Security3 distinct publishers3 min readPublished
Cloudflare and Google DoH/DoT endpoints are failing on Russian networks, but the largest public measurement found no protocol-wide block. That makes the breakage messier, not milder.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The number worth pulling out of the ZaTelecom sample is not 3186. Participants ran 124 tests across 66 autonomous systems against 29 DoH servers on 22 and 23 August, according to Digital Report's account [14], which tops out at 3596 individual checks. The tally is 410 short of that, so the average run reached roughly 26 of the 29 endpoints, and the write-up does not account for the gap [1].
Headline success was 55%, rising to 73% once dead control addresses and errors from an outdated curl were removed [15]. That leaves 27% failure in aggregate, while Cloudflare's two endpoints failed 16 to 17% of the time and dns.google, Mozilla's Cloudflare address and several others sat between 4 and 9% [17][2]. The aggregate is being carried by cases like AdGuard's retired domain, which answered nothing in 90% of checks and was unreachable in 61 of 66 networks, against 8% failure for the current address of the same service [16].
Partial is the operationally awkward outcome. On Beeline's mobile network, Techora reported TLS connections to 1.1.1.1 and 1.0.0.1 on port 853 being reset while Google's dns.google timed out [10], and in some cases the same providers still answered plain unencrypted queries [12]. A reset comes back fast and a client can fall back; a timeout burns the full DNS timeout first, and a device pinned to DoT with no plaintext path simply stops resolving. Variance makes it harder to plan around: at Rostelecom, MTS, MGTS and SkyNet, between two and 17 services failed within the same network depending on the run, for reasons the measurement could not establish [19], while at Kompanon, NECSTEL and TeleMaks encrypted DNS was effectively absent [18].
Risky Business dated its bulletin 26 August 2026 and described blocking as under way [8]. The author of the Russian measurement concluded the opposite, that no sign of DoH being blocked as a protocol had turned up [21], and pointed out that the widely shared line about three thousand checks confirming a block inverts his own finding [22]. Both readings survive, because filtering particular resolver addresses and ports on particular networks is not a protocol ban, and 51 of the 66 networks were sampled once, leaving seven operators, about 11% of the set, with enough runs to support anything durable [20][3].
Roskomnadzor has confirmed nothing [5], the operators have not commented [13], and the March test on Beeline was denied by the ISP while outside experts documented it [6]. Set against the regulator's 2021 statement that it intended to block protocols hiding a user's destination, with DoH named [7], the pattern to design for is quiet, address-level filtering rather than an announced ban. Note what that filtering never needed to defeat: the ISP already saw which resolver was chosen and the connections that followed [24], and SNI stays in the clear without Encrypted Client Hello [26]. Confidentiality was not the pressure point. Reachability is cheaper to break.
Ranked by verification strength, evidence, and original report placement.
Risky Business published a Risky Bulletin podcast dated August 26, 2026, headlined "Russia starts blocking DoH and DoT", presented by news editor Catalin Cimpanu.
Russian internet users began reporting problems connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two protocols.
The reported bans cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 DNS servers.
DoH and DoT hide a user's DNS queries and intended destination from ISPs and other parties on the wire.
Blocks have been reported across several Russian regions, but Roskomnadzor has not confirmed an official block.
Roskomnadzor appears to have tested the block in March on the network of Beeline, one of Russia's largest telcos; the ISP denied the block while technical experts caught and documented it.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One sizeable public measurement, self-limiting
The breakage is documented beyond anecdote: a crowd-run test of 3186 checks across 66 autonomous systems and 29 DoH servers, with per-endpoint and per-network breakdowns and an explicit correction of the raw success rate from 55% to 73%. But it is a single, non-replicated measurement whose own author reports no protocol-level block, 51 of 66 networks were sampled once, and no operator or regulator statement exists to corroborate either reading.
Real but uneven and localized breakage
Observed impact is concrete but partial rather than systemic: near-total encrypted DNS unavailability at three small providers, 16-17% failures for Cloudflare's tested endpoints, 4-9% for dns.google and other well-reachable servers, and run-to-run instability of two to 17 failing services at four larger networks. Reports span Beeline, Rostelecom, Dom.ru and SkyNet, so the failures affect real users across multiple operators, but nothing in the sources shows nationwide or protocol-wide loss of DoH/DoT.
Block narrative outruns the measurement
Headlines in the cluster state flatly that Russia has started blocking DoH and DoT and that 'the bans cover' Cloudflare and Google resolvers, and a viral claim holds that more than three thousand checks confirmed the block. The measurement those checks come from concluded the opposite - no signs of DoH being blocked as a protocol - and showed failure concentrated on particular endpoints and small networks. The underlying breakage is real, which keeps the gap short of the extreme, but the causal and scope claims are overstated relative to what was measured.
State control motive documented, amplification pressure visible
Incentives are legible on several sides. Roskomnadzor stated in 2021 that it intended to block protocols hiding a user's intended destination and named DoH specifically, which gives the state a standing motive and makes suspicion cheap to assert. A prior denial by Beeline of a documented test shows operator incentive to deny filtering. Reporting incentives are also visible: a block headline travels further than an uneven-failures headline, as the viral 'three thousand checks confirmed the block' claim demonstrates, and one source is an explicitly sponsored newsletter. Finally, encrypted DNS itself shifts query visibility to Google or Cloudflare, giving those operators an interest in the reachability story.
Breakage solid, causation unresolved
Two independent publishers agree that Google and Cloudflare encrypted DNS is failing on multiple Russian networks, and one supplies a documented measurement with explicit limitations, so confidence in the reachability facts is fair. Confidence in causation is low: no official confirmation, a single non-replicated measurement, 77% of networks sampled once, and unexplained run-to-run variance mean the question of deliberate protocol filtering remains open.
build
77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
security
PavinLoader: the lures keep changing, the MSBuild stage does not1 distinct publisher
build
796 pages of semantic search with no vector database, and what it cost to skip one1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026
1 article · August 25, 2026
2 articles · August 25, 2026