IRBlock

Longitudinal measurement of Internet censorship in Iran, observed from outside

About

IRBlock tests four censorship mechanisms: DNS injection (forged answers from injectors at 10.10.34.x), HTTP block-page injection, HTTPS (TCP RST injection) (forged TCP resets triggered by the TLS SNI), and UDP/QUIC dropping (detected with a DNS-QUIC-DNS sandwich probe). Domain-level scans periodically test over 500M FQDNs (fully-qualified domain names) against the censored address population; inferred blocking rules are confirmed across repeated scans before release.

We measure from outside the country by using the GFI's own blocking as a side channel. Much of its filtering acts on traffic regardless of the direction it travels, so a crafted packet sent inward provokes filtering that a user inside would also encounter, and the injected response is the measurement. That bidirectional behaviour is not universal, so what we observe is the bidirectionally-triggerable portion of Iran's filtering apparatus: a user inside meets at least this much, and may meet more. See Q&A for what that includes and excludes, and Research for more technical details.

Censored IP addresses over time, by blocking mechanism

Unique IPv4 addresses in Iran observed under each censorship mechanism, one point per scanning batch. Scan cadence has varied over the record, and there are periods with no measurement due to factors outside our control, such as network and power outages or storage and system maintenance. The line breaks across those periods rather than joining over them.

These figures are a lower bound on censorship: we measure from outside Iran, so anything our probes cannot reach is missing rather than absent. See Q&A for what these measurements do and do not show.