FINDING · EVALUATION
In AS197207 (Iran, MCI), approximately 50% of DoT endpoints failed consistently — the only case across all tested ASN/protocol combinations where failure exceeded 20%. In Kazakhstan (AS48716) and China (AS45090), more than 80% of DoT and DoH endpoints were always reachable.
From 2021-basso-measuring — Measuring DoT/DoH blocking using OONI Probe: a preliminary study · §V-F, Table VII · 2021 · DNS Privacy Workshop
Implications
- DoT (port 853) is a high-risk transport for Iranian users; circumvention tools routing DNS through DoT should treat MCI as a hostile network and fall back automatically.
- Failure rate alone is insufficient to characterize blocking — tool designers should instrument failure mode (connect vs. TLS handshake vs. post-handshake timeout) to distinguish IP blocking from SNI-based blocking.
Tags
Extracted by claude-sonnet-4-6 — review before relying.