FINDING · EVALUATION
Chinese public (pDNS) and ISP (iDNS) DNS resolvers exhibit highly variable filtering bypass rates: some resolvers return correct IPs for specific blocked domains with ACR > 0.6 (e.g., wsj.com, vpnintouch.com), while the same resolver queried from a different ISP or region may have ACR < 0.1. The paper identifies three factors that determine effective bypass: DNS resolver identity, client vantage-point location, and the specific blocked domain.
From 2022-cheng-in-depth — In-Depth Evaluation of the Impact of National-Level DNS Filtering on DNS Resolvers over Space and Time · §4.2–§4.3, Figure 7–9 · 2022 · Electronics
Implications
- Resolver selection is not uniform in China — circumvention tools bootstrapping via DNS should test multiple Chinese ISP resolvers per region rather than assuming uniform behavior.
- Domain-specific bypass patterns (certain resolvers reliably returning correct IPs for select domains) can be exploited as a covert channel to bootstrap initial proxy server contact.
Tags
Extracted by claude-sonnet-4-6 — review before relying.