FINDING · DETECTION
In AS197207 (Iran), Google's DoT endpoint 8.8.4.4:853 is blocked 100% of the time while 8.8.8.8:853 is always accessible, regardless of SNI value. TLSv1.3 handshake analysis (hiding server certificates) confirmed no SNI correlation, establishing that Google's DoT blocking depends solely on the destination IP endpoint.
From 2021-basso-measuring — Measuring DoT/DoH blocking using OONI Probe: a preliminary study · §V-I, Table X · 2021 · DNS Privacy Workshop
Implications
- Protocols relying on well-known DoT/DoH IPs (e.g., 8.8.4.4, Cloudflare ranges) as a transport must rotate or avoid those specific IPs in Iran — the block is IP-keyed, not protocol-keyed, so SNI camouflage provides no benefit.
- Endpoint-based blocking means fresh IPs or domain-fronted DoH (where the blocking signal is the IP, not the SNI) are the appropriate evasion strategy in this context.
Tags
Extracted by claude-sonnet-4-6 — review before relying.