FINDING · DETECTION

In AS197207 (Iran), Google's DoT endpoint 8.8.4.4:853 is blocked 100% of the time while 8.8.8.8:853 is always accessible, regardless of SNI value. TLSv1.3 handshake analysis (hiding server certificates) confirmed no SNI correlation, establishing that Google's DoT blocking depends solely on the destination IP endpoint.

From 2021-basso-measuringMeasuring DoT/DoH blocking using OONI Probe: a preliminary study · §V-I, Table X · 2021 · DNS Privacy Workshop

Implications

Tags

censors
ir
techniques
ip-blocking

Extracted by claude-sonnet-4-6 — review before relying.