Understanding the Impact of Encrypted DNS on Internet Censorship
Lin Jin, Shuai Hao, Haining Wang, Chase Cotton
Abstract
DNS traffic is transmitted in plaintext, resulting in privacy leakage. To combat this problem, secure protocols have been used to encrypt DNS messages. Existing studies have investigated the performance overhead and privacy benefits of encrypted DNS communications, yet little has been done from the perspective of censorship. In this paper, we study the impact of the encrypted DNS on Internet censorship in two aspects. On one hand, we explore the severity of DNS manipulation, which could be leveraged for Internet censorship, given the use of encrypted DNS resolvers. In particular, we perform 7.4 million DNS lookup measurements on 3,813 DoT and 75 DoH resolvers and identify that 1.66% of DoT responses and 1.42% of DoH responses undergo DNS manipulation. More importantly, we observe that more than two-thirds of the DoT and DoH resolvers manipulate DNS responses from at least one domain, indicating that the DNS manipulation is prevalent in encrypted DNS, which can be further exploited for enhancing Internet censorship. On the other hand, we evaluate the effectiveness of using encrypted DNS resolvers for censorship circumvention. Specifically, we first discover those vantage points that involve DNS manipulation through on-path devices, and then we apply encrypted DNS resolvers at these vantage points to access the censored domains. We reveal that 37% of the domains are accessible from the vantage points in China, but none of the domains is accessible from the vantage points in Iran, indicating that the censorship circumvention of using encrypted DNS resolvers varies from country to country. Moreover, for a vantage point, using a different encrypted DNS resolver does not lead to a noticeable difference in accessing the censored domains.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 753fa16e-6e5d-4f4d-bff2-70d3713497caCited by top-tier papers1
Ask how each one uses itBuilds on11
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- Global Measurement of DNS ManipulationPaul Pearce, Ben Jones, Frank Li, Roya Ensafi et al.USENIX Security 2017 · 163 citations
- Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution PathBaojun Liu, Chaoyi Lu, Hai-Xin Duan, Ying Liu et al.USENIX Security 2018 · 67 citations
- Quack: Scalable Remote Measurement of Application-Layer CensorshipBenjamin VanderSloot, Allison McDonald, Will Scott, J. Alex Halderman et al.USENIX Security 2018 · 66 citations
- Geneva: Evolving Censorship Evasion StrategiesKevin Bock, George Hughey, Xiao Qiang, Dave LevinCCS 2019 · 60 citations
Related papers
- Tracking the Stray Sheep: Understanding DNS Response Manipulation in the WildWenhao Wu, Zhaohua Wang, Zihan Li, Qinxin Li et al.WWW 2026
- Encrypted DNS -> Privacy? A Traffic Analysis PerspectiveSandra Deepthy Siby, Marc Juarez, Claudia Díaz, Narseo Vallina-Rodriguez et al.NDSS 2020
- Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-LayerNiklas Niere, Felix Lange, Robert Merget, Juraj SomorovskyS&P 2025
- Comparing the Effects of DNS, DoT, and DoH on Web PerformanceAustin Hounsel, Kevin Borgolte, Paul Schmitt, Jordan Holland et al.WWW 2020 · 59 citations
- How the Great Firewall of China Detects and Blocks Fully Encrypted TrafficMingshi Wu, Jackson Sippe, Danesh Sivakumar, Jack Burg et al.USENIX Security 2023
