An internet-wide scan of 500k IP addresses from an in-country VPS vantage point
found TCP establishment-interception injections on 43,479 addresses (8.7% of
scanned), with over 70% concentrated in two Akamai ASes (AS16625 and AS20940).
The injection pattern — triggered by the first packet sent to these addresses —
is consistent with targeted blocking of domain-fronting proxies hosted on Akamai CDN.
From 2025-alaraj-iran-refraction — Measuring Censorship in Iran Using Refraction-based Proxies
· §4.1.2
· 2025
· ACM ASIA Conference on Computer and Communications Security
Implications
Akamai CDN IPs used for domain fronting face pre-establishment TCP injection in Iran; operators should test CDN-specific blocking and consider rotating to CDN providers with smaller IP footprint (CloudFront, Fastly) that may not yet be targeted.
Pre-establishment injection (before any application data) means SNI or content-based fingerprinting is not required; the censor is blocking the CDN IP range itself, not the TLS payload.