You do not need access to your host's routers to map their edge. Start with public data.
- BGP looking glasses. Multiple IXPs and transit providers run public route servers. Telnet or web UI, query the IP they gave you. See which ASN originates it, which upstreams propagate it. If you see only one upstream ASN for their prefix, they are single-homed. Two or more with different paths, multi-homed. Simple.
- Traceroute with TCP SYN on port 443. UDP traceroute is filtered by many scrubbing layers. TCP often slips through and reveals the hop structure past the anycast edge. I have seen 3 Gbps attacks where the victim was on a host with no scrubbing, just upstream ACLs. The traceroute showed the filter appliance at hop 2.
- DNS anycast mapping. If they run their own resolvers, ping from multiple locations. Compare