FINDING · DETECTION
The GFW does not distinguish DNS query traffic directionality, injecting forged replies for both inbound and outbound queries on monitored links. This causes collateral censorship of DNS resolvers outside China when they contact authoritative nameservers located in or whose paths transit China, even for non-Chinese clients.
From 2014-anonymous-towards — Towards a Comprehensive Picture of the Great Firewall's DNS Censorship · §2 · 2014 · Free and Open Communications on the Internet
Implications
- Circumvention DNS infrastructure — including authoritative nameservers for decoy or fronting domains — should be hosted on paths that do not transit Chinese border ASes, to avoid triggering GFW injection for non-Chinese users.
- Anycast DNS deployments should verify that China-adjacent PoPs do not attract queries whose return paths cross GFW-monitored links, since the GFW ignores traffic directionality.
Tags
Extracted by claude-sonnet-4-6 — review before relying.