FINDING · DETECTION

Nonsense domains with known-censored hostnames embedded as subdomains (e.g., www.epochtimes.com.pSyfA6srAZ0qCxU63.com) triggered the same tampered responses — returning the pool of 8 bad IPs — as direct queries for the censored domain. Control-subdomain nonsense domains (e.g., www.pSyfA6srAZ0qCxU63.com) did not trigger tampering, indicating the GFW performs substring keyword matching across the full DNS query label string.

From 2007-lowe-greatThe Great DNS Wall of China · §6.2 · 2007 · New York University

Implications

Tags

censors
cn
techniques
dns-poisoningkeyword-filtering

Extracted by claude-sonnet-4-6 — review before relying.