Net Neutrality Monitor analyses how Internet Service Providers resolve, block and inject DNS traffic. The platform tracks servers under examination, surfaces country-level reports, and publishes a live blacklist of injected addresses.
View Country ReportsWhat the platform does
Net Neutrality Monitor provides real-time analysis of the censorship systems used by Internet Service Providers. It tracks DNS servers currently under examination, lists known DNS servers that respond correctly to specific tests, and produces country reports on the types of blocking detected — from gambling and file-sharing to streaming and image hosting.
- DNS probes
- Country reports
- Injected addresses
- ISP scoring
Coverage across the monitored regions
Country reports are available for China, Colombia, Denmark, Estonia, Finland, Italy, Korea Republic of, Sweden, Switzerland, Thailand, Turkey and additional regions as new probes are activated.
- 11+Countries with published reports
- LiveDNS server list under examination
- CC BY 2.5 IT / BY-SA 3.0Content licensing applied
- OpenDonations and probe submissions
The Hidden Risks of Public DNS in Countries With Internet Filtering
Australia's online landscape feels wide open compared to heavily filtered jurisdictions, yet the local DNS environment is rarely neutral. Telstra, Optus and TPG routinely resolve queries through infrastructure that honours ACMA takedown orders and the 2017 metadata retention regime. Many households treat their ISP-supplied resolver as a black box, assuming it simply translates names into addresses. In practice, the resolver is a pressure point where privacy, accuracy and censorship intersect.
A public DNS service such as Google Public DNS or Cloudflare 1.1.1.1 is often promoted as a privacy upgrade, but it carries trade-offs. Switching resolvers can bypass some ISP-level blocks, yet it can expose queries to foreign operators bound by different legal regimes. For Australians who travel, work remotely or access content from restricted regions, the resolver choice shapes what the internet actually looks like.
DNS lookups happen invisibly. Every link clicked, every app opened, every background check begins with a query that reveals intent. When a resolver logs, blocks or redirects that query, the consequences extend beyond a single webpage.
This piece walks through the hidden risks of relying on widely used public DNS services in places where filtering is active. It draws on patterns seen in network neutrality monitoring projects, where Australian submissions frequently show the same handful of resolvers producing inconsistent results.
Why Public Resolvers Carry Real Weight
Domain Name System queries are the address book of the internet. When a device wants to reach a website, it asks a resolver to translate a human-readable name into a numeric IP. Whoever runs that resolver sees every destination by name, the timestamp, and often the originating network. That visibility is what makes resolvers attractive to surveillance agencies and data brokers.
Public resolvers promise speed, redundancy and a clean reputation. Google Public DNS, Cloudflare, OpenDNS and Quad9 are the most commonly cited. Each markets itself with a privacy angle, ranging from "no logging" claims to IP truncation. The legal obligation to retain or share data depends on where the resolver is incorporated and where its servers sit. For Australians routing queries through a foreign resolver, the governing law can be the US, the UK or the Netherlands rather than Australian statute.
Switching resolvers does not necessarily increase privacy. It can simply shift visibility from Telstra or Optus to a multinational operator with its own disclosure obligations. In some restricted countries, foreign resolvers are intercepted and forced to return sanitised answers, defeating the purpose of changing resolvers entirely.
How DNS Hijacking Looks in Practice
DNS hijacking, also called DNS redirection or poisoning, happens when a query is answered with an IP the user did not request. The technique is used by ISPs to display captive portals, by governments to block banned content, and by criminals to drive traffic to phishing pages. In Australia, ISPs sometimes inject NXDOMAIN responses or redirect failed lookups to branded landing pages, particularly on mobile networks. Travellers connecting through hotel Wi-Fi in countries such as China, Iran, Turkey or Myanmar encounter more aggressive variants.
The danger is that the browser loads a page that looks plausible. A bank login might resolve to a clone site that captures credentials. A news domain might resolve to a state-approved mirror that mixes accurate reporting with planted articles. Because the address bar still shows the intended domain, the hijack is invisible without manual IP checks.
Researchers who track such behaviour often rely on community-submitted evidence. Australians who notice a familiar site returning odd results can submit a URL to a monitoring project so others can verify whether the anomaly is local or widespread.
Censorship Patterns at the Resolver Level
Restricted countries typically operate two filtering layers: one at the resolver, one at the routing level. The resolver layer is cheaper to maintain, so it is where most low-level blocking happens. Common targets include news outlets, opposition political sites, VPN provider domains, gambling platforms, and circumvention tools. In Australia, ACMA orders have produced blocks on piracy-related domains and, more recently, on certain extremist forums. These blocks are enforced at the resolver level, which means they affect every customer of an affected ISP but leave users of foreign public resolvers untouched.
The catch is that foreign resolvers may themselves be blocked. Several restrictive jurisdictions maintain lists of DNS over HTTPS endpoints and IP ranges belonging to common public resolvers. When that happens, the resolver either becomes unreachable or is forced through a middlebox that rewrites responses. For Australians using a public resolver to bypass a domestic ACMA block, the approach may simply not work when they cross into a country with active filtering.
