Abstract pattern of interconnected red and black data lines suggesting network traffic on a dark background

Net Neutrality Monitor analyses how Internet Service Providers resolve, block and inject DNS traffic. The platform tracks servers under examination, surfaces country-level reports, and publishes a live blacklist of injected addresses.

View Country Reports
Continuous DNS probing across participating ISPs
Country-level neutrality scoring and breakdowns
Blacklist of injected addresses from probe data
Community-driven via forum, IRC and wiki

What the platform does

Net Neutrality Monitor provides real-time analysis of the censorship systems used by Internet Service Providers. It tracks DNS servers currently under examination, lists known DNS servers that respond correctly to specific tests, and produces country reports on the types of blocking detected — from gambling and file-sharing to streaming and image hosting.

  • DNS probes
  • Country reports
  • Injected addresses
  • ISP scoring
About the Project
Minimal line drawing of a server rack and connecting cables on a white background

Coverage across the monitored regions

Country reports are available for China, Colombia, Denmark, Estonia, Finland, Italy, Korea Republic of, Sweden, Switzerland, Thailand, Turkey and additional regions as new probes are activated.

  • 11+Countries with published reports
  • LiveDNS server list under examination
  • CC BY 2.5 IT / BY-SA 3.0Content licensing applied
  • OpenDonations and probe submissions
Browse DNS List
Monitored since 2010 Geo data · ipinfodb

How DNS over HTTPS shields your browsing from censorship

Every time you type a web address into your browser, your device reaches out to a Domain Name System (DNS) server to translate that friendly name into a machine-readable IP address. This lookup is one of the oldest and most exposed parts of internet plumbing, and in Australia it typically travels through networks operated by Telstra, Optus, TPG, and a handful of smaller carriers that share similar infrastructure.

DNS over HTTPS (DoH) wraps those lookups inside the same encrypted channel used to load ordinary web pages. Instead of asking "what is the IP for example.com?" in plain text, your browser sends the question through a TLS-encrypted HTTPS connection. The result is a request that looks like any other web traffic, making it much harder for intermediaries to read, log, or rewrite.

That privacy layer matters because DNS queries reveal where you are going even when the content itself is protected by HTTPS. Researchers, journalists, and curious everyday users in Melbourne, Sydney, Brisbane, Perth, and Adelaide all benefit from a setup that prevents third parties from profiling their reading habits or silently blocking specific destinations.

Beyond personal privacy, DoH has become a frontline tool in the debate over online filtering. As governments and ISPs experiment with content controls — from the long-running ACMA blacklist to newer court-ordered blocks — the technology offers a practical way to verify what is actually being restricted, rather than trusting whatever appears in the address bar.

How plain DNS leaks your activity

A standard DNS query is a small, unauthenticated UDP packet sent to a server, usually on port 53. Anyone sitting between your laptop and that server — the café Wi-Fi operator in a Brisbane shopping centre, the hotel network in Surfers Paradise, your home router, or your ISP itself — can read the destination hostname in clear text. The contents of the page you load are encrypted, but the front door is wide open.

Australian ISPs have historically logged these queries for operational and legal reasons. Retention periods vary, and metadata about who looked up which site at what time is precisely the kind of record that can be requested under a warrant, shared with overseas partners, or quietly monetised through advertising partners. The same metadata also feeds internal systems used to enforce content blocks, which is why a "blocked" page sometimes appears even when the destination is technically reachable.

Even networks that promise not to log cannot fully prevent upstream observers from seeing your lookups. A request that leaves your house in Hobart and passes through Sydney, Singapore, and Los Angeles touches several operators along the way, each capable of copying the hostname. Plain DNS treats every hop as a potential eavesdropper.

What DNS over HTTPS actually does

DoH takes the same question your computer needs to ask — "what is the IP for this domain?" — and ships it inside an HTTPS request, normally to a well-known URI on port 443. Because the entire exchange is encrypted with TLS, no observer between you and the DoH server can read the hostname you are asking about. The traffic also blends in with regular web browsing, which makes it much harder to identify and tamper with using deep packet inspection boxes.

The protocol is formalised in RFC 8484 and has been adopted by every major browser, most modern operating systems, and several public resolvers. The table below compares the most common approaches Australians are likely to encounter.

Feature Plain DNS DNS over HTTPS (DoH) DNS over TLS (DoT)
Default port 53 443 853
Encryption None TLS via HTTPS TLS directly
Looks like web traffic No Yes No
Easy to block centrally Easy Harder Easy
Browser support N/A Built into Firefox, Chrome, Edge Limited

DoT (DNS over TLS) provides similar confidentiality but uses a dedicated port that network operators can recognise and throttle. DoH hides in plain sight on the same port as HTTPS, which is why privacy advocates and censorship researchers tend to recommend it for everyday users.

