NZ IPv6 & DNSSEC Update
A year ago I published a table of New Zealand ISP IPv6 support. At the time support was fairly poor. I’m pleased to report that things have gotten better over the last year. There has also been a very pleasing uptick in DNSSEC support.
The big movers here are Trustpower & Orcon, who have both enabled IPv6 by default for their users. So now we have the two largest ISPs still only offering IPv4, but all of the next tier of ISPs are offering IPv6. New Zealand has a flexible ISP market, and almost all consumers can change provider quickly & easily. This means that IPv6 is effectively available for all who want it.
The numbers are still small, but we can see a move upwards towards the end of the year when Orcon & Trustpower enabled IPv6. Many legacy home routers have IPv6 disabled, but as these get replaced/reconfigured, I expect to see a steady increase in IPv6 uptake across those ISPs.
DNSSEC - Well done Spark!
DNSSEC validation numbers look much better:
We see a big jump here, with around half of all DNS queries from NZ going through resolvers with DNSSEC validation enabled. This jump is almost entirely due to Spark changing their policy. Smaller ISPs such as Trustpower have also recently enabled DNSSEC validation.
Vodafone continues to drag the chain. No IPv6, no DNSSEC. It’s a bit embarrassing that their AS is described in whois as “VODAFONE-NZ-NGN-AS.” Are you allowed to describe your network as “Next Generation” when you don’t support basic services such as IPv6 and DNSSEC? There should be rules about that sort of thing.
The good news is that consumers now have a range of viable suppliers for these services. Changing ISP is trivial, and I highly recommend that you change supplier if you’re not getting the services you want. If enough people move, maybe the laggards will finally get the message.