UK FACT CHECK POLITICS

UK FACT CHECK POLITICS

Independent reporting, transparently verified by objective AI fact-checking
Menu
Get Involved
Account
arxiv.org 11 July 2026 at 04:17

A Multi-Perspective Study of the Internet Shutdown in Iran

View original article →
82
Trust Score

Largely Credible / Mostly Verified (methodology unverifiable, core context confirmed)

Confidence: Medium-High

Standard
Emotional Tone Low
How emotionally charged the language is (low is neutral)
Reading Level Advanced
Suitable for age 16+ readers (grade 11)
Article Length Very long
5,290 words
Caps & Emphasis Moderate
3.9% of words are capitalised (high can indicate sensationalism)

Executive Summary

This preprint presents a three-plane (Censys passive scans, active TCP reachability probing from five vantage points, and RIPE RIS BGP analysis) characterisation of Iranian Internet shutdowns in January and March 2026, plus longitudinal comparison with the 2019 and 2022 events. Its central factual premises are strongly corroborated by independent, reputable sources: Iran did impose a nationwide blackout beginning 8 January 2026 and a second, far more severe blackout from 28 February 2026 that became the longest recorded nationwide shutdown (widely reported as ~88 days). The paper's headline mechanism claim — that Iran enforces shutdowns via forwarding-plane null-routing at TIC's centralised gateway while leaving BGP announcements broadly intact — aligns closely with Kentik/Doug Madory's independent analysis ('stealth blackout'). Contextual entities (TIC/AS49666, the National Information Network, ArvanCloud's censorship role and sanctions) are all verifiable. The main caveat is that the paper frames both 2026 events as protest-driven, whereas independent reporting shows the late-February/March event coincided with (and was triggered by) US-Israel military strikes on 28 February 2026 — a contextual omission rather than a factual error. The paper's internal quantitative claims (exact host-count decompositions, per-prefix verdict percentages, Censys pipeline-artefact attribution) cannot be independently verified as they depend on the authors' own unpublished datasets; these are marked Unverified rather than disputed. No fabrication indicators were found; the tone is measured, technical, and appropriately hedged (self-labelled preprint). Overall the document is a credible technical contribution whose external factual scaffolding checks out.

Factual Verification

Verified Claims

  • Iran imposed a nationwide Internet shutdown beginning in January 2026 (independent sources date onset to 8 January 2026, the 12th day of protests).
  • A second, more severe nationwide blackout began in late February / March 2026 and became the longest documented nationwide Internet shutdown in any country (widely reported as ~88 days).
  • Iran's Telecommunication Infrastructure Company (TIC) operates AS49666 and functions as the centralised international gateway/backbone; confirmed via PeeringDB and Wikipedia.
  • Iran operates the National Information Network (NIN), a domestic intranet enabling continued internal connectivity during global-Internet cutoffs; confirmed by US Treasury and multiple sources.
  • ArvanCloud has been officially associated with facilitating Iranian Internet censorship and was sanctioned by the US Treasury/OFAC (June 2023), EU and others.
  • Iran shut down the Internet during the November 2019 fuel-price protests (onset 16 November 2019) and during the 2022 Mahsa Amini protests.
  • Kentik/Doug Madory independently documented that during the 2026 shutdown the vast majority of Iranian IPv4 routes continued to be announced globally despite the traffic blackout, consistent with the paper's 'forwarding-plane null-routing with BGP retention' thesis ('stealth blackout').

Unverified Claims

  • Specific quantitative figure that 96.5-97.4% of 4,571 BGP-visible Iranian prefixes are null-routed across all five vantage points (depends on authors' own active-probing dataset; not independently reproducible).
  • The anomalous 3.7x inter-event Censys expansion peaking at ~3.48M hosts and its attribution to Censys predictive re-injection plus transient DPI reconfiguration (authors' interpretation of their own dataset).
  • Precise host-count decompositions in Tables 1-2 (e.g., January floor 46K/-95.3%; March active-host floor ~10-11K; ArvanCloud retaining 99.7% visibility; academic networks 79% of the 16-17 March recovery).
  • Exact BGP-coverage percentages in Table 3 across 33 RIPE RIS snapshots (e.g., 85.1%->62.3%->54.7% in 2019; 80-88% stable in 2022/2026) — directionally consistent with public reporting but specific figures rely on the authors' parsing.
  • The claim that 2022 used 'pure' forwarding-plane null-routing with no BGP withdrawal (public 2022 reporting emphasises throttling/regional cuts; the fine-grained BGP-stability quantification is the authors' own).
  • Claim that ~12-20% of RIPE-allocated Iranian IPv4 prefixes are not globally announced under normal conditions (authors' measurement).

