2026-anon-insights-into-iranian
findings extracted from this paper
-
HTTP censorship blockpages in Iran fell into two distinct clusters distinguished by IP TTL values: type NTL1 (TTL 53–55) and type NTE1 (TTL 186–188); TCP RST injections targeting TLS and DNS-over-TCP exhibited the same two TTL ranges. The NTL1 injector was absent on June 11 but present on other days, leading the authors to conclude that an entire injector went offline rather than that a single injection pattern was selectively disabled.
-
After the shutdown lifted (Scan 3), DNS-over-UDP degraded severely — 89.18% of the 9,000 queried domains were affected — but the paper attributes this to general UDP transport instability rather than domain-specific censorship, corroborated by GitHub user reports of ongoing UDP issues. TCP-based protocols (HTTP, TLS) returned to pre-shutdown censorship levels (~15%) in Scan 3, confirming the post-shutdown persistence effect was UDP-specific and not a broadening of the blocklist.
-
In the pre-shutdown scan (Scan 2), Iran's QUIC censorship jumped from 1 domain (0.01%) to 9,000 domains (100%) via complete UDP Initial-packet drops, while DNS-over-TCP censorship spiked from 15.12% to 96.68% of 9,000 queried domains. Both changes preceded the full blackout by roughly 5 days, indicating they were preparatory measures rather than incidental. After the shutdown lifted, QUIC remained 100% blocked while DNS-over-TCP returned to baseline (15.38%).
-
Iran's June 2025 shutdown was enforced using fine-grained, service-level techniques rather than BGP withdrawals or a single 'big switch' event: individual protocols were selectively blocked before and after the 7-day full blackout (June 18–25), with the total preparation and recovery periods each lasting roughly 4–5 days. Cloudflare Radar showed HTTP traffic reaching near-zero by June 18 but partial recovery already on June 21, while the authors' vantage point (AS57497) remained unreachable until June 25, confirming heterogeneous recovery across Iranian networks.
-
The paper demonstrates that two protocol-specific censorship changes — QUIC blocking reaching 100% and DNS-over-TCP blocking reaching 96.68% — both occurred in the scan conducted immediately before Iran's June 18 full blackout, and that similar shutdown preparations were also documented before Iran's January 2026 shutdown. The authors hypothesize that continuous long-term measurement of protocol-specific censorship rates could provide advance warning of impending shutdowns before they come into full effect.