The Neumon community regularly discusses these inconsistencies, with volunteers posting traceroutes and dig outputs that show where blocks originate. The pattern is rarely uniform: blocks appear on some Australian mobile networks but not on fixed-line NBN connections, on some international roaming routes but not others.
Risks Specific to Australians
The local context shapes the risk profile. Australia sits at the moderate end of the censorship spectrum. ACMA blocks are targeted rather than sweeping, and the major ISPs generally do not inject advertising into failed DNS queries. However, the 2017 metadata retention scheme obliges carriers to store connection records for two years, and resolver logs fall within that scope. Australians using the default ISP resolver leave a query trail that can be requested by law enforcement without a warrant in many cases.
Australians travelling or working remotely face different risks. Hotel and conference Wi-Fi in restrictive jurisdictions often forces all DNS through a local middlebox. Returning home, users may find their device still configured with a foreign resolver that performs poorly on Australian latency tests. Streaming services, banking apps and government portals such as myGov, ATO and Centrelink check the resolver's geographic origin and either degrade or refuse service when queries arrive from a foreign endpoint.
A few Australian-specific details worth noting:
- Telstra and Optus mobile networks sometimes return branded search pages for unrecognised domains, which can mask genuine hijacks.
- NBN providers such as Aussie Broadband and Superloop have built reputations on minimal interference, but their logging obligations remain identical to larger carriers.
- Public Wi-Fi at airports in Sydney, Melbourne and Brisbane often relies on captive portals that intercept the first DNS query to inject a login page.
Encrypted DNS and Its Practical Limits
DNS over HTTPS and DNS over TLS were designed to address interception by encrypting queries between the device and the resolver. DoH and DoT prevent casual eavesdropping on local networks and stop some forms of middlebox interference. They do not, however, hide the IP addresses of the resolvers themselves, and they do not protect against a resolver that willingly logs. A user in a restricted country who points their device at 1.1.1.1 over DoH still reveals that fact to any deep-packet inspection system along the path.
For Australians, encrypted DNS offers meaningful benefits on public Wi-Fi in cafes and airports, where unencrypted queries would otherwise be visible to anyone running a packet sniffer. The benefit diminishes on a home NBN connection. In a country with aggressive filtering, DoH can prevent the middlebox from rewriting responses, but only if the middlebox does not also block the DoH endpoint. When the endpoint is blocked, the connection times out and the device falls back to plain DNS, which the middlebox can manipulate freely.
A practical approach is to combine encrypted DNS with a trusted resolver that publishes a transparency report and operates in a jurisdiction with strong legal protections. Quad9 is operated by a Swiss non-profit and publishes regular statistics on blocked domains. Even so, no resolver is a substitute for understanding what is being asked of it and why.
Choosing a Resolver That Fits Your Situation
The right resolver depends on where you are, what you are doing and what you are trying to protect. The table below compares common public resolvers against Australian and international constraints.
| Resolver | Operator Jurisdiction | Logging Policy | Behaviour in Restricted Countries | Suitability for Australians |
|---|---|---|---|---|
| Google Public DNS 8.8.8.8 | United States | Temporary logs, deleted within 24–48 hours | Often reachable but subject to local blocking | Good for reliability, weak for privacy |
| Cloudflare 1.1.1.1 | United States | Claims no persistent logs | Reachable in most regions, DoH supported | Strong performance from Australian ISPs |
| Quad9 9.9.9.9 | Switzerland | No personal data logging, blocks malicious domains | Reachable where DoH is permitted | Useful for security-focused users |
| OpenDNS | United States (Cisco) | Logs for abuse mitigation | Reachable but historically blocked in some jurisdictions | Limited privacy benefit over ISP defaults |
| ISP default (Telstra, Optus, TPG) | Australia | Retained under metadata scheme | Honours ACMA orders | Simplest, but logged |
Beyond the table, three habits help in practice:
- Test resolvers from your actual location using dig or a dedicated app, not from a marketing page.
- Pair any resolver choice with encrypted transport (DoH or DoT) when possible.
- Remember that a resolver change does not hide your IP address from the destination server.
Resolver choice is a layered decision rather than a single switch. Australians who want both domestic reliability and reduced exposure abroad benefit from using a resolver that logs minimally, supports encrypted transport and is not on the block lists of the countries they visit. Pairing that resolver with a VPN that handles its own DNS avoids the gap where the tunnel drops, and checking that the chosen endpoints actually resolve from your local network keeps the configuration honest. The internet's address book is more consequential than its modest interface suggests, and a few minutes of resolver audit pays back every time the network behaves oddly.
Transparent, analytical, community-run
The platform documents how ISPs handle neutrality on the wire, with method notes, country breakdowns and a public blacklist of injected addresses. — Project methodology