The censorship connection

Filtering in Australia is layered. The Australian Communications and Media Authority (ACMA) maintains a list of URLs deemed to relate to issues such as child exploitation material, and ISPs are required to block them at the resolver level. Federal Court cases have added piracy sites to that invisible wall, and Section 313 of the Telecommunications Act gives law enforcement broad powers to request metadata that includes DNS records.

These mechanisms rely on the assumption that ISPs can see and shape DNS traffic. When a customer in Adelaide tries to load a blocked site, their resolver returns a different IP or a "this site is blocked" page. DoH short-circuits that flow by routing the lookup to a resolver outside the local filtering system, so the answer that comes back reflects the real state of the internet rather than the policy of one carrier.

This is also why open monitoring matters. Independent projects such as the probe network gather real-world measurements from volunteer machines around the country and compare what each ISP actually returns. The resulting data makes it possible to spot discrepancies, document overblocking, and hold carriers accountable for the boundaries they draw.

Setting up DoH on common devices

Enabling DoH is usually a matter of flipping a switch. Firefox has had built-in support for years and can be configured under Settings → General → Network Settings to use a custom resolver such as Cloudflare, Mullvad, or Quad9. Chrome and Edge expose the same option under Privacy and Security → Security → Use secure DNS, with the same provider list plus Google itself.

On mobile, iOS 14 and later and Android 9 and later both support system-wide encrypted DNS, though Android labels it "Private DNS" and asks for a hostname rather than a URL. Entering one.one.one.one (Cloudflare) or dns.quad9.net activates DoH or DoT depending on the network, with no app required. Windows 11 surfaces the same setting under Network & Internet → Wi-Fi → DNS server assignment, where you can point the machine at any compliant resolver.

For anyone who wants to contribute to the broader picture, submit URLs for review to help community-run monitors keep their blocklists fresh. A single submission from a Perth suburb can confirm whether a given hostname is reachable on every major Australian carrier or only some.

Limitations and trade-offs to keep in mind

DoH does not make you invisible. Your ISP still sees the IP addresses you ultimately connect to, the volume of traffic, and the timing patterns that traffic produces. Anyone performing a deep enough analysis — for instance, correlating a flurry of connections with a news event — can still draw conclusions. The technology removes the hostname layer from that view, which is meaningful but not absolute.

There is also a performance consideration. Routing every lookup through a distant resolver can add latency, especially for users in regional Queensland or Western Australia who are already far from the closest CDN edge. Local caching helps, and major DoH providers have anycast endpoints that land most Australians on a nearby point of presence, but the trade-off is worth knowing about.

Some networks actively fight back. Public Wi-Fi in airports, libraries, and certain hotels has been known to block known DoH endpoints, forcing devices to fall back to plain DNS or simply lose connectivity. A small set of behaviours to watch for includes browsers that silently disable DoH when captive portals are detected, enterprise-managed devices that override personal settings, and parental-control routers that intercept the DNS channel upstream. None of these are reasons to avoid DoH, but they are reminders that no single tool solves filtering on its own.

For readers who want to dig into how these systems behave under real Australian conditions, Megaways Pai Gow Poker analysis shows how a single domain's reachability can shift between carriers and over time, illustrating why continuous measurement matters.

Resolvers worth considering

  • Cloudflare 1.1.1.1 — fast, audited, with a strict no-logging policy.
  • Quad9 9.9.9.9 — blocks access to known malicious domains by default.
  • Mullvad DNS — operated by a Swedish VPN provider with a strong privacy record.
  • Google Public DNS 8.8.8.8 — widely supported but logs some data for diagnostics.

What to check on your Australian connection

  • Whether your chosen resolver returns the same answers from Sydney, Melbourne, and Perth.
  • Whether major sites still load when DoH is forced on and other VPN features are off.
  • Whether the ISP modem itself has a separate DNS override that needs disabling.

The practical takeaway is straightforward. Switching on DNS over HTTPS is a small, reversible change that meaningfully raises the cost of mass surveillance and routine content blocking. For Australians who care about a genuinely open web — whether the concern is the ACMA blacklist, court-ordered piracy blocks, or simply not leaving a list of every site they visit in their ISP's logs — enabling DoH in a mainstream browser is the lowest-friction place to start, and it pairs naturally with the community-run measurement projects that keep watch over what filters actually do.

Transparent, analytical, community-run

The platform documents how ISPs handle neutrality on the wire, with method notes, country breakdowns and a public blacklist of injected addresses. — Project methodology
Minimal line drawing of a person silhouette with a speech bubble on neutral background

Country reports at a glance

Snapshots from the published country reports. Open a tile to view the full regional analysis on the Reports page.

Minimal line drawing of Italy outline in red on white Minimal line drawing of Denmark outline in red on white Minimal line drawing of Switzerland outline in red on white Minimal line drawing of Thailand outline in red on white Minimal line drawing of Turkey outline in red on white Minimal line drawing of Malaysia outline in red on white Minimal line drawing of Belgium outline in red on white

Follow new probes, blacklist updates and country reports as they are published.

Subscribe