Disputed / False Claims

  • No claim was confirmed False against a primary source or two dated reputable secondary sources. NOTE (contextual discrepancy, not a false claim): the paper characterises both 2026 events as occurring during 'unrest/crisis' and lists them among protest-era shutdowns, but independent sources (Britannica, Wikipedia, Amnesty International) attribute the 28 February 2026 blackout to the US-Israel military strikes on Iran that began 28 February 2026 rather than to protests alone; this is an incomplete framing rather than a demonstrable falsehood.
  • Potential tension (not adjudicated False): some monitors (e.g., Cloudflare via Internet Society Pulse) reported a ~98.5% drop in announced Iranian IPv6 space on 8 January 2026, which appears to partially conflict with the paper's 'BGP announcements remain stable' thesis; the paper's claim is specific to IPv4 prefix coverage, so this is a scope difference requiring caution rather than a confirmed error.

Bias & Presentation

Detected Biases:

  • Framing bias (mild): both 2026 events are grouped under protest/'unrest' framing, underplaying that the late-February event coincided with US-Israel military strikes.
  • Methodological self-interest (low): paper repeatedly emphasises limitations of BGP-only monitors and passive scans to motivate its own multi-plane approach, but does so transparently.
  • No evident political/ideological slant; the document is technically neutral and does not editorialise about the Iranian government beyond factual attribution of enforcement.

Language Patterns

Emotional manipulation: 0.04

Quality Assurance

Limitations: Article contains no resolvable embedded sources; internal datasets are unpublished, so quantitative reproduction was not possible. Verification focused on externally checkable facts and mechanism corroboration.

Confidence

Level: Medium-High

High confidence in the external factual scaffolding: the existence, dates, severity and record-setting duration of the 2026 shutdowns, the identity and role of TIC/AS49666, the NIN, ArvanCloud's sanctioned censorship role, and the 2019/2022 precedents are all corroborated by multiple reputable and primary sources, and the paper's central null-routing/BGP-retention mechanism is independently supported by Kentik/Madory. Confidence is reduced to Medium-High overall because the paper's fine-grained quantitative results depend entirely on the authors' unpublished datasets and cannot be independently reproduced (marked Unverified), and because of a contextual framing gap regarding the US-Israel-strike trigger of the March event plus an IPv4-vs-IPv6 scope nuance. As an un-peer-reviewed preprint, residual uncertainty remains on the precise figures.

Search Journal

Query: Iran internet shutdown January 2026

Query: Iran nationwide internet shutdown March 2026

Query: Iran TIC Telecommunication Infrastructure Company AS49666 gateway

Query: ArvanCloud AS205585 sanctions Treasury jy1518

Query: Iran 2019 November internet shutdown BGP

Query: Iran 2022 Mahsa Amini internet shutdown

Query: Madory Kentik Iran stealth blackout whitelisting BGP routes remain

Query: Iran 2026 blackout Israel US strikes February 28 timeline

Query: National Information Network Iran NIN

Query: IODA Iran 2019 BGP visible active probing blackout

Article Content

###### Abstract.

Iran conducted two nationwide Internet shutdowns in January and March 2026, the latter ongoing at the time of writing and the longest documented Iranian disruption. Using a three-plane methodology combining passive Censys scan data, active TCP reachability probing from five vantage points, and BGP analysis across 33 RIPE RIS snapshots from 2019 to 2026, we show that the 2022 and 2026 shutdowns are enforced via forwarding-plane null-routing at a centralized border while BGP announcements remain stable, and that Iran shifted from partial BGP withdrawal in 2019 to pure null-routing by 2022. This control- and forwarding-plane decoupling prevents BGP-based outage monitors from detecting shutdowns.

Active probing of 4,571 BGP-visible Iranian prefixes shows that 96.5 to 97.4% are null-routed across all vantage points, indicating a centrally coordinated mechanism. Passive scan analysis reveals a 3.7 times increase in visible hosts between shutdown events due to measurement artifacts rather than recovery, along with two structural exemptions: academic networks rise from 1.4 to 66.6% of visible hosts during partial recovery, and ArvanCloud CDN retains 99.7% visibility while other major operators drop by at least 77%.

