Domain lookup
DNS Blocking
Manipulation of DNS responses to prevent domain resolution.
Read the definitionThe definition and detection notes below retain the published reference wording. They are not a current network test.
01 / Definition
What it means.
DNS blocking occurs when a DNS resolver returns incorrect or null responses for specific domain queries, preventing users from reaching the intended destination. This can manifest as NXDOMAIN responses (claiming the domain doesn't exist), redirects to warning pages, or connection timeouts.
DNS blocking is one of the most common censorship techniques because it's easy to implement at the ISP level and affects all users relying on that resolver. However, it's also relatively easy to circumvent by using alternative DNS providers.
02 / How We Detect This
What we look for.
We compare DNS responses from ISP resolvers against control measurements from uncensored vantage points. When a resolver returns NXDOMAIN, a different IP, or times out for domains that resolve correctly elsewhere, we flag potential DNS blocking. We validate findings across multiple probes to reduce false positives.
03 / Examples
What it can look like.
ISP returns NXDOMAIN for blocked news sites
DNS queries redirected to government warning page
Timeout on DNS resolution for VPN provider domains
Illustrative examples from the glossary, not incident reports or live observations.
Sources
Read the original.
Reference context & original shorthand
Published bypass label: Easy to bypass.
This is the original index’s editorial shorthand. Actual access depends on the network and technique; this label is not a guarantee. The glossary has no per-entry publication or review date.
Related links lead to definitions in the published glossary.
Complete definition →