FINDING · EVALUATION

DPYProxy-DNS tested 8 circumvention modes against DNS censorship from vantage points in Iran (AS201295, Mashhad) and China (AS4837, China Unicom). In Iran, DoQ was entirely uncensored even with the SNI extension present; DoH3 worked for all Cloudflare and NextDNS resolvers. Iran's censor operates in-path (not on-path like the GFW), making the "Last Response" mode (wait 3s for the last UDP reply) ineffective in Iran but highly effective in China. Auto-mode averaged 12.32s (median 8.28s) in Iran and 13.78s (median 12.90s) in China to discover a working combination.

From 2026-lange-towardsTowards Automated DNS Censorship Circumvention · §6.2, §6.3 · 2026 · Free and Open Communications on the Internet

Implications

Tags

censors
ircn
techniques
dns-poisoningsni-blockingip-blocking
defenses
tunnelingech-esni

Extracted by claude-sonnet-4-6 — review before relying.