## 1. Introduction

Internet censorship and traffic manipulation in Iran have been documented for over a decade(Verkamp and Gupta, [2012]( "Inferring mechanics of web censorship around the world"); Aryan et al., [2013]( "Internet censorship in Iran: A first look"); Anderson, [2013]( "Dimming the Internet: Detecting throttling as a mechanism of censorship in Iran")), with prior work characterizing mechanisms such as protocol filtering and keyword-based blocking(Pearce et al., [2017b]( "Global measurement of DNS manipulation"), [a]( "Augur: Internet-wide detection of connectivity disruptions"); Tai et al., [2025]( "IRBlock a large-scale measurement study of the great firewall of Iran"); Elmenhorst et al., [2021]( "Web censorship measurements of HTTP/3 over QUIC")). Less attention has been given to large-scale, event-driven Internet disruptions, which have been observed in multiple countries during periods of unrest or crisis, including Egypt and Libya in 2011(Dainotti et al., [2011]( "Analysis of country-wide Internet outages caused by censorship")) and Myanmar in 2021.1 1 1[ Iran has also experienced such disruptions, including during the 2019 fuel-price protests, the 2022 Mahsa Amini period, and two nationwide events in early 2026 that we examine in this paper.1 1 footnotetext: This manuscript is a preprint. We welcome feedback and suggestions.

#### The problem.

Iran’s Telecommunication Infrastructure Company (TIC, AS49666) operates a centralized international gateway. Rather than withdrawing routes, TIC enforces shutdowns by installing forwarding-plane null routes that silently discard traffic while leaving BGP announcements intact. As a result, Iran remains visible to BGP-based monitors during nationwide outages. Using 33 RIPE RIS snapshots across three events (2019–2026), we show 80–88% RIPE-allocated Iranian IPv4 prefixes remain globally announced during the 2022 and 2026 shutdowns, with within-event variation under 1.7 percentage points (pp). In contrast, in 2019, coverage drops from 85.1% to 62.3% and 54.7%, indicating partial BGP withdrawal. This shift suggests an evolution from a mixed control- and forwarding-plane approach in 2019 to pure forwarding-plane null routing in later events.

#### The 2026 events.

We analyze two nationwide shutdowns in January and March 2026 using a multi-plane measurement approach combining passive Censys scan data, active TCP reachability probing from five global vantage points, and BGP routing analysis. The January event reduces visible hosts by 95.3% from a baseline of approximately 935K. The March event is more severe, reaching a floor of approximately 10–11K hosts, or about 1% of the historically validated baseline. Between these events, the Censys dataset exhibits an anomalous 3.7\times expansion in visible Iranian IP space, peaking at {\approx}3.48\text{M} hosts. This behavior has no precedent in 2025 data and is not observed in a control country. We attribute this inflation to the interaction between Censys’s predictive re-injection mechanism and Iran’s filtering infrastructure, and adjust all cross-event comparisons accordingly.

We apply a multi-plane measurement approach to Internet shutdowns to show how these perspectives complement each other and to expose the limitations of each method. This provides guidance for more accurate and informed shutdown analysis. In summary, this paper makes the following contributions:

* • We provide a multi-plane characterization of two recent Iranian shutdowns, showing that passive scans, active TCP probing, and BGP analysis yield different and complementary observations.

* • We show forwarding-plane null-routing with BGP retention as Iran’s shutdown mechanism in 2022 and 2026, and document a mechanism shift from partial BGP withdrawal in 2019, providing a longitudinal view of evolving enforcement.

* • We identify the anomalous inter-event Censys expansion and missing records as measurement pipeline artifacts, with implications for passive-scan studies of shutdown severity.

* • We present the first AS-level analysis of shutdown survivors and partial recovery, identifying ArvanCloud CDN as fully exempt from shutdowns and attributing the majority of the March 16 and 17 recovery to academic networks, consistent with targeted temporary exemptions.

## 2. Background and Related Work

Prior work has developed complementary approaches to detecting and characterizing Internet shutdowns. Early studies by Dainotti et al.(Dainotti et al., [2011]( "Analysis of country-wide Internet outages caused by censorship")) demonstrated the use of BGP and darknet traffic to analyze the 2011 shutdowns in Egypt and Libya. More recent work by Ramesh et al.(Ramesh et al., [2023]( "Network responses to Russia’s invasion of Ukraine in 2022: A cautionary tale for internet freedom")) applied multi-plane measurements to Russia’s 2022 network responses, identifying control-plane changes and forwarding-plane filtering. The OONI project(Filasto and Appelbaum, [2012]( "OONI: Open Observatory of Network Interference")) and Aryan et al.(Aryan et al., [2013]( "Internet censorship in Iran: A first look")) have documented Iranian application-layer blocking through in-country measurement. The January 2026 shutdown is investigated using aggregated third-party data and transit traffic data, with analysis of circumvention via Starlink and peer-to-peer mesh tools(Aceto et al., [2026]( "Iran’s January 2026 Internet shutdown: Public data, censorship methods, and circumvention techniques")). In contrast, we perform per-prefix active TCP reachability across all BGP-visible Iranian prefixes, extend the analysis to the March 2026 shutdown, and identify Censys pipeline artifacts that cause passive-scan studies to misreport onset and severity of shutdowns.

