FINDING · DETECTION
The GFW deploys DNS injection nodes only at China's border, within 2–3 hops of international transit points, across 16 border ASes. Internal probing found only 0.04% of 42,849 domestic routing paths exhibited DNS pollution, versus ~80% of externally-facing /24 subnets.
From 2014-anonymous-towards — Towards a Comprehensive Picture of the Great Firewall's DNS Censorship · §5 · 2014 · Free and Open Communications on the Internet
Implications
- Route circumvention DNS traffic to avoid paths transiting Chinese border ASes — domestic Chinese ISP infrastructure is largely free of DNS injection.
- DNS-over-HTTPS or DNS-over-TLS tunnels to resolvers outside China bypass GFW DNS injection, since pollution occurs only at border links.
Tags
Extracted by claude-sonnet-4-6 — review before relying.