What is MANRS?
MANRS is a routing security initiative. Learn its four actions: filtering, anti-spoofing, coordination and global validation with RPKI.
Last updated:
MANRS (Mutually Agreed Norms for Routing Security) is a global initiative that defines a set of agreed-upon norms to improve the security of Internet routing. It targets network operators, IXPs, cloud and CDN providers, and equipment vendors above all. MANRS aims to reduce the most common BGP threats, such as route hijacks and route leaks, by implementing concrete, measurable technical actions.
BGP was designed in an era when the Internet relied on mutual trust between participants, and by default it does not verify whether the network announcing a given address block actually has the right to do so. MANRS does not replace BGP. It provides a common framework of good practices that fills this gap and that operators can publicly commit to and maintain.
The four core MANRS actions
The network operator programme is built around four actions. The first three are mandatory for participation, while the fourth is strongly recommended:
- Filtering: preventing propagation of incorrect routing information. The operator defines which prefixes a given BGP neighbour may announce and rejects announcements outside that list, using IRR databases and RPKI.
- Anti-spoofing: preventing traffic with spoofed source IP addresses. It works by filtering packets at the network edge, typically following BCP 38 and uRPF, which makes spoofed DDoS attacks harder.
- Coordination: maintaining up-to-date and publicly available contact information, for example in PeeringDB, RIR databases and IRR objects, so other operators can respond quickly to incidents.
- Global validation: publishing your own routing policy, including correct ROA objects in RPKI, so that others can validate whether a network's announcements are authentic.
Why routing security matters
Routing incidents have real, measurable consequences. A route hijack occurs when a network announces address space it does not own, which can reroute traffic, enable interception, or cause service outages. A route leak is the unintended re-announcement of routes that should not be propagated further, for example passing routes from one transit provider to another. Both happen regularly and often result from misconfiguration rather than deliberate attack.
The MANRS actions reinforce one another. Filtering and RPKI validation limit the impact of neighbours' mistakes, anti-spoofing reduces the scale of volumetric attacks, and good coordination shortens response time. The more networks adopt these norms, the less room there is for incorrect routes to spread across the wider ecosystem.
What MANRS compliance means for an operator
Being MANRS-compliant means committing to and genuinely maintaining the required actions, and being listed on the public participant list. For an operator it gives a clear signal to peering partners and customers that the network follows proven routing hygiene practices. In practice, implementation comes down to configuring prefix filters, enabling RPKI validation on edge routers, deploying BCP 38, and keeping IRR and RPKI objects current. Compliance is not a one-off task. It requires ongoing maintenance, because policies and address allocations change over time.
Frequently asked questions
Is MANRS mandatory?
No, MANRS is a voluntary initiative. An operator commits to implementing the required actions and joins the public participant list, but it is not a legal requirement.
What is the difference between MANRS and RPKI?
RPKI is a specific technology for cryptographic validation of route origin. MANRS is a broader framework of good practices in which publishing ROA objects in RPKI is one of its four recommended actions.
Who can join MANRS?
There are separate programmes for network operators, IXPs, cloud and CDN providers, equipment vendors, and the public sector. Each has its own set of expected actions.
Is MANRS compliance verified?
Yes, compliance is monitored using publicly observable routing data such as BGP announcements and objects in RPKI and IRR. Operators are expected to maintain the actions on an ongoing basis.
