RPKI Valid, Invalid and Not Found Explained

Validate a prefix–origin pair, including its prefix length, and keep validator availability separate from the routing result.

Check the pair that was actually observed

Use the RPKI origin validator with a prefix and AS number from the same routing observation. A multiple-origin prefix needs a separate check for every origin.

Interpret the four displayed states

Valid means at least one covering validated payload authorizes this origin and length. Invalid means covering payloads exist but none authorize the announcement. Not found means this validated set has no covering payload. Unknown is a tool/source state: the validator is unavailable or its snapshot is stale, so no current validation conclusion is offered.

Prefix length matters

In a hypothetical example, a payload for 192.0.2.0/24 authorizes AS64496 with maximum length 24. The /24 with that origin is authorized, but 192.0.2.0/25 exceeds the permitted length. This is a documentation example, not a live route or a recommended authorization.

Investigate an Invalid result

Compare the observed origin, covering payloads, maximum lengths and both observation times. Check whether the intended route or authorization recently changed. Coordinate with the responsible network and resource holder; do not broaden a maximum length or change an origin merely to clear a warning.

Limits of the conclusion

Origin validation does not authenticate the whole AS path, verify a website or establish a host’s reputation. Not found is different from Invalid. A stale validator response should not be silently presented as a fresh result. Continue to Prefix Lookup for source-specific routing evidence.

Sources