Internet Outage Detection and Analysis (IODA)([9]( "Internet Outage Detection and Analysis (IODA)")) integrates BGP visibility, active ICMP probing, and Internet background radiation to provide near-real-time outage detection. Internet-wide scanning approaches, such as those provided by Censys, are described by Durumeric et al.(Durumeric et al., [2025]( "Censys: A map of Internet hosts and services")). While platforms such as IODA, NetBlocks, and Kentik have reported on these events in near-real-time(Madory, [2026]( "From stealth blackout to whitelisting: inside the iranian shutdown")), our work provides the first _per-prefix_ forwarding-plane characterization across multiple vantage points, quantifies partial BGP withdrawal in 2019 and BGP stability in 2022 and 2026, and identifies measurement artifacts that cause Internet scanning platforms to systematically misreport shutdown severity.

Our work explicitly uses cross-plane discrepancies as the primary indicator of disruption. We show that stability in the BGP control plane is not necessarily indicative of normal operation, but can instead reflect systematic forwarding-plane enforcement. While platforms such as IODA and RIPE Atlas incorporate multiple vantage points that can expose such effects, prior work has not, to our knowledge, explicitly isolated or quantified this phenomenon. We show that Iran’s BGP routing tables remain stable in recent shutdowns, reflecting a shift from the 2019 withdrawal-based approach.

### 2.1. Iranian Internet Architecture

Iran operates a highly centralized Internet architecture in which the TIC and Institute for Research in Fundamental Sciences (IPM) function as the primary international transit gateways(Anderson, [2013]( "Dimming the Internet: Detecting throttling as a mechanism of censorship in Iran"); Madory, [2026]( "From stealth blackout to whitelisting: inside the iranian shutdown")). Domestic operators rely on TIC for upstream access, creating a natural enforcement point at the international boundary. This centralized topology enables coordinated, near-simultaneous disruption across heterogeneous ASes without requiring independent action by individual networks.

In parallel, Iran has developed the National Information Network (NIN)(Aryan et al., [2013]( "Internet censorship in Iran: A first look"); Mehr News Agency, [2016]( "Iran launches national information network")), a domestically scoped infrastructure that maintains internal connectivity independent of global routing. The NIN is the operational foundation that makes prolonged shutdowns feasible: by preserving domestic reachability, TIC can enforce forwarding-plane null routes at the international boundary while government and critical services continue to function internally. Separately, approximately 12–20% of RIPE-allocated Iranian IPv4 prefixes are not globally announced under normal conditions, held in reserve or used for address space that does not require international reachability. This property is stable across all measurement dates rather than a shutdown artifact, and motivates our use of RIPE-delegated address space as the denominator for all coverage and severity calculations.

## 3. Methodology

Our methodology combines three measurement planes, each providing a complementary view of Iranian Internet connectivity that no single plane can supply alone.

### 3.1. Passive Measurement (Censys)

We use the Censys BigQuery dataset, which provides daily snapshots of Internet-wide scan observations(Durumeric et al., [2025]( "Censys: A map of Internet hosts and services")). For each day from January 1 to March 31, 2026, we query the number of distinct IPv4 addresses geolocated to Iran, yielding 87 daily observations (January 9–11 are absent from the Censys dataset). We additionally extract per-AS host counts on eight key dates to support AS-level analysis in Section[5]( "5. AS-Level Host Composition ‣ A Multi-Perspective Study of the Internet Shutdown in Iran").

#### Baseline and control.

To establish a baseline, we query twelve monthly snapshots across 2025, showing a stable range of approximately 910K–1.17M Iranian hosts with no observable trend. The January 2026 pre-shutdown value ({\approx}935K) falls within this range. Using Turkey as a control country, we observe a stable host count of approximately 1.3M, indicating that observed variations are specific to Iran rather than global scanning dynamics.

### 3.2. Active TCP Reachability Probing

#### Vantage Points.

We deploy measurement agents on five VPS instances in Istanbul, Frankfurt, Amsterdam, Singapore, and New York, providing geographic and topological diversity. All systems include opt-out webpages and reverse DNS records for identification in accordance with responsible scanning practices(Durumeric et al., [2024]( "Ten years of Zmap")).

#### Per-prefix probing.

We probe all 4,571 prefixes from the April 7, 2026 BGP snapshot via TCP to ports 80, 443, and 179 (BGP) at the sixth host address of each prefix; port 179 provides a routing-plane signal using standard TCP connection attempts. Each vantage swept the full prefix set 33–34 times over April 7–25 (169 total runs), with consensus results determined by majority vote. We classify each prefix into five result categories: null_route (all three ports time out, indicating a forwarding plane black hole despite a valid BGP route); bgp_withdraw (at least one port returns ICMP unreachable, consistent with absent forwarding state); firewall_acl (ports 80/443 time out while port 179 returns TCP RST, with routing infrastructure reachable and application traffic blocked); reachable (at least one application port responds); ambiguous (no condition above is met, typically due to mixed per-run verdicts below majority threshold).

