Insights into an Iranian Internet Shutdown (FOCI 2026)

Insights into an Iranian Internet Shutdown
Anonymous, Niklas Niere, Felix Graf Lange, Juraj Somorovsky
https://www.petsymposium.org/foci/2026/foci-2026-0016.php
PDF
Pcap files

The paper presents new observations from the June 18–25, 2025 Internet shutdown in Iran. (Not the more recent shutdowns of 2026 (Iran: Internet shutdown from 18:45 UTC 8 January 2026 · Issue #561 · net4people/bbs · GitHub, Iran: Internet shutdown from 7 UTC 28 February 2026 · Issue #586 · net4people/bbs · GitHub), the one last year.) The observations come out of incidental DNS, HTTP, TLS, and QUIC domain blocking experiments the authors were running at the time. By comparing data from before and after the shutdown, they were able to show that the shutdown was not an abrupt on–off event, but sequence of gradual and detectable changes. For example: QUIC started to be blocked before the shutdown and remained blocked afterward; while TCP-based DNS blocking increased before and returned to normal after. The authors express a hope that careful monitoring of network signals may allow predicting shutdowns shortly before they occur.

The domain blocking experiments used an in-country VPS vantage point located in AS57497. They were scanning 9,000 Tranco domains over DNS, HTTP, TLS, and QUIC, sending probes to their own server in Germany. They ran three separate scans: Scan 1 well before the shutdown; Scan 2 immediately before (interrupted by the onset of the shutdown); and Scan 3 after they regained access to the VPS. The period of complete shutdown began on 2025-06-18 and ended on 2025-06-21, but even then access was not completely restored. Their VPS did not become accessible again until 2025-06-25.

Start date End date Observations
Scan 1 2025-06-01 2025-06-12
  • Normal censorship for Iran, about 15% of domains blocked on DNS, HTTP, and TLS
  • No QUIC blocking
Scan 2 2025-06-17 2025-06-18 13:10
  • QUIC initial packets 100% blocked
  • DNS over TCP 97% blocked (post TCP handshake)
Shutdown and partial recovery 2025-06-18 14:00 2025-06-25
  • Complete shutdown June 18 to 21
  • Partial restoration until June 25
Scan 3 2025-06-25 10:30 2025-07-07
  • QUIC remained 100% blocked
  • DNS over TCP blocking returned to normal, about 15%
  • DNS over UDP blocking increased to 89% (packet dropping)

This paper’s scans did not see evidence of the additional brief shutdown on 2026-07-05 that was reported by other sources.

Besides the changes in protocol and domain blocks, they recorded evidence of two different censorship injectors for HTTP and TCP. The injectors are distinguishable in the HTML title that appears in block pages and in the ranges of IP TTLs they use. The injector that has an HTML title of “NTE1” had an observed TTL range of 186–188. The other injector had a title of “NTL1” and a TTL range of 53–55. Both injectors were observed on all days except on 2025-06-11, when only NTL1 was seen.

So did the VPN over DNS-UDP work during the outage?

This paper doesn’t talk about DNS tunneling directly. Section 2.2.4 says that there was a much higher rate of DNS/UDP packet drops after the shutdown.

Separately, the evidence is ambiguous, but DNS tunnels may have been partially effective. One user reported “dns tunnel won’t work, only A records return, TXT no response”. Cloudflare Radar showed an increase in the proportion of TXT queries during the shutdown, which is a sign of DNS tunneling:

"DNS queries by type time series for Iran. Distribution of DNS queries by type over time." A stacked histogram over time for June 2025. The usual state has about 60% type A, 20% type AAAA, 0% type TXT. Starting about June 13, the fraction of TXT starts to grow, reaching a maximum of about 25% on June 21, then decreasing sharply on June 25 and then going almost again to zero on June 29.

There’s more evidence of DNS tunneling in the 8–27 Jan 2026 and 28 Feb–26 May 2026 shutdowns. On those threads there were many guides on setting up and using DNS tunnels. Cloudflare Radar shows an even larger increase in the proportion of TXT queries as well (sorry about the different colors):

"DNS queries by type time series for Iran. Distribution of DNS queries by type over time." A stacked histogram over time for January–June 2026. The usual state has about 60% type A, 20% type AAAA, 0% type TXT. In January and then again in March–June, the fraction of TXT greatly increases, reaching a maximum of about 90% on March 1. By the end of June TXT is down to about 10%.