Abstract pattern of interconnected red and black data lines suggesting network traffic on a dark background

Net Neutrality Monitor analyses how Internet Service Providers resolve, block and inject DNS traffic. The platform tracks servers under examination, surfaces country-level reports, and publishes a live blacklist of injected addresses.

View Country Reports
Continuous DNS probing across participating ISPs
Country-level neutrality scoring and breakdowns
Blacklist of injected addresses from probe data
Community-driven via forum, IRC and wiki

What the platform does

Net Neutrality Monitor provides real-time analysis of the censorship systems used by Internet Service Providers. It tracks DNS servers currently under examination, lists known DNS servers that respond correctly to specific tests, and produces country reports on the types of blocking detected — from gambling and file-sharing to streaming and image hosting.

  • DNS probes
  • Country reports
  • Injected addresses
  • ISP scoring
About the Project
Minimal line drawing of a server rack and connecting cables on a white background

Coverage across the monitored regions

Country reports are available for China, Colombia, Denmark, Estonia, Finland, Italy, Korea Republic of, Sweden, Switzerland, Thailand, Turkey and additional regions as new probes are activated.

  • 11+Countries with published reports
  • LiveDNS server list under examination
  • CC BY 2.5 IT / BY-SA 3.0Content licensing applied
  • OpenDonations and probe submissions
Browse DNS List
Monitored since 2010 Geo data · ipinfodb

What our blacklist data reveals about regional censorship patterns

Internet filtering rarely follows a single national script. A website can be reachable through one provider, blocked by another, and unavailable only when a particular DNS resolver is used. Blacklist records help expose those differences by showing where a domain or IP address was tested, how it was classified, and whether the result was consistent across networks.

For people in Australia, this matters because access is shaped by a mix of federal regulation, commercial infrastructure and local network conditions. A household on the NBN in suburban Melbourne may see a different result from a traveller using mobile data in Cairns, while a business in Perth may rely on a managed DNS service with its own filtering rules. The data is most useful when treated as a map of observed behaviour rather than a final verdict about intent.

Signals in the dataset

A blacklist entry is a signal that a domain, URL or IP address has been associated with a filtering event. It may indicate a DNS response that prevents resolution, an ISP-level block page, a routing failure, or a match against a provider’s prohibited-content list. These mechanisms can look similar to an ordinary user, even though they point to different technical causes.

Regional patterns become clearer when individual records are grouped. If several probes in the same country report a matching result, that may suggest a broadly applied policy. If reports cluster around one provider, city or access method, the likely explanation is narrower: an ISP rule, a resolver configuration or a network-specific implementation.

The project accepts submissions for further monitoring, so researchers can submit an address when a blocked or questionable result needs to be checked over time. Repeated observations are more informative than a single failed connection, particularly when a site is also experiencing downtime, certificate errors or a change of hosting provider.

Geography changes the result

Censorship is often described by country, but national borders are only the first layer. Within Australia, traffic can pass through different carrier networks, DNS services and filtering systems depending on whether someone is in Sydney, regional New South Wales, Darwin or a remote Queensland community. A result recorded in one location should not automatically be treated as universal.

The structure of the Australian market reinforces this variation. Telstra, Optus and TPG operate large fixed and mobile networks, while smaller providers resell access or use different upstream arrangements. A local ISP may apply its own safety controls, use a third-party resolver, or leave DNS handling to the customer. Two neighbours on different plans can therefore encounter different responses to the same domain.

Network geography also affects measurement. A regional connection may take a different route from one in Brisbane, and mobile traffic can be handled through carrier infrastructure that changes as a device moves between coverage areas. During an outage, a block may be mistaken for censorship unless the same address is checked through several networks and at more than one time.

DNS filtering leaves distinctive traces

DNS filtering works before a browser retrieves most website content. The resolver may return an incorrect address, refuse to answer, redirect the user to a warning page, or claim that the domain does not exist. These outcomes can prevent access without the website itself being offline, making DNS records valuable indicators in a censorship investigation.

The pattern can be especially confusing when people use public resolvers, workplace networks or family safety products. An Australian home user might receive one answer from the ISP’s default DNS service and another after changing resolver settings. That difference does not prove that the website is safe or that a government order exists; it shows that control is being applied at a particular point in the connection.

Blacklist data can separate broad domain blocking from narrower URL filtering. A whole domain may fail consistently, while a specific path remains available. IP-based blocking creates another complication because unrelated sites can share hosting infrastructure. A record attached to an address may reflect collateral impact rather than a deliberate decision to target every service on that server.

Regulation and commercial policy overlap

Censorship patterns can reflect formal government action, but they can also arise from private terms of service, copyright enforcement, malware protection and parental controls. The visible outcome is similar: a user cannot reach a resource. The underlying authority, legal basis and technical method may be completely different.