### 3.3. BGP Routing Table Analysis

We download and parse 33 bview snapshots from RIPE RIS collector rrc00(RIPE NCC, [2024]( "RIPE Routing Information Service (RIS): Route Collectors")) spanning the 2019, 2022, and 2026 events (8, 8, and 17 dates), including pre-shutdown baselines for each event. Table[3]( "Table 3 ‣ Baseline coverage of Iranian address space. ‣ 6.1. BGP Routing Table Analysis ‣ 6. BGP Routing During Shutdowns ‣ A Multi-Perspective Study of the Internet Shutdown in Iran") shows one representative date per shutdown phase. We parse TABLE_DUMP_V2 RIB_IPV4_UNICAST entries and identify Iranian-origin prefixes using date-correct Iranian ASN sets extracted from RIPE NCC delegated statistics, yielding 668–842 Iranian ASNs per date depending on the year. We define _BGP coverage_ as the fraction of RIPE-allocated Iranian IPv4 prefixes with at least one covering BGP announcement (exact match, more-specific, or aggregate), computed using Python ipaddress containment checks. Manual inspection confirms zero false negatives. We additionally process four intermediate 2019 dates (Nov 16, 18, 19, 21) to characterize the withdrawal trajectory between the dates shown in Table 3; the Nov 21 floor (54.7% coverage) is reported in Section[6]( "6. BGP Routing During Shutdowns ‣ A Multi-Perspective Study of the Internet Shutdown in Iran").

### 3.4. Ethical Considerations

All measurements follow established responsible scanning practices(Durumeric et al., [2024]( "Ten years of Zmap")). Probes are rate-limited TCP SYN attempts imposing negligible network load. All vantage systems carry clear identification and opt-out mechanisms. Results are reported only at aggregate AS and prefix granularity; no IP-level or user-identifying data are collected or retained.

## 4. Passive Scan Measurements: Censys Host Visibility

Figure[1]( "Figure 1 ‣ 4. Passive Scan Measurements: Censys Host Visibility ‣ A Multi-Perspective Study of the Internet Shutdown in Iran") shows daily Censys host counts for Iranian IPv4 addresses from January 1 to March 31, 2026 (87 observations), including all addresses in each snapshot regardless of pending-eviction state. Because Censys retains unresponsive hosts for up to 72 hours before removal(Durumeric et al., [2025]( "Censys: A map of Internet hosts and services")), these headline counts may overstate reachability during rapid enforcement events. To address this, we perform host-level pending analysis on key dates, distinguishing _active_ hosts (no pending flag) from headline counts.

Figure 1. Censys-visible Iranian IPv4 hosts. Red bands: shutdown windows; Event 2 begins March 1. Purple band: anomalous inter-event peak of 3.48M hosts (February 26). Gray dashed bands indicate 2025 baseline.

#### Baseline and severity.

Twelve monthly 2025 snapshots establish a stable baseline of {\sim}910 K–1.17M hosts; the pre-shutdown January 2026 count of {\sim}935 K falls within this range. Table[1]( "Table 1 ‣ Anomalous inter-event baseline. ‣ 4. Passive Scan Measurements: Censys Host Visibility ‣ A Multi-Perspective Study of the Internet Shutdown in Iran") summarizes the host-level decomposition at key dates for both events.

Event 1 onset occurred between the January 8 and 9 scans: on January 8, {\approx}1.02 M hosts were actively responding with normal pipeline churn (13% pending, compared to 14–17% pre-shutdown), while January 9–11 are absent from the Censys dataset; the 4% pending rate on January 12 confirms near-total enforcement had already completed, leaving no eviction-queue carry-over. Event 2 shows a contrasting, staged pattern: February 28 produces 231K newly-pending hosts, 4.2\times the four-day average of 55K/day, signalling partial TIC enforcement one day before the full shutdown. On March 1, 99.1% of the 3.4M Censys count is in the eviction queue; only 30,211 hosts are actively responding, establishing March 1 as the true forwarding-plane onset at -96.8% from the validated baseline ({\sim}935 K). The March 2 count of {\sim}402 K is 86.1% eviction-queue carry-over from March 1. Event 2 then deepens genuinely: active hosts decline from 90K (March 3) to 22K (March 15), a further -75\%. The pending queue accounts for only 3–18% of visible hosts throughout this period, ruling out eviction-lag as an explanation and confirming progressive null-route extension to a floor of -97.6\% by March 15.

