Insights into an Iranian Internet Shutdown
Anonymous, Niklas Niere, Felix Graf Lange, Juraj Somorovsky
https://www.petsymposium.org/foci/2026/foci-2026-0016.php
PDF
Pcap files
The paper presents new observations from the June 18–25, 2025 Internet shutdown in Iran. (Not the more recent shutdowns of 2026 (Iran: Internet shutdown from 18:45 UTC 8 January 2026 · Issue #561 · net4people/bbs · GitHub, Iran: Internet shutdown from 7 UTC 28 February 2026 · Issue #586 · net4people/bbs · GitHub), the one last year.) The observations come out of incidental DNS, HTTP, TLS, and QUIC domain blocking experiments the authors were running at the time. By comparing data from before and after the shutdown, they were able to show that the shutdown was not an abrupt on–off event, but sequence of gradual and detectable changes. For example: QUIC started to be blocked before the shutdown and remained blocked afterward; while TCP-based DNS blocking increased before and returned to normal after. The authors express a hope that careful monitoring of network signals may allow predicting shutdowns shortly before they occur.
The domain blocking experiments used an in-country VPS vantage point located in AS57497. They were scanning 9,000 Tranco domains over DNS, HTTP, TLS, and QUIC, sending probes to their own server in Germany. They ran three separate scans: Scan 1 well before the shutdown; Scan 2 immediately before (interrupted by the onset of the shutdown); and Scan 3 after they regained access to the VPS. The period of complete shutdown began on 2025-06-18 and ended on 2025-06-21, but even then access was not completely restored. Their VPS did not become accessible again until 2025-06-25.
| Start date | End date | Observations | |
|---|---|---|---|
| Scan 1 | 2025-06-01 | 2025-06-12 |
|
| Scan 2 | 2025-06-17 | 2025-06-18 13:10 |
|
| Shutdown and partial recovery | 2025-06-18 14:00 | 2025-06-25 |
|
| Scan 3 | 2025-06-25 10:30 | 2025-07-07 |
|
This paper’s scans did not see evidence of the additional brief shutdown on 2026-07-05 that was reported by other sources.
Besides the changes in protocol and domain blocks, they recorded evidence of two different censorship injectors for HTTP and TCP. The injectors are distinguishable in the HTML title that appears in block pages and in the ranges of IP TTLs they use. The injector that has an HTML title of “NTE1” had an observed TTL range of 186–188. The other injector had a title of “NTL1” and a TTL range of 53–55. Both injectors were observed on all days except on 2025-06-11, when only NTL1 was seen.

