FINDING · DETECTION

Several Iranian domains maintain DNS A records pointing to RFC1918 private addresses that resolve only when queried against Iranian nameservers (IRNIC); the same query to Google's public DNS (8.8.8.8) returns REFUSED. Domains including realm.blizz.ir (→ 10.175.27.120), isftak.ir, and geeges.co.ir exhibit this split-DNS pattern as of September 2012.

From 2012-anderson-hiddenThe Hidden Internet of Iran: Private Address Allocations on a National Network · §5.2, §6 · 2012

Implications

Tags

censors
ir
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.