice for a ccTLD.
Eighteen delegations still have no IPv6 glue in the zone: .cd, .ck, .dj, .et, .fk, .ge, .gf, .hm, .kp, .mh, .mm, .mp, .mq, .sl and four internationalised names. That is 1.3% of the root, and it is the sort of fact this register exists to make cheap — three filter clicks, no query language.
The shape of a delegation
How many nameservers does a top-level domain run? The zone answers precisely, and the answer is bimodal in a way that no summary statistic captures.
Figure 2
Four or six. Almost nothing else.
Delegations by nameserver count. 1,438 TLDs, 7,628 NS records. Counted 2026-09-22, 22:35 UTC.
Bars below five TLDs are drawn at a visible minimum and are marked with their true count. 1,061 of 1,438 delegations — 73.8% — run either four or six nameservers; a further 106 run five. Fourteen run two, which is the zone’s floor.
Beneath that sits the fact the register makes easiest to find and hardest to look away
from: 5,914 hostnames sound like diversity, and 310 of them serve more than one TLD. Four
hostnames under trs-dns carry 76, 76, 72 and 72 delegations apiece. Five under
charlestonroadregistry.com carry 46 each.
| Nameserver suffix | TLDs served | Share of root |
|---|---|---|
| trs-dns.com | 76 | 5.3% |
| trs-dns.net | 76 | 5.3% |
| trs-dns.org | 72 | 5.0% |
| trs-dns.info | 72 | 5.0% |
| charlestonroadregistry.com | 46 | 3.2% |
| gmoregistry.net | 46 | 3.2% |
| nic.fr | 35 | 2.4% |
| irondns.net | 31 | 2.2% |
| afrinic.net | 25 | 1.7% |
| ripe.net | 24 | 1.7% |
Counted by registrable suffix over the 7,628 NS records in root-data.js; a TLD is counted once per suffix. 1,257 distinct suffixes serve the root in total. This table is mine, not the page’s — The Root gives you the hostnames and lets you filter, but it does not aggregate by operator.
The watch, and the twenty-six days
A snapshot register is a claim about a moving file, and most of them handle that by saying nothing. The Root handles it by putting a serial watch at the top of the page: the zone’s serial as the resolvers answer it this second, beside the serial of the file it parsed, and a plain verdict.
Figure 3
The register is 26 days behind the zone, and says so.
Serials are dated: 2026082702 is the second revision of 27 August 2026; 2026092200 is the zero-th of 22 September. Read from the page’s own live watch at 22:36:46 UTC, 2026-09-22.
At the page’s own stated cadence, roughly fifty revisions passed between the file on the page and the file on the wire. Most of those touch a handful of records and change nothing you are reading. Some do not.
What saves this from being a flaw disguised as a feature is the per-TLD check. Ask the register about one name and it will go to the resolvers for that name now and compare the answer to the snapshot in front of you. The page’s framing is exactly right: “What neither says, this page does not invent.” That sentence is doing more work than most engineering blog posts.
The shortcoming
The honesty is real; the freshness is not. The register on labs.llc/root/ is a static snapshot parsed on 28 August and it has not been re-parsed since. The page tells you this clearly and gives you a per-TLD escape hatch — but the escape hatch is one name at a time, and the six headline figures at the top of the register (1,438, 248, 1,039, 151, 1,350, 1,420) carry no staleness marker at all. A visitor who reads the figures row and leaves has taken away 26-day-old counts with no indication of it. The watch sits in a different band of the page. Either the figures row should carry the same verdict the watch carries, or the snapshot should be rebuilt on the zone’s cadence rather than on a build’s.
The verdict, such as it is
The Root does the unfashionable thing: it goes to the primary document. Nothing between the zone file and the register is anybody’s product, nothing is reconciled behind your back, and the one place where a snapshot cannot tell the truth — time — is the place the page spends its effort. Against that, 26 days of drift on an unmarked figures row is a real cost, and it is the only thing standing between a good reference page and an authoritative one.
Read it yourself: labs.llc/root/. Bring a TLD you care about and press the resolver check — that is the part of the page that cannot go stale.