Net Neutrality Monitor analyses how Internet Service Providers resolve, block and inject DNS traffic. The platform tracks servers under examination, surfaces country-level reports, and publishes a live blacklist of injected addresses.
View Country ReportsWhat the platform does
Net Neutrality Monitor provides real-time analysis of the censorship systems used by Internet Service Providers. It tracks DNS servers currently under examination, lists known DNS servers that respond correctly to specific tests, and produces country reports on the types of blocking detected — from gambling and file-sharing to streaming and image hosting.
- DNS probes
- Country reports
- Injected addresses
- ISP scoring
Coverage across the monitored regions
Country reports are available for China, Colombia, Denmark, Estonia, Finland, Italy, Korea Republic of, Sweden, Switzerland, Thailand, Turkey and additional regions as new probes are activated.
- 11+Countries with published reports
- LiveDNS server list under examination
- CC BY 2.5 IT / BY-SA 3.0Content licensing applied
- OpenDonations and probe submissions
Comparing DNS Blocking and HTTP Filtering in Australia
Every time a page fails to load on the NBN at home in Sydney or over a public Wi-Fi link in Melbourne, the cause is rarely a single thing. It might be a misconfigured router, a regional outage, or a deliberate act of filtering by the network operator. For researchers and curious users tracking how Australia's internet gets shaped, two techniques sit at the centre of almost every censorship debate: DNS blocking and HTTP filtering. They look similar from the outside, but they sit at very different layers of the network stack and show up with very different frequency in local data.
Understanding which approach is more common requires more than anecdote. It means looking at how Australian ISPs like Telstra, Optus, and TPG actually implement restrictions, what regulators at the Australian Communications and Media Authority (ACMA) require of them, and where the choke points really sit. This article walks through how each method works, what the local legal environment looks like, and what monitoring data is beginning to show about how often each technique actually appears in practice.
The mechanics of DNS-based blocking
DNS blocking operates at the level of name resolution. When a user types a domain into a browser, the device asks a DNS resolver to translate that name into an IP address. If the resolver has been instructed to refuse to answer for a specific domain, the request simply returns an error or a false address. The rest of the network never sees the original destination. This approach is cheap, easy to roll out, and trivial for an ISP to maintain through a centrally managed list.
In Australia, several major providers lean heavily on DNS-based responses for compliance. ACMA's "blocked websites" register, which includes offshore wagering operators and certain infringing sites, is often enforced this way. The advantage for the ISP is that the intervention happens before any HTTP traffic even leaves the customer's router. There is no need to inspect payloads, no need to maintain expensive deep-packet inspection clusters, and minimal impact on backbone throughput in Brisbane, Perth, or Adelaide. The trade-off is that anyone using a third-party resolver such as 1.1.1.1, 8.8.8.8, or a VPN-routed DNS server can usually bypass the block entirely.
The side effect is that DNS blocking tends to be over-broad in ways that frustrate researchers. When ACMA orders a provider to block a gambling operator's domain, the same order frequently takes down related mirror domains, analytics subdomains, and shared hosting ranges. False positives are common, and even services that integrate with public safety networks can be caught in the splash zone when a domain is broadly enumerated. From a monitoring standpoint, this means DNS blocks appear in the data as clusters of failures rather than a single clean signal, and they are particularly visible on consumer-grade connections in regional centres where users are less likely to change their default resolver.
How HTTP filtering intercepts requests
HTTP filtering sits higher up the stack. Instead of refusing to translate a name, the network element waits until the connection is opened and then inspects the request itself. This usually involves a transparent proxy or a layer-7 device that can read the Host header, the URL path, or even the contents of an encrypted payload if a TLS-inspection certificate is in play. A useful primer on the underlying mechanics can be found in an explainer on how firewalls block sites, which walks through the request lifecycle in more detail.
Because HTTP filtering is more granular, it is also more expensive. The device has to keep state on every active connection, parse request lines, and decide in milliseconds whether to forward, rewrite, or drop the traffic. For Australian ISPs operating at the scale of the NBN, this kind of stateful inspection is reserved for specific scenarios rather than used as a default censorship tool. Where it does appear is in enterprise contracts, public Wi-Fi gateways, school networks, and in the technical measures that rights-holders use to interrupt peer-to-peer piracy.
The same property that makes HTTP filtering expensive also makes it more precise. A well-configured filter can target a single path, a single user-agent, or a single query string while leaving the rest of the site untouched. That precision is rarely needed for the wide-net obligations that Australian law imposes, which is one of the main reasons HTTP filtering is far less common than DNS blocking at the consumer-ISP level. It still shows up, but in narrower, more deliberate contexts.
The Australian regulatory framework for blocking
Three legal pillars shape what gets blocked, and they each lean on different mechanisms. The Interactive Gambling Act 2001 gives ACMA the power to require ISPs to take "reasonable steps" to prevent Australians from accessing prohibited online wagering services. The Copyright Act under the "site blocking" regime, expanded through reforms in 2015, allows rights-holders to seek Federal Court orders forcing ISPs to render infringing sites inaccessible. The Enhancing Online Safety Act supports the eSafety Commissioner's work on cyber-bullying material and child sexual abuse content, which triggers blocking of its own kind.
