FINDING · DETECTION
Domains on VLESS+WebSocket behind Cloudflare are blocked in Iran even when they have no configured DNS A record and the root domain was never used — indicating Iran blocklists domain names extracted from SNI in reassembled TCP streams rather than requiring prior DNS query evidence.
From 2026-pooribitwise-iran-advanced-dpi — [Iran] Advanced DPI is reassembling TCP fragments to extract SNI on VLESS/WS + CDN · Issue body — The Issue · 2026 · net4people/bbs
Implications
- Do not assume an unconfigured or freshly provisioned domain is safe — Iran's censor extracts and blocklists SNI values regardless of whether the domain resolves or has prior observable traffic.
- Use per-session ephemeral subdomains or wildcard fronting (if the CDN supports it) to slow domain-level blocklisting, or switch to ECH to structurally hide the SNI.
Tags
Extracted by claude-sonnet-4-6 — review before relying.