FINDING · DEFENSE

Despite AWS, Google, and Microsoft having publicly withdrawn CDN-level domain-fronting support to preserve commercial relationships with censoring states, domain fronting remains functional on AWS Lambda as of early 2026. Microsoft Azure Functions explicitly rejects mismatched SNI/Host headers, whereas AWS Lambda permits a client to present a legitimate *.lambda-url.*.on.aws SNI while routing internally to a different serverless function via the HTTP Host header.

From 2026-kang-censorless-serverlessCensorLess: Cost-Efficient Censorship Circumvention Through Serverless Cloud Functions · §4.7 · 2026 · PETS 2026

Implications

Tags

censors
generic
techniques
sni-blocking
defenses
domain-frontingbridges

Extracted by claude-sonnet-4-6 — review before relying.