net4people / bbs

Forum for discussing Internet censorship circumvention
3.2k stars 75 forks source link

Is CloudFlare's DoH working in Iran? #224

Open parsanoori opened 1 year ago

parsanoori commented 1 year ago

If yes then how can we use it for v2ray clients?

wkrp commented 1 year ago

According to information in existing threads, it looks like Cloudflare's and many other DoH servers are blocked, or at least that the censors are trying to block them.

https://github.com/net4people/bbs/issues/125#issuecomment-1258220351

https://ooni.org/post/2022-iran-blocks-social-media-mahsa-amini-protests/#blocking-of-dns-over-https-doh

From the above chart (which aggregates OONI measurement coverage from the testing of popular DoH endpoints in Iran), we can see that as of 20th September 2022:

  • DoH endpoints that were previously accessible (such as cloudflare-dns.com and doh.opendns.com) started being blocked;
  • DoH endpoints that previously presented “anomalies” (due to TLS based interference, which is not automatically confirmed blocked) started to be annotated as “confirmed blocked” as well (as a result of ISPs implementing DNS based blocking by returning bogons, enabling the automatic detection and confirmation of censorship).

https://github.com/net4people/bbs/issues/153#issuecomment-1312425599

not so many DOH works good in iran, so i just test some DNSCRYPT and naive is working, some others are connecting using 1.1.1.1 DOH.

https://github.com/net4people/bbs/issues/156#issue-1452047373

Secondly, DOH and other types of encrypted DNS resolutions are completely or partly blocked in Iran. I have personally checked Google and Cloudflare DNS DOH servers in YogaDNS and can confirm this on Mokhaberat and Irancell ISPs. Please do share your finding. So DOH in itself is not much of help; unless we somehow get access to it (I will explain more down below).

us254 commented 1 year ago

If yes then how can we use it for v2ray clients?

nope

ftfws commented 1 year ago

https://every1dns.com/dns-query