Abstract pattern of interconnected red and black data lines suggesting network traffic on a dark background

Net Neutrality Monitor analyses how Internet Service Providers resolve, block and inject DNS traffic. The platform tracks servers under examination, surfaces country-level reports, and publishes a live blacklist of injected addresses.

View Country Reports
Continuous DNS probing across participating ISPs
Country-level neutrality scoring and breakdowns
Blacklist of injected addresses from probe data
Community-driven via forum, IRC and wiki

What the platform does

Net Neutrality Monitor provides real-time analysis of the censorship systems used by Internet Service Providers. It tracks DNS servers currently under examination, lists known DNS servers that respond correctly to specific tests, and produces country reports on the types of blocking detected — from gambling and file-sharing to streaming and image hosting.

  • DNS probes
  • Country reports
  • Injected addresses
  • ISP scoring
About the Project
Minimal line drawing of a server rack and connecting cables on a white background

Coverage across the monitored regions

Country reports are available for China, Colombia, Denmark, Estonia, Finland, Italy, Korea Republic of, Sweden, Switzerland, Thailand, Turkey and additional regions as new probes are activated.

  • 11+Countries with published reports
  • LiveDNS server list under examination
  • CC BY 2.5 IT / BY-SA 3.0Content licensing applied
  • OpenDonations and probe submissions
Browse DNS List
Monitored since 2010 Geo data · ipinfodb

How Volunteer Probes Reveal Internet Filtering Worldwide

Internet censorship can look different from one connection to the next. A website may load normally in Sydney but fail on a regional NBN connection, resolve to an unusual address in another country, or appear reachable while its HTTP request is quietly interrupted. To study these differences, Net Neutrality Monitor gathers measurements from volunteer-run probe nodes distributed across multiple networks and locations.

The project treats each probe as a useful observation rather than an unquestionable verdict. Nodes contribute DNS responses, connection results, filtering signals and timing information, allowing researchers to compare patterns across countries, providers and protocols. The data is intended for indicative research, so the collection process must be transparent about uncertainty, privacy and the limits of each measurement.

Measurement What the probe checks What it can indicate
DNS lookup Returned records, errors and altered answers DNS blocking, redirection or resolver differences
TCP connection Whether an address and port can be reached Routing failure, port filtering or network outage
TLS handshake Whether encrypted negotiation completes SNI-based interference, certificate problems or disruption
HTTP request Response code, content and connection behaviour Blocking pages, resets, throttling or application filtering
Repeated probe Whether the result persists over time Stable censorship versus temporary faults

How A Volunteer Probe Works

A volunteer node is a computer, server or compatible device that runs a measurement client from an ordinary Internet connection. The software receives a test target, performs a defined sequence of checks and sends back structured results. It does not need to inspect a user’s private browsing activity, and a well-designed probe should run only the tasks that its operator has authorised.

The process usually begins with a domain lookup. The node records which DNS resolver answered, what address was returned and whether the request produced an error. It may then attempt a direct connection to the resulting IP address, establish TLS, and request a page over HTTP or HTTPS. Comparing these stages helps distinguish a DNS block from interference that occurs later in the connection.

A probe also records context such as country, network, software version and approximate time. Precision is important because filtering systems can change quickly, while public IP addresses and ISP routes can shift. The system therefore associates results with a node identity without publishing unnecessary information about the volunteer or their household.

Hardware and network placement matter. A small home server in Melbourne may produce different evidence from a cloud instance in Perth, even when both use the same ISP brand. Selecting a node for a particular measurement goal resembles choosing mission-specific hardware: the equipment, connection and operating environment should suit the question being tested.

Why Location And Network Context Matter

Filtering is often implemented at the resolver, access network, transit provider or application layer. A result from a single location cannot establish that an entire country blocks a domain. Multiple nodes make it possible to compare an apparent failure with control observations from other networks and regions.

Australian geography makes this especially clear. A volunteer in Sydney or Melbourne may have a dense choice of fixed-line and mobile services, while someone in regional Queensland, Western Australia or the Northern Territory may depend on a smaller number of routes. NBN technology also varies between premises, so latency, packet loss and resolver behaviour can reflect access infrastructure as well as deliberate filtering.

The local market adds another variable. Telstra, Optus, TPG and smaller providers can use different DNS defaults, peering arrangements and filtering policies. A site that works through one Australian connection but fails through another deserves a comparative test rather than a simple “Australia blocks it” label. Mobile networks may produce still another result because their gateways and address pools differ from home broadband.

Legal and policy settings are part of the context, too. Australian copyright-related website blocking can involve court orders under the Copyright Act, while online safety regulation and provider policies may affect specific services or material. The monitoring system does not treat every failed request as proof of a legal block; it looks for technical signatures and records the level of confidence attached to each finding.