#### Anomalous inter-event baseline.

Between the events (January 27–March 1), visible hosts peak at {\sim}3.48 M, representing a 3.7\times increase over the 2025 baseline, absent in our Turkey control and without historical precedent. We attribute this to two Censys pipeline effects: (i)the predictive re-injection engine re-queues evicted hosts from the past 60 days, flooding scan queues with Iranian IP-port pairs and surfacing services on non-standard ports previously hidden behind TIC’s DPI; and (ii)transient DPI reconfiguration at TIC during shutdown deployment and recovery, permitting probes to reach normally-filtered hosts. Applying Censys’s active-host filter across six inter-event dates removed only 1.6–4.7% of hosts, confirming the inflation reflects genuinely responding services rather than stale pipeline records. The partial recovery spikes (March 16–17, 19–20) are similarly amplified by re-injection: restored routing allows the pipeline to rediscover removed hosts within the same snapshot cycle, overstating recovery magnitude. We use the 2025-validated {\sim}910 K–1.17M range as the reference denominator; the residual late-March floor of {\sim}10–11K is verified as genuine infrastructure by active TCP probing (Section[7]( "7. Active TCP Reachability Census ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")).

Table 1. Censys total vs. active host counts at key dates. Active hosts exclude pending-eviction hosts. Reduction is relative to the 2025-validated {\sim}935 K baseline. †Mar 2 Censys count of 402K is 86% eviction-queue carry-over from Mar 1.

Date Phase Censys count Active hosts Reduction vs. 935K Event 1 (January) Jan 7 baseline 935K 798K— Jan 8 scan spike 1.18M 1.02M not begun Jan 12 floor 46K 44K-95.3% Event 2 (March) Feb 28 pre-onset 3.47M 3.16M— Mar 1 true onset 3.40M 30K-96.8% Mar 2 Censys onset 402K†56K-94.0% Mar 15 floor 23K 22K-97.6%

## 5. AS-Level Host Composition

Table[2]( "Table 2 ‣ Academic networks drive the anomalous inter-event inflation. ‣ 5. AS-Level Host Composition ‣ A Multi-Perspective Study of the Internet Shutdown in Iran") shows Censys-visible host counts by AS category across key dates for both events. AS categories were assigned using the ipverse AS metadata dataset(ipverse contributors, [2026]( "as-metadata: Autonomous System metadata dataset")), supplemented by keyword matching on AS names and descriptions for ASes with null or ambiguous categories, and manual override for a small number of operators.

#### Uniform collapse confirms centralized enforcement.

Both events produce near-simultaneous drops across all AS categories. In Event 1, state telecom falls -98.7% (101K to 1.3K, Jan 7 to Jan 16), commercial ISPs fall -95.5% (727K to 33K), and mobile infrastructure falls -94.4% (3.6K to 0.2K), a spread of 4.3 pp across three independently operated network categories. Event 2 is even more uniform: TCI alone (AS58224) falls from 1.34M to 2,368 hosts (-99.8%), MCCI (AS197207) from 10,130 to 2,237 (-77.9%), and every other category drops below -95% except mobile (-92.6%), which is dominated by MCCI. Observed synchrony across independent operators is consistent with enforcement at TIC’s single international gateway.

#### ArvanCloud is the only fully-exempt AS across both events.

ArvanCloud CDN (AS205585) retains {\approx}1{,}025 hosts throughout Event 2 (99.7% of its Mar 1 baseline) and {\approx}1{,}027 throughout Event 1 (99.6% of its Jan 7 baseline). No other AS in the dataset approaches this retention rate across either event. Every other major AS drops by at least 77%. ArvanCloud has been associated with the facilitation of Internet censorship in Iran,2 2 2[ releases/jy1518]( and its persistent visibility across both shutdowns, with values varying by fewer than 10 hosts over two months, is consistent with routing through non-Iranian upstreams or deliberate exemption from forwarding-plane enforcement.

#### MCCI counter-intuitively drops during partial recovery.

MCCI (AS197207) retains 2,237 hosts at the Event 2 floor (22.1% of Mar 1 baseline), the highest retention of any major operator. However, its count falls further to 601 during the Mar 16–17 partial recovery, while every other major category except mobile (which MCCI dominates) increases. This anti-correlation suggests that MCCI’s residual visibility at the floor corresponds to BGP peering infrastructure addresses that are deliberately kept reachable for routing protocol operation (consistent with the FIREWALL_ACL verdict for three MCCI prefixes in Section[7]( "7. Active TCP Reachability Census ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")), rather than end-user–accessible hosts.