In practice, the IGA pathway is dominated by DNS-level responses. The regulator publishes an updated list of prohibited services, and major providers implement blocking against that list through their recursive resolvers. This is why consumers looking for offshore casino and wagering platforms often see a clean "server not found" or a redirect to a warning page. Observers tracking blocked domains frequently surface clusters around real money casino brands as a useful indicator of how aggressively the list is enforced across providers.
Copyright site blocking is a different story. Federal Court orders tend to be specific about the technical method, and over time the preferred approach has drifted toward DNS blocking for most mainstream orders, with some hybrid arrangements that combine DNS redirection with HTTP path filtering. The technical expertise of the rights-holder's lawyers and the willingness of the ISP to deploy a specific appliance both shape the outcome. Either way, the orders are case-by-case rather than blanket, which is why they produce a smaller, more targeted footprint in monitoring data.
Head-to-head: how the two methods differ in practice
The table below summarises the operational differences that matter most when you are staring at probe data and trying to work out why a site is unreachable.
| Dimension | DNS blocking | HTTP filtering |
|---|---|---|
| Layer of operation | Name resolution (port 53) | Application layer (HTTP/HTTPS) |
| Typical accuracy | Coarse; affects subdomains and shared hosts | Fine; can target specific paths |
| Bypass difficulty | Low for users on third-party resolvers | Higher; requires VPN or TLS tricks |
| Infrastructure cost | Low; relies on recursive resolvers | High; needs stateful inspection |
| Legal use in Australia | Interactive Gambling Act, most site-blocking orders | Reserved for specific enterprise and school contexts |
| Visibility in consumer probes | Very common, often the first signal | Less common, more localised |
| False-positive risk | High when domains are shared | Low when configured carefully |
In Australian consumer traffic, the left column dominates. Probes run from home NBN connections in Sydney, Melbourne, and regional Queensland overwhelmingly show DNS-level symptoms when blocking is in effect, while HTTP-level symptoms tend to be confined to specific networks.
Where DNS blocking dominates in Australian traffic data
Probe data collected by volunteer projects that monitor reachability across Australian IP ranges consistently shows that DNS blocking is the workhorse of consumer-facing censorship. The pattern repeats across Telstra, Optus, and TPG, and it shows up even more sharply on smaller regional providers that resell NBN backhaul. The blocking is often invisible to the average user, who simply sees a "site can't be reached" error and assumes the site itself is down.
This is the regime that catches ordinary users looking for offshore wagering, certain infringing streaming services, and domains listed by international child-safety bodies. Researchers who chart block lists over time notice that DNS targets tend to expand quickly around major events. During the AFL and NRL seasons, for instance, ACMA and the major providers are known to refresh gambling-related block entries with unusual frequency, and the same ripple appears in DNS resolution failures for adjacent poker and casino variants that share infrastructure with blocked brands.
The reason DNS blocking wins on volume is partly technical and partly economic. A change to a resolver's response table takes minutes to push out. A new deep-packet inspection policy takes days to tune, certify, and roll back if it goes wrong. For compliance teams under regulatory deadline, the lower-friction option is almost always the one that gets chosen, and that bias is visible in the long-term shape of Australian monitoring data.
Where HTTP filtering still matters in Australia
HTTP filtering is rarer at the consumer level, but it is not absent. The clearest cases are corporate and education networks in the CBDs of Brisbane, Sydney, and Melbourne, where policy enforcement happens on the local gateway rather than at the ISP. Schools in particular use HTTP filtering to enforce the eSafety Commissioner's expectations around age-inappropriate content, and many of those deployments combine path-level blocking with DNS sinkholing for redundancy.
The other place HTTP filtering persists is in public Wi-Fi and venue networks. Pubs, libraries, and transport hubs that offer free connectivity frequently operate transparent proxies that can refuse, log, or rewrite HTTP traffic. These deployments are small in absolute terms compared to the DNS regime, but they produce a lot of complaints because users hit them unexpectedly when travelling. Mobile carriers in Australia, by contrast, have largely moved away from HTTP filtering for compliance purposes and rely on DNS and SNI-based responses instead, which keeps the consumer-ISP picture weighted toward the simpler approach.
For anyone trying to measure net neutrality in practice, the takeaway is that the most common intervention in Australia is also the most bypassable. Tracking which method is in play, and which provider is applying it, remains the clearest signal of how the country's filtering machinery is actually operating.
The cleanest way to contribute to that picture is to submit a specific URL or IP address through the Net Neutrality Monitor's monitoring form and tag the country as Australia, so the next round of probes adds a local data point to the global comparison.
Transparent, analytical, community-run
The platform documents how ISPs handle neutrality on the wire, with method notes, country breakdowns and a public blacklist of injected addresses. — Project methodology