Australia has a strong regulatory focus on online safety, harmful material and unlawful content. The eSafety Commissioner, courts, law enforcement bodies and industry codes can influence how providers respond to certain categories of material. Separately, gambling websites, piracy-related domains, scam infrastructure and child-abuse material may be treated under different processes. A blacklist result should therefore be read alongside the type of content and the network responsible for the block.

The Australian experience also includes practical differences between home broadband, public Wi-Fi and workplace access. A café in Adelaide may use a commercial security gateway, a university in Canberra may enforce an institutional policy, and a hotel in Hobart may filter categories through a managed service. Those results are relevant to access research, but they should not be presented as evidence of a nationwide restriction without broader testing.

What a blocked address can and cannot prove

A blacklist record shows that a test produced an observed result under defined conditions. It does not, by itself, prove why the result occurred. The domain could have changed its DNS records, the server could have been temporarily unavailable, or an automated security system could have classified it incorrectly. Time stamps and repeated probes are essential for distinguishing a persistent block from a short-lived technical fault.

IP addresses require particular caution. Hosting companies often place many unrelated domains on one address, and cloud platforms can move services between addresses quickly. A block aimed at one website may affect other services unintentionally. Conversely, a domain-based block may miss alternate subdomains, mirrors or newly registered addresses.

Country-level labels also need careful wording. If observations come from a limited number of networks, the dataset describes those tested networks rather than every user in the jurisdiction. This is why indicative research data should be reported with its sample size, probe location, access type and collection date. Clear limits strengthen the finding instead of weakening it.

Using the evidence carefully

The project is presented as a beta, volunteer-supported service developed and powered by AirVPN. Its project background explains the scope and purpose of the monitoring work, while the records themselves provide material for comparison rather than an official legal classification. Researchers, journalists and network operators can use the information as an early warning layer before conducting deeper technical checks.

A sound reading practice combines blacklist results with independent observations. Useful checks include comparing multiple DNS resolvers, testing both domain and IP access, reviewing the provider’s response, and checking whether the site works from a separate network. For Australian users, this might mean comparing a home NBN line with mobile data or a different ISP rather than relying on a single browser session.

Practical recommendations for interpreting regional censorship evidence include:

  • Record the test date, country, city or region, provider and DNS resolver.
  • Repeat the test from fixed-line and mobile networks where possible.
  • Separate DNS failure, HTTP blocking, routing problems and server downtime.
  • Treat IP-based matches cautiously when several domains share the address.
  • Describe results as observations unless an authoritative source confirms the cause.

This approach also helps prevent overstatement. A map showing many blocked entries can indicate a significant filtering environment, but it cannot reveal whether every block was ordered by the state, applied voluntarily by providers or triggered by a technical security rule. The strongest reports preserve that distinction.

Regional patterns reveal network priorities

Clusters in blacklist data can point to the priorities of different networks. A high concentration of blocked gambling domains may reflect local compliance practices or a targeted enforcement programme. A group of malware-related domains may show aggressive threat protection rather than political censorship. A sudden increase in inaccessible news or activist sites can warrant closer investigation, especially if it appears across several independent providers.

Timing matters as well. A domain may be blocked during a legal dispute, an election period, a major sporting event or a public safety incident, then become reachable later. Comparing records over weeks and months can reveal whether filtering is permanent, episodic or reactive. In Australia, an isolated event affecting users in Western Australia should not be generalised to the east coast without matching observations.

Differences between networks can be just as revealing as similarities. If one ISP blocks a category while another leaves it accessible, the result may expose commercial filtering choices or uneven implementation of a shared policy. If every tested provider returns the same failure, the explanation may lie outside censorship altogether, such as a global hosting outage, a domain seizure or a change in the site’s infrastructure.

The value of blacklist data lies in this pattern recognition. It turns scattered reports of “the internet being blocked” into comparable observations tied to place, provider, technology and time. Readers should remember that the most credible interpretation is precise: identify what was tested, describe what happened, and keep the technical evidence separate from assumptions about motive.

Transparent, analytical, community-run

The platform documents how ISPs handle neutrality on the wire, with method notes, country breakdowns and a public blacklist of injected addresses. — Project methodology
Minimal line drawing of a person silhouette with a speech bubble on neutral background

Country reports at a glance

Snapshots from the published country reports. Open a tile to view the full regional analysis on the Reports page.

Minimal line drawing of Italy outline in red on white Minimal line drawing of Denmark outline in red on white Minimal line drawing of Switzerland outline in red on white Minimal line drawing of Thailand outline in red on white Minimal line drawing of Turkey outline in red on white Minimal line drawing of Malaysia outline in red on white Minimal line drawing of Belgium outline in red on white

Follow new probes, blacklist updates and country reports as they are published.

Subscribe