FINDING · DETECTION

Iran's censor deploys a two-stage blocking response within 24 hours of domain exposure: DNS hijacking that resolves blocked domains to 10.10.34.34, combined with RST floods when clients connect directly to Cloudflare IPs using the blocked SNI. Both mechanisms activate independently, so DNS-resistant clients are still terminated at the TCP layer.

From 2026-pooribitwise-iran-advanced-dpi[Iran] Advanced DPI is reassembling TCP fragments to extract SNI on VLESS/WS + CDN · Issue body — The Issue · 2026 · net4people/bbs

Implications

Tags

censors
ir
techniques
dns-poisoningrst-injectionsni-blocking

Extracted by claude-sonnet-4-6 — review before relying.