FINDING · DETECTION

MCI (AS197207, Iran) intercepts cleartext DNS and returns the bogon address 10.10.34.36 for dns.adguard.com A queries regardless of which upstream resolver is used (system, 8.8.8.8, or 9.9.9.9), and intercepted queries never reached a researcher-controlled DNS-over-UDP server. This bogon falls in the same /24 documented in prior Iranian censorship research. Additionally, SNI blocking for dns.adguard.com was confirmed independently on both port 853 (DoT) and port 443 (DoH).

From 2021-basso-measuringMeasuring DoT/DoH blocking using OONI Probe: a preliminary study · §V-D · 2021 · DNS Privacy Workshop

Implications

Tags

censors
ir
techniques
dns-poisoningsni-blocking

Extracted by claude-sonnet-4-6 — review before relying.