Question

What is anycast, and how can one IP address be in many places?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Anycast announces the same IP address from multiple locations, and the routing system naturally delivers each user's traffic to whichever location is closest in network terms. It is one of the more elegant tricks in internet infrastructure.

The addressing modes, for contrast:

Unicast — one address, one destination. The normal case.

Broadcast — to everyone on a local network.

Multicast — to a subscribed group.

Anycast — one address, many possible destinations, and the network chooses.

How it works. Several sites announce the same address block into BGP. Every router on the internet independently selects what it considers the best path to that block — usually the shortest AS path. Different routers therefore reach different sites, without knowing or caring that more than one exists. The routing system does the load distribution for free, as a side effect of doing what it always does.

What this buys:

Low latency, since users reach a nearby instance automatically, with no geolocation database or DNS trickery required.

Automatic failover. If a site goes offline it stops announcing, routes reconverge, and traffic shifts to the remaining sites within seconds. Users generally notice nothing.

DDoS resilience, which is the most important application. An attack is distributed across every anycast site by the same routing logic, so the load is absorbed rather than concentrated. This is fundamental to how large DNS and CDN operators survive attacks that would overwhelm any single location.

Where it is used: root and public DNS resolvers, CDN edge networks, and increasingly general web services.

Why it is not used for everything. Anycast works best with short, stateless transactions. A DNS query is a single request and reply — if the next query reaches a different site, nothing is lost.

Long-lived stateful connections are harder. If routing changes mid-session, packets may arrive at a different site with no knowledge of the TCP connection, which breaks it. In practice routes are stable enough that TCP over anycast works well and is widely deployed, but it requires care.

Debugging is awkward, since two users querying the same address may be talking to machines on different continents.

Related Questions