FINDING · DETECTION
Several Iranian domains maintain DNS A records pointing to RFC1918 private addresses that resolve only when queried against Iranian nameservers (IRNIC); the same query to Google's public DNS (8.8.8.8) returns REFUSED. Domains including realm.blizz.ir (→ 10.175.27.120), isftak.ir, and geeges.co.ir exhibit this split-DNS pattern as of September 2012.
From 2012-anderson-hidden — The Hidden Internet of Iran: Private Address Allocations on a National Network · §5.2, §6 · 2012
Implications
- Circumvention tools that enforce encrypted DNS (DoH/DoT) to public resolvers will silently fail to resolve Iran-internal .ir domains — consider a fallback path for .ir queries via domestic resolvers for users who need both domestic and foreign access.
- The split-DNS pattern is a precursor to a full split-horizon regime; monitor for Iran expanding this to actively return NXDOMAIN or RFC1918 addresses for .ir domains at the network level rather than only at the authoritative nameserver.
Tags
Extracted by claude-sonnet-4-6 — review before relying.