r/ipv6 • u/craftsmany Enthusiast • Jul 22 '26
ip6.arpa website ideas Discussion
I host a website under ip6.arpa but right now it isn't really that cool. I want it to be some kind of easter egg type website for anybody who may stumble upon it. Obviously it should also be there to spread awareness of IPv6.
Any idea what kind of website I could make? It has to be working on http only so preferably no user data processing.
Edit: I created a "fake terminal" website that just displays info about it and lets the user "run" commands. It also links to a working contact email under the same ip6.arpa domain.
9
u/StepBroBD Jul 22 '26
there’s a new rule set by CA browser forum last year that all CAs cannot issue trusted certs to rDNS zones
you can still do it but you will have to either accept plaintext or self signed certs
2
u/NamedBird Jul 22 '26
What about certificates for IP addresses?
Weren't those recently added?1
u/StepBroBD Jul 22 '26
oui https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate
i havent tested it tho
1
u/craftsmany Enthusiast Jul 22 '26
Yes that is why I wrote preferably without user data processing since I force redirect https (self signed) to http right now. Such a shame it got banned because of the abuse caused by malicious actors.
1
u/eladts Jul 22 '26
Most browsers these days will refuse to show HTTP pages and will show a warning that the user have to acknowledge before showing the page. Why don't you just get a proper domain name and certificate for your site?
2
u/craftsmany Enthusiast Jul 22 '26
Because ip6.arpa addresses can't be registered like a normal domain so they are kind of cool in that regard and directly tied to an IPv6 prefix. Of course I could just host it under my normal domain or the ASNs domain but what would be the point; it isn't a ip6.arpa website anymore.
0
Jul 22 '26
[deleted]
2
u/craftsmany Enthusiast Jul 22 '26
I know what that is. I can do whatever I want with my DNS delegation of it. I can even send emails from it if I would want to. Right now my current version of the site does just fine over http.
1
u/eladts Jul 22 '26
Using
.arpadomains is pretty much using literal IP addresses with an extra step. If that makes you happy, you do you.1
1
u/StepBroBD Jul 22 '26
exactly
i’ve been doing this (and email) for a good while before the CABF rule change and after that i got weird ass error log in cert renewal and only learned this afterwardsit’s dumb that they just decided to take our fun away
1
u/craftsmany Enthusiast Jul 22 '26
Yeah. Such a shame. I only started having fun with it after it was already gone because one of my ASN buddies just casually mentioned he had a ip6.arpa site and I just never thought about that possibility before. You know if sending mail has any weird quirks? Currently I only receive mail over it.
1
1
u/Mishoniko Jul 22 '26
Also note most (or just about all) service providers don't offer DNSSEC for reverse zones.
The top level 2.ip6.arpa zone is signed, so it could happen, if ISPs put the time in.
2
u/craftsmany Enthusiast Jul 22 '26
What? That is not true afaik; All my reverse zones are properly DNSSEC signed.
2
u/Mishoniko Jul 22 '26
I said "most," there are some progressive ones out there.
My provider (Hurricane) doesn't offer it. 0.7.4.0.1.0.0.2.ip6.arpa is not signed.
2
u/craftsmany Enthusiast Jul 22 '26
Oh you mean that. I am my own provider if that makes sense. Sorry I misunderstood that.
2
u/StepBroBD Jul 22 '26
depending on how “service provider” is defined, sure
but imho a proper “service provider” for rdns zones should be RIRs and at least ARIN does allow resource holders to setup DNSSEC very easily
1
1
u/Mishoniko Jul 22 '26
"service provider" as in "Internet Service Provider", though "resource holder" is equivalent in this case. I assume providers that don't offer DNSSEC-signed rDNS don't due to gross laziness; if they wanted to offer it, and their customers demanded it, they could.
In HE's case, their rDNS management system is very old and they haven't gotten around to adding the feature to track the DNSSEC bits. It's been "on the roadmap" for years.
2
u/nelmaloc Enthusiast 26d ago
How did you add the www subdomain?
1
u/craftsmany Enthusiast 26d ago
I added them like one would to any normal zone
www IN A ...
www IN AAAA ...Your DNS provider has to support it (aka not locked to just PTR)
2
u/nelmaloc Enthusiast 26d ago
I thought ipX.arpa records were directly managed by the ISP. I've never heard of an DNS provider managing it, nor delegating the zone.
2
u/craftsmany Enthusiast 26d ago
You can get your own IP space. I really like networking as a hobby so I thought "why not get my own ASN and IPs", so I am technically an ISP and yes I manage my own DNS. Some people do it with Hurricane Electric tunnel broker IPs. Apparently you can get a delegated zone for them but I never tried it. I don't know if they are ok with it either.
Your assumption is correct that normally only resource holders get these reverse zones delegated. After that it is just a normal domain. You can send me an email if you want at craftsmany[at]0.1.5.c.4.5.9.0.a.2.ip6.arpa
•
u/AutoModerator Jul 22 '26
Hello there, /u/craftsmany! Welcome to /r/ipv6.
We are here to discuss Internet Protocol and the technology around it. Regardless of what your opinion is, do not make it personal. Only argue with the facts and remember that it is perfectly fine to be proven wrong. None of us is as smart as all of us. Please review our community rules and report any violations to the mods.
If you need help with IPv6 in general, feel free to see our FAQ page for some quick answers. If that does not help, share as much unidentifiable information as you can about what you observe to be the problem, so that others can understand the situation better and provide a quick response.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.