Why Website Owners Ask This Question
If you run an online store, a SaaS product or a content site with readers in mainland China, a sudden drop in Chinese traffic is usually the first sign that something is wrong. Before you start debugging your server, it is worth checking whether your domain is being filtered by the Great Firewall (GFW) — the collection of technical measures China uses to control access to foreign websites.
The Great Firewall uses several techniques at once. This guide focuses on the one you can test most easily from anywhere in the world: DNS poisoning. You can run the test yourself with our China Firewall Test.
How the Great Firewall Blocks Websites
There is no single “block switch”. Depending on the site, Chinese networks may use one or more of these methods:
- DNS poisoning (DNS injection): when a resolver inside China asks for the IP address of a blocked domain, a forged answer is injected that points to a wrong address. The browser then connects to a server that has nothing to do with the website, and the page never loads.
- IP blocking: traffic to specific IP addresses or ranges is dropped.
- SNI and keyword filtering: the firewall inspects the server name sent at the start of an HTTPS connection and resets connections to blocked hostnames.
- Throttling: some services are not blocked outright but become so slow that they are unusable.
DNS poisoning is the most common first layer for well-known blocked domains, and it leaves a clear fingerprint you can measure.
What a Poisoned DNS Answer Looks Like
A normal DNS lookup returns the addresses chosen by the domain’s own nameservers. A poisoned lookup returns addresses that the domain owner never published. In practice the forged addresses often belong to completely unrelated organizations. In our own tests, a Chinese public resolver answered wikipedia.org and youtube.com with addresses registered to Facebook’s network, while Google Public DNS returned the real Wikimedia and Google addresses.
Other possible signs are an empty answer, an NXDOMAIN (“domain does not exist”) response for a domain that clearly exists, or an answer in a private address range.
How Our China Firewall Test Works
The tool sends the same query to two resolvers:
- Google Public DNS (8.8.8.8) as the reference outside China.
- 114DNS (114.114.114.114), a widely used public resolver in China.
It then compares the answers. Because poisoned answers are injected on the path into China, querying a Chinese resolver from outside the country is enough to trigger the same behavior for many blocked domains.
Why a Different IP Address Is Not Automatically a Block
Large websites use content delivery networks (CDNs) and return different IP addresses depending on where the resolver is located. A Chinese resolver and Google’s resolver can therefore receive different, but perfectly legitimate, addresses. Simple tools that flag every difference produce many false alarms.
To avoid this, our tool looks up the autonomous system number (ASN) — the network that announces each IP address — for both answers. If both answers belong to the same network (for example, both to Cloudflare or both to Akamai), the difference is treated as normal CDN routing. If the Chinese answer points to an unrelated network, the result is reported as possibly blocked. You can look up any ASN yourself with our ASN Lookup tool.
How to Read the Results
- Not blocked at DNS level: the Chinese resolver returned the same addresses or addresses from the same network. DNS is not being poisoned, although other blocking methods may still apply.
- Possibly blocked – answer points to another network: the classic poisoning pattern.
- Possibly blocked – no DNS answer: the Chinese resolver returned nothing while Google returned a valid answer.
- Inconclusive: the reference resolver itself returned no answer, usually because the domain does not exist or has no A record.
One known limitation: when a blocked domain’s fake answer happens to fall inside the same network as its real answer, the DNS comparison cannot see the difference. That is rare, but it means a “not blocked” result is strong evidence rather than absolute proof.
What to Do If Your Site Is Blocked
There is no appeal process for the Great Firewall, and getting a domain unblocked is generally not possible. Businesses that depend on Chinese visitors usually choose one of these paths:
- A separate China-hosted site: hosting inside mainland China requires an ICP license issued by the Chinese authorities, and usually a local business entity or partner.
- Removing blocked third-party resources: sometimes a site is not blocked itself but feels broken because it loads fonts, scripts or maps from blocked services such as Google. Self-hosting these assets can make a big difference.
- Testing regularly: blocking can start or stop without notice. Re-test after major changes and monitor traffic from China in your analytics.
Related Checks
- Use DNS Propagation Checker to compare answers from resolvers around the world.
- Use Iran Firewall Test if you also serve users in Iran.
- Use Is My Site Down to rule out a general outage first.