Methodology
What OpenPath measures, how it decides what to publish, and — as importantly — what it refuses to conclude.
Who decides what is measured
OpenPath administrators define every service and every measurement target. Volunteers contribute probes and cannot choose what those probes test, submit a hostname, or edit a check. A probe that has not been approved by a human receives an empty configuration and measures nothing.
This is the difference between a measurement network and an open scanner, and it is enforced in the API rather than by policy.
How probes are approved
An operator registers a probe, which then authenticates and reports in but receives no measurement targets until an administrator reviews it. Reviewers see the country and network the platform detected, how many other probes share that address or operator, and whether the declared location disagrees with the detected one.
An operator cannot approve their own probe.
How a country is determined
From the address the platform observes the probe connecting from — never from anything the probe says about itself. A probe that could nominate its own country could nominate which national conclusion it influences.
Geolocation is an estimate. VPNs, proxies, carrier-grade NAT and re-assigned address ranges all produce wrong answers that no database fully corrects. A probe whose country cannot be determined still measures, and simply does not contribute to any country.
How status is calculated
Each probe's measurements in a window collapse to one verdict for that probe, and those verdicts are counted. Measurements are not counted directly: a probe checking every minute would otherwise outvote several probes checking every twenty.
The denominator is probes that reported, not probes that exist. A probe that was rebooting is a gap in observation, not a failure to reach — counting it as a failure would publish an outage every time a volunteer restarted a machine. The gap is shown separately.
Why one probe is never enough
A single probe cannot distinguish “the service is down” from “this machine is down”. Where there are fewer than 2 reporting probes, or fewer than 3 measurements, OpenPath publishes not enough evidence rather than a figure.
That is a deliberate refusal, not a gap. A percentage would look like an answer, and zero would look like a total outage.
How confidence is calculated
Confidence is separate from status and is never folded into it. It reflects how many probes reported, how many independent networks they sit on, and how much they agreed.
Network diversity matters as much as probe count. Eight probes behind one ISP are one ISP's view of the internet seen eight times; three probes on three networks are three independent observations.
What OpenPath does not claim
OpenPath reports what probes observed. It does not infer a cause. Censorship, an outage, a routing fault, a CDN misconfiguration and one badly-behaved ISP produce the same reachability measurements, and this data alone cannot separate them.
So a country page says “unreachable from 3 of 7 probes”, and never “blocked”.
Known limitations
- Coverage is uneven — this is a volunteer network, not a survey.
- Cloud-hosted probes see a datacentre's internet, not a household's.
- Geolocation is approximate and sometimes wrong.
- A window with stale aggregates is labelled as such rather than presented as current.
- Results describe the probes that reported. They are not a random sample of a country.
Privacy
Operator identities, exact addresses, hostnames and internal notes are never published. What is and is not public.