FINDING · DETECTION
Community analysis of the Iran VLESS+TLS failure identified DNS poisoning as a primary root cause: domain-based resolution for services like Instagram, YouTube, and Facebook was disrupted even when traffic transited a VLESS+TLS tunnel from a domestic VPS, bypassing the transport-layer obfuscation entirely.
From 2022-oftenhamed-vless-tls-has — Vless + TLS has a weird behavior on Iran VPS · Issue thread (abstract) · 2022 · net4people/bbs
Implications
- Bundle a trusted, non-local DNS resolver (DoH, DoT, or DNS-over-proxy) inside the tunnel to prevent the censor's poisoned DNS from affecting destination resolution.
- Do not rely on the system resolver when operating from within a censored network, even when the tunnel transport is undetected.
Tags
Extracted by claude-sonnet-4-6 — review before relying.