Is this route origin valid?
Check a prefix and origin AS against the validated ROA set our own routers use. Valid, invalid or not found, with the covering ROAs.
Enter the prefix and the AS that originates it.
We look it up in the validated ROA set our own routers feed on.
You get valid, invalid or not found — and every ROA that covers the space.
What the three answers mean
Valid — a ROA covers this prefix, names this AS and permits this length. Networks that filter on route origin accept it.
Invalid — a ROA covers the space but does not authorise this origin. Networks that filter DROP it. This is the state that takes a prefix off the internet, and it is usually a max-length that is too short or a ROA nobody updated after a renumber.
Not found — no ROA covers it. Nothing is wrong; the route is simply unsigned, and origin validation neither helps nor hurts it.
