FINDING · DETECTION

Over 90% of tested censored domains returned private IP addresses in the 10.10.34.0/24 range (chiefly 10.10.34.34) via injected DNS replies during the June 2025 shutdown, with poisoned response TTLs often very low—consistent with inline DPI injection rather than a recursive DNS lookup. A small set of domains including Google and state-approved services were whitelisted and resolved correctly.

From 2025-aryapour-stealth-blackoutIran's Stealth Internet Blackout: A New Model of Censorship · §4.1 · 2025 · arXiv preprint (cs.NI)

Implications

Tags

censors
ir
techniques
dns-poisoningdpi

Extracted by claude-sonnet-4-6 — review before relying.