What Is Anycast?

Also called: IP anycast, Anycast routing

Related problems: Users far from our servers see slow DNS and website response times; A DDoS attack could overwhelm a single hosting location; Need a service to stay reachable if one site goes offline

Anycast is a way of routing internet traffic in which the same IP address is announced from many locations at once, and the network delivers each user’s traffic to one of them, usually a nearby one. The user sees a single address; behind it are many servers in different cities. Anycast is widely used by DNS providers, content delivery networks (CDNs) and DDoS protection services to cut response times and spread load across many sites.

At a glance

  • One IP address is announced from many locations, and routing chooses which one each user reaches.
  • It usually sends users to a nearby location in network terms, which is not always the geographically closest.
  • If a location goes offline and stops announcing the address, traffic typically shifts to others.
  • It spreads attack traffic across many sites, which helps absorb DDoS attacks.
  • Most businesses use it through DNS, CDN or DDoS services rather than running it themselves.

What problem it solves

A service hosted at a single location is far from many of its users and depends on that one location staying up. Users on the other side of the world see higher latency. A power or network failure at the site takes the service down. A large DDoS attack aimed at that one address has a single target to overwhelm.

Running copies of the service in many locations solves part of this, but users still need to be pointed at the right copy. Anycast handles that at the routing layer: every location shares the same address, and the internet’s routing system steers each user to one of them without any change on the user’s side.

How it works

Announcing the address. An operator with its own IP address block announces the same prefix from each location using the Border Gateway Protocol (BGP), the protocol networks use to exchange routes on the internet.

Route selection. Each network on the internet hears several paths to that prefix and picks one using its own routing policy, often favoring the shortest path or a preferred peer. That choice decides which anycast location receives the user’s traffic. The result is usually a nearby site, but routing policy, peering arrangements and congestion can send a user somewhere farther away.

Failover. If a location fails or is taken offline, it withdraws its announcement, and networks shift traffic to other locations once routing updates. How quickly that happens depends on the operator’s setup and on how fast routing changes spread across the internet.

Best-suited traffic. Anycast works especially well for short exchanges such as DNS queries, which often fit in a single request and response. For longer connections, such as web sessions, operators manage the risk that a routing change mid-session sends packets to a different site; CDNs do this routinely.

Attack absorption. Because attack traffic from around the world is spread across many sites, each one handles a share. Each site still needs filtering and capacity to drop malicious traffic.

To compare services built on this kind of global footprint, see our Cloud Content Delivery Network solution page.

When it matters for buyers

  • Choosing a DNS provider. An anycast DNS network commonly answers faster for users in many regions and is harder to knock offline than a few standalone name servers.
  • Choosing CDN or DDoS protection. The number and location of anycast sites, and their capacity, shape performance and attack resilience.
  • Serving users globally. If customers are spread across regions, anycast-based services usually help more than one central location.
  • Running your own network. Organizations with their own address space and multiple data centers sometimes run anycast for internal or public services.

Questions to ask vendors

  • How many anycast locations do you operate, and where are they relative to our users?
  • How do you check that users are actually reaching a nearby location, and can you show us data for our regions?
  • How much capacity does each location have to absorb attack traffic?
  • What happens to active sessions when a location fails or routing changes?
  • Do you announce our IP addresses from your network, and what does that require from us?

How it differs from a CDN

A CDN is a service: a network of servers that store and deliver copies of web content close to users. Anycast is a routing technique, and one common way of directing users to those servers. Many CDNs rely on anycast, while others steer users with DNS, returning different addresses to different users based on their location. Anycast also has uses outside CDNs, most notably for DNS resolvers and authoritative DNS. In short, a CDN is what you buy, and anycast is one of the mechanisms it may use to route you.

Frequently Asked Questions

Does anycast always send users to the closest server?
No. It sends traffic to the location that internet routing prefers, which is usually nearby in network terms but not always the closest geographically or the fastest. Results depend on how each provider peers and routes.
Why do DNS services use anycast?
DNS queries are short and usually fit in a single packet, so they work well when users are spread across many sites. Anycast lets a DNS provider answer from many locations with the same address, cutting response times and spreading load.
How does anycast help with DDoS attacks?
Attack traffic is usually routed to many anycast locations instead of one, so no single site has to absorb all of it. Each site still needs enough capacity and filtering; anycast spreads the load but does not filter it.
Can a business run its own anycast?
It is possible with its own IP address block, several locations and BGP sessions with providers at each, but most businesses get anycast through a DNS, CDN or DDoS protection service that already operates it.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.