Minimal line drawing of a network map with red marker dots scattered across a light grid background, neutral and analytical in mood.

Blacklist Address List

Records of injected addresses and blacklisted content identified through the monitoring probes. Each entry reflects what the platform observed in active DNS responses.

What this list contains

The blacklist gathers addresses that appear to be inserted by Internet Service Providers into DNS responses, instead of returning the legitimate answer. These injected entries often redirect users to notification pages, block screens, or third-party landing zones.

Entries are gathered through the same probe network that powers the DNS server list. Each row is linked back to the ISP and country where the injection was observed, making cross-comparisons possible.

How entries are classified

An address is added when a probe receives a DNS reply that does not match the authoritative record and instead points to a different IP controlled by the ISP or a partner. Repeated observations across multiple probes strengthen confidence in the entry.

Some addresses appear only briefly during testing campaigns; others persist across months. The list does not judge legality or intent — it simply reports what was returned.

The blacklist page collects addresses that monitoring probes have observed being inserted into DNS responses by Internet Service Providers. Rather than returning the correct answer for a requested domain, these responses are altered to point toward notification pages, block screens, or third-party landing zones. Every entry reflects what was detected in live network traffic by the same probe infrastructure that feeds the broader monitoring system, offering a snapshot of how DNS-level filtering is being applied across participating regions and providers.

Each row in the list is connected back to the Internet Service Provider associated with the observation, making it possible to see where a particular address or hostname was being interfered with. The records are generated from continuous data collection, so the blacklist evolves as new injections are detected and previously active ones fade. Because the entries come from real DNS responses captured by the probes, they serve as a direct indication of which destinations are being substituted or redirected at the network layer in the countries and operators being studied.

The blacklist complements the other resources on the platform by focusing specifically on content that has been blocked, redirected, or otherwise tampered with through provider-controlled DNS systems. It works alongside the country reports, server lists, and statistical views to give a fuller picture of censorship activity and net neutrality conditions. Users exploring the page can compare entries across providers and regions to understand patterns in how filtering is implemented, helping frame discussions about transparency, user rights, and the integrity of internet routing in the areas covered by the monitoring effort.

Correlation with ISPs and countries

Each blacklist entry can be filtered by the country where it was seen and by the ISP operating the resolving DNS server. This makes it easier to spot nationwide block pages versus provider-specific actions.

For full context, the country pages summarise the blocking patterns observed, including categories such as gambling, file-sharing, and streaming where they apply.

  • Country reports
  • DNS server list
  • Probe network

View country reports

Contributing new findings

Observations grow stronger when more probes participate. If you can run a probe or submit DNS data for your country or ISP, the blacklist becomes a more accurate mirror of on-the-ground behaviour.

Help us monitor   Probes list