#### March 16–17 partial recovery is 79% academic networks.

The +54 K host increase from Mar 15 to Mar 17 decomposes as: academic networks +43 K (79.5% of total), led by University of Tehran AS29068 (+14{,}520, from 2,077 to 16,597) and Sharif University AS12660 (+3{,}655). Academic networks’ share rises from 33.7% at the floor to 66.6% at the recovery peak, inverting the Jan 7 baseline where they represented only 1.4% of visible hosts. This is consistent with a targeted temporary exemption for Iranian universities. Critically, the recovery produces zero change in BGP prefix visibility (Section[6]( "6. BGP Routing During Shutdowns ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")), confirming pure forwarding-plane toggling.

#### Academic networks drive the anomalous inter-event inflation.

Academic ASes grow 16\times from Jan 7 to Mar 1 ({\approx}13{,}200 to {\approx}214{,}000 hosts) while total observed hosts grow only 3.6\times. The most extreme individual multipliers are IRANET-IPM AS6736 (127\times, 523 to 66,404 hosts) and University of Tehran AS29068 (388\times, 55 to 21,350 hosts), suggesting these networks are more heavily filtered by TIC under normal conditions and Event 1 disruption temporarily exposed them to Censys scanning (Section[4]( "4. Passive Scan Measurements: Censys Host Visibility ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")).

Table 2. Censys-visible Iranian hosts by AS category (% of daily total in parentheses; values in thousands). E2 floor=Mar 15; E2 rec.=Mar 17 partial recovery peak. Mar 1 total is inflated by the anomalous inter-event baseline (Section[4]( "4. Passive Scan Measurements: Censys Host Visibility ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")).

Category Event 1 Event 2 Jan 7 Jan 16 Mar 1 Mar 2 E2 floor E2 rec. State tel.101 (10.7)1.3 (3.1)278 (8.2)29 (7.2)0.8 (4.0)0.7 (0.9) Mobile 2.9 (0.3)<0.1 34 (1.0)10 (2.6)2.5 (11.9)0.6 (0.8) Mob. infra 3.6 (0.4)0.2 (0.4)8.4 (0.2)1.8 (0.5)0.0 (0.0)0.5 (0.7) Comm. ISP 727 (77.7)33 (81.8)2495 (73.8)295 (73.8)9.4 (45.0)21 (28.3) Academic 13 (1.4)0.6 (1.6)214 (6.3)20 (5.0)7.0 (33.7)50 (66.6) CDN 12 (1.3)1.3 (3.2)24 (0.7)4.8 (1.2)1.1 (5.4)2.0 (2.7) Other 77 (8.2)3.9 (9.7)326 (9.7)39 (9.8)0.0 (0.0)0.0 (0.0) Total 936 40 3380 400 21 75

## 6. BGP Routing During Shutdowns

Iran’s shutdown mechanism evolves across the three events. In 2019, TIC combines forwarding-plane null routing with partial BGP withdrawal: coverage drops from 85.1% (pre-shutdown) to 54.7% (floor), implying {\approx}440 prefixes withdrawn from the global routing table. In 2022 and 2026, this hybrid approach is replaced by pure forwarding-plane null routing: TIC discards packets while preserving BGP announcements, making Iran appear reachable to control-plane monitors.

### 6.1. BGP Routing Table Analysis

Table[3]( "Table 3 ‣ Baseline coverage of Iranian address space. ‣ 6.1. BGP Routing Table Analysis ‣ 6. BGP Routing During Shutdowns ‣ A Multi-Perspective Study of the Internet Shutdown in Iran") summarises BGP coverage of RIPE-allocated Iranian IPv4 prefixes across the three shutdown events.

#### Baseline coverage of Iranian address space.

Of 1,453–1,917 RIPE-allocated Iranian IPv4 prefixes per date, approximately 80–88% are visible in the global BGP table, either as exact matches or via sub-prefix disaggregation. The remaining 12–20% are domestically routed or held in reserve. This baseline is stable across all measurement dates: 87.6% on January 5, 2026, and 86.0% at Event 2 onset on March 3, 2026.

Table 3. BGP coverage of RIPE-allocated Iranian IPv4 prefixes across three shutdown events. Phase: _B_ baseline, _O_ onset, _D_ deep, _R_ recovery, _P_ partial recovery, _V_ recovery reversal, _G_ ongoing.

