FINDING · EVALUATION
Sending DNS queries to eight non-DNS IP addresses within the Chinese IP range reliably detects GFW DNS poisoning: any response indicates the censor intercepted and replied to the query, since a legitimate non-DNS server would not respond. This external vantage-point technique discovers poisoned domains without in-country volunteers or local infrastructure.
From 2017-darer-filteredweb — FilteredWeb: A Framework for the Automated Search-Based Discovery of Blocked URLs · §IV-C · 2017 · Network Traffic Measurement and Analysis
Implications
- Circumvention tool operators can externally validate whether their proxy domains are GFW-poisoned by querying non-DNS Chinese IPs — no in-country presence required for continuous monitoring.
- Continuous external DNS poisoning checks should be integrated into proxy infrastructure health monitoring, since poisoning can silently break connectivity before users report failures.
Tags
Extracted by claude-sonnet-4-6 — review before relying.