From Raw Measurements To Evidence

Raw probe output is converted into comparable events. A DNS response might be classified as successful, empty, redirected or inconsistent. A connection can be marked reachable, refused, timed out or reset. The classification rules are deliberately conservative because the same symptom can result from congestion, a broken server, a firewall or a temporary routing incident.

The system compares a target with reference domains and control measurements. If several unrelated sites fail at the same time, the likely explanation may be a local outage. If one domain returns a distinctive block page while control sites work normally, filtering becomes more plausible. Repeating the test from different nodes and at different times helps separate persistent behaviour from a short-lived technical fault.

Statistical summaries are useful only when their denominator is clear. A percentage may describe successful probes, responding nodes, tested networks or individual attempts. Users reviewing the dashboard can learn how to read dashboard charts before drawing conclusions from apparent increases or decreases in blocking.

The project also keeps failures visible. Missing data, stale nodes and incomplete protocol checks should not be silently presented as negative results. A node that has gone offline may reduce coverage, while a resolver timeout may say more about connectivity than censorship. Good reporting shows sample size, collection period, geographic spread and any confidence or quality indicators available.

Protecting Volunteers And Preserving Integrity

Volunteer participation requires clear boundaries. Operators should know what software will run, which destinations may be contacted, how often tests occur and what information is transmitted. The client should avoid collecting browsing history, credentials or unrelated traffic, and it should provide a straightforward way to pause or remove a node.

Privacy safeguards include minimising IP retention, separating operational identifiers from public results and aggregating location data where exact precision could identify a household. Australian participants may be particularly cautious about personal information leaving the country, so documentation should explain storage, access and deletion practices in plain language. The Privacy Act 1988 and the Australian Privacy Principles provide an important baseline, even where a volunteer project operates across several jurisdictions.

Probe integrity depends on tamper resistance and reproducibility. Results should include timestamps, software versions and test definitions, with changes to measurement logic documented. Independent checks can identify nodes that return implausible results, repeat identical answers or appear to manipulate requests. A suspicious node is not automatically malicious; misconfigured DNS, captive portals and home security products can create unusual patterns.

The project’s beta status and volunteer-supported model make transparency especially valuable. Public data should be described as indicative research, not a legal ruling or a guarantee that a service is inaccessible to every person in a country. Researchers can then cite the measurements responsibly and investigate disputed findings without overstating what the network can prove.

Practical Guidance For Interpreting Results

Readers can get more value from probe data by treating it as a body of evidence. A single red marker on a map is a starting point, while repeated results across independent nodes, providers and protocols provide stronger support for a filtering hypothesis. A dashboard should be read alongside its methodology, timestamps and coverage information.

Those who want a particular domain monitored can submit a URL through the project’s site-submission process. A useful submission includes the exact hostname, relevant scheme and any known alternative addresses. That helps distinguish a problem with one subdomain from a broader service outage.

Practical habits improve interpretation:

  • Compare DNS, TCP, TLS and HTTP results instead of relying on one failure signal.
  • Check several Australian networks or locations before describing a national pattern.
  • Treat mobile, NBN and cloud-hosted probes as different measurement environments.
  • Look at the collection period, sample size and node availability behind each statistic.
  • Use repeated tests to separate stable filtering from congestion or an ordinary outage.
  • Avoid publishing details that could identify a volunteer’s home connection.
  • Report uncertain findings as observations requiring further verification.

For Australian readers, local context should remain visible in every analysis. A result from a Sydney fibre connection may not represent a remote Western Australian service, and a DNS answer from a default ISP resolver may differ from one obtained through an independent resolver. Comparing these conditions is what turns scattered probe readings into a more useful picture of Internet access.

The central value of volunteer nodes is their diversity. Each node contributes a small, time-stamped view of how a network behaves, while the combined dataset reveals recurring differences between providers, places and protocols. What readers should remember is that reliable censorship analysis comes from repeated, privacy-conscious measurements interpreted with careful attention to network context.

Transparent, analytical, community-run

The platform documents how ISPs handle neutrality on the wire, with method notes, country breakdowns and a public blacklist of injected addresses. — Project methodology
Minimal line drawing of a person silhouette with a speech bubble on neutral background

Country reports at a glance

Snapshots from the published country reports. Open a tile to view the full regional analysis on the Reports page.

Minimal line drawing of Italy outline in red on white Minimal line drawing of Denmark outline in red on white Minimal line drawing of Switzerland outline in red on white Minimal line drawing of Thailand outline in red on white Minimal line drawing of Turkey outline in red on white Minimal line drawing of Malaysia outline in red on white Minimal line drawing of Belgium outline in red on white

Follow new probes, blacklist updates and country reports as they are published.

Subscribe