True native IPv6. No NAT66 hacks. No translation layers. Pure BGP routing like the internet was meant to be.

Our Commitment to Native IPv6

At doxx.net, we believe every customer deserves native IPv6 connectivity without translation. While many providers disable IPv6 or resort to NAT66 workarounds, we've built our infrastructure from the ground up to deliver true dual-stack connectivity. Your IPv6 traffic flows end-to-end exactly as the protocol intended. No compromises, no shortcuts.

Complete IPv6 Coverage

Our dual-stack infrastructure handles ALL IPv6 traffic natively. Every connection, every packet, fully supported without fallbacks or workarounds.

IPv6-Native WireGuard Endpoints

All our WireGuard servers are IPv6-native. Connect via IPv6 or IPv4 with full dual-stack support from the connection level up. No IPv4-only bottlenecks.

Real Routed IPv6 Address

Get your own globally-routable /127 subnet from our 2602:F5C1::/36 ARIN allocation. Not shared, not NAT'd. It's yours.

No NAT66

Pure BGP routing with no address translation. Your IPv6 packets flow end-to-end as intended. Native IPv6 for all devices on your LAN.

BGP Mesh Backbone

Full mesh BGP topology between all backbone servers. Your /127 is automatically advertised across our global network.

IPv6-Aware Packet Filtering

Native transparent proxy, firewall rules, and connection tracking for IPv6 traffic.

Technical Architecture

Full Dual-Stack From Connection to Egress

doxx.net is fully dual-stack at every layer:

Connection Layer:
  • WireGuard endpoints accessible via IPv4 OR IPv6
  • Connect to us using your native IPv6 connection
  • No IPv4 dependency for establishing tunnel

Tunnel Layer:
  • Dual-stack tunnel (IPv4 + IPv6 simultaneously)
  • Your traffic uses YOUR routed IPv6 address
  • Full native IPv6 support throughout

Egress Layer:
  • Exit to internet via IPv4 or IPv6
  • Native IPv6 to CDNs (Google, Cloudflare, etc.)
  • No NAT66 bottlenecks

Dual-Stack Services

10.10.10.10:53        → dn-dns (IPv4)
fd10:10:10::10:53     → dn-dns (IPv6)

10.10.10.10:8080      → Transparent HTTP Proxy (IPv4)
fd10:10:10::10:9091   → Transparent Proxy (IPv6)

BGP Route Advertisement

When you connect to doxx.net:

  1. You're allocated a unique IPv6 address that's static until you change it
  2. Your /127 is immediately injected into BGP
  3. All backbone servers learn your route via BGP mesh
  4. Traffic to your IPv6 address routes to your connected server
  5. No NAT, no translation: pure routing

A True Meshed Encrypted Backbone

BGP Mesh Backbone

Why IPv6 Actually Matters

IPv6 isn't just about more addresses. It's about a faster, more private, and more modern internet:

⚡ Faster Performance

All major CDNs are IPv6-native. Google, Cloudflare, Akamai, and Fastly all prioritize IPv6. With doxx.net's dual-stack endpoints and native IPv6 routing, you get direct access to IPv6-optimized infrastructure: better routing, lower latency, and less congestion.

🔒 QUIC & HTTP/3

QUIC (HTTP/3) works best on IPv6. Google's entire infrastructure is IPv6-native. YouTube, Gmail, and Search are all optimized for IPv6. You get faster page loads and better connection multiplexing.

🔐 Better Privacy

IPv6 offers better privacy than IPv4. No more carrier-grade NAT tracking you across multiple connections. With doxx.net's native routing, you get a clean, private IPv6 address that's yours alone, not shared with thousands of other users.

🚀 Less Congested Networks

IPv6 networks are less congested. While everyone fights over IPv4 address space, IPv6 gives you access to modern, high-capacity routes with fewer hops and better peering.

🔓 No Legacy Security Baggage

IPv6 isn't overburdened with legacy IPv4 security tools. Deep packet inspection, stateful firewalls, and carrier surveillance are all designed for IPv4. IPv6's end-to-end encryption and modern design make blanket surveillance much harder.

🌐 Future-Proof

IPv6 is the present, not the future. Over 40% of global internet traffic is IPv6. Major networks (Google, Facebook, Netflix) are IPv6-first. Don't get left behind on legacy IPv4.

Who This Is For

For Network Engineers: This is how Internet connectivity should be built. No hacks, no workarounds. Just proper IPv6 routing infrastructure the way it was designed.

For Enterprises: Production-grade IPv6 support means your infrastructure is ready for the IPv6-native internet, today. Get native IPv6 for all devices on your network without SOCKS5 proxies or NAT66 hacks.

For IPv6 Advocates: Finally, an Internet service provider that respects IPv6's design principles. No more NAT66 compromises. Real routed prefixes, real end-to-end connectivity.

For Privacy-Conscious Users: Better performance and access to the modern internet without compromise. IPv6 is inherently more private than shared IPv4 NAT pools.

Current Status

Server Infrastructure: ✅ Fully operational. Native IPv6 routing, BGP mesh, packet filtering, and dual-stack services are live.

When IPv6 privacy concerns are fully resolved at the client level, flipping the switch to enable full dual-stack operation will be trivial. The hard work is already done.

The doxx.net Difference

Feature Traditional Approach NAT66 Approach doxx.net
IPv6 Endpoints ❌ IPv4 only ❌ IPv4 only ✅ Full dual-stack
IPv6 Support Inside Tunnel ❌ Disabled 🟡 NAT66 only ✅ Native routing
IPv6 Handling ❌ Blocks/Disables 🟡 Translates traffic ✅ Native dual-stack
Routed IPv6 Prefix ❌ Not available ❌ No (SOCKS5 instead) ✅ Your own /127
Network IPv6 Support ❌ Not available ❌ No native ✅ Native for all devices
BGP Mesh Backbone ❌ No ❌ No ✅ Full mesh
Shared IPv6 Address N/A ⚠️ Yes (NAT66) ✅ Dedicated address
True No NAT N/A ❌ Uses NAT66 ✅ Pure routing

An IPv6-First Internet Service Provider

doxx.net is committed to delivering native IPv6 connectivity to every customer. No translation, no workarounds. Just the best network connection, built right from day one.