Date Ev.Ph.BGP ann.Cov.Cov.% Baselines 2026-01-05 E1 B 8,563 1,661 87.6 2026-03-01 E2 B 7,521 1,551 80.9 2019 fuel protests 2019-11-10 19 B 6,078 1,237 85.1 2019-11-17 19 O 6,090 1,241 85.3 2019-11-20 19 D 4,118 906 62.3† 2019-11-25 19 R 5,864 1,181 79.9 2022 Mahsa Amini protests 2022-09-14 22 B 7,816 1,451 88.5 2022-09-23 22 O 7,817 1,426 86.9 2022-09-25 22 D 7,809 1,425 86.8 2022-10-05 22 R 7,858 1,451 88.2 2026 Event 1 (January) 2026-01-10 E1 O 8,256 1,640 86.5 2026-01-12 E1 D 7,661 1,555 82.0 2026-01-20 E1 R 8,373 1,590 83.8 2026 Event 2 (March, ongoing) 2026-03-03 E2 O 8,537 1,647 86.0 2026-03-15 E2 D 8,349 1,633 85.2 2026-03-17 E2 P 8,415 1,626 84.8 2026-03-18 E2 V 8,468 1,630 85.0 2026-03-23 E2 G 8,494 1,632 85.1 2026-03-29 E2 G 8,489 1,637 85.4 †Coverage continues declining to 54.7% on 2019-11-21 before recovering; Nov 20 shown as the first confirmed withdrawal date.

#### Stability across 2022 and 2026 events.

For the 2022 Mahsa Amini protests and both 2026 events, the globally announced Iranian prefix set remains effectively constant through every shutdown phase. Within-event variation is 1.7 pp (2022), 4.5 pp (Event 1), and 1.2 pp (Event 2), all consistent with normal BGP churn. Critically, the March 16–17 partial recovery (Section[5]( "5. AS-Level Host Composition ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")), in which Censys-visible hosts increase by +54 K, coincides with a -0.4 pp _decrease_ in BGP coverage (85.2% to 84.8%, -7 prefixes). The two signals move in opposite directions, ruling out control-plane modification and confirming forwarding-plane toggling as the recovery mechanism.

#### BGP withdrawal before null-routing in 2019.

In 2019, coverage holds at 85.1–85.3% through the onset (Nov 10–17), then drops to 62.3% by Nov 20 and 54.7% by Nov 21, as 440 prefixes (\approx 36% of the covered set) are progressively withdrawn from BGP during the deep shutdown. Cross-checks with rrc03 and rrc04 (using the same ASN set) show \leq 1.7 pp deviation, indicating the BGP drop is not specific to rrc00. Partial recovery to 79.9% by Nov 25 confirms these withdrawals were shutdown-induced. This is distinct from the 2022 and 2026 events, indicating that Iran transitioned from a hybrid BGP-withdrawal mechanism in 2019 to pure forwarding-plane null-routing by 2022, consistent with progressive consolidation of shutdown enforcement at TIC’s international gateway.

## 7. Active TCP Reachability Census

We conducted the active TCP reachability census described in Section[3.2]( "3.2. Active TCP Reachability Probing ‣ 3. Methodology ‣ A Multi-Perspective Study of the Internet Shutdown in Iran") over April 7–25, 2026, during Event 2.

We distinguish five verdict categories. null_route: all three ports time out. Packets are silently discarded despite a valid BGP route, the definitive forwarding-plane black-hole signature. bgp_withdraw: at least one port returns ICMP unreachable, consistent with data-plane route withdrawal. firewall_acl: ports 80/443 time out while port 179 returns TCP RST, indicating selective application-layer filtering with routing infrastructure intact. reachable: at least one application port responds. ambiguous: captures prefixes where no single verdict reaches the majority threshold across runs; this category contains a single prefix in our census.

null_route dominates at 96.5–97.4% of prefixes across five vantage points, with a cross-vantage spread of 0.9 pp and a per-vantage run-to-run spread of 1.0–2.0 pp over 18 days of continuous probing. This confirms a highly uniform, globally visible, and temporally stable enforcement mechanism consistent with BGP stability (Section[6]( "6. BGP Routing During Shutdowns ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")). Category-level analysis reveals two structural exceptions. Mobile operator prefixes exhibit the highest non-null rate ({\approx}10.7\% across vantage points), reflecting reachable BGP peering and signalling infrastructure. Academic prefixes show a disproportionate bgp_withdraw rate of 13.3%, indicating selective route withdrawal rather than forwarding-plane enforcement, corresponding to the same academic networks that dominate the March 16–17 passive scan recovery (Section[5]( "5. AS-Level Host Composition ‣ A Multi-Perspective Study of the Internet Shutdown in Iran")). CDN/cloud, mobile infrastructure, state telecom, and commercial ISP prefixes exhibit near-total null routing with no cross-vantage variation.

Table 4. Per-prefix TCP reachability verdict distribution, active probing of 4,571 Iranian IPv4 prefixes over April 7–25, 2026 (169 total runs across five vantages). NR:null_route; RE:reachable; BW:bgp_withdraw; FA:firewall_acl; AM:ambiguous.

Vantage Runs NR RE BW FA AM Amsterdam 34 96.6%(4,416)2.0%(92)1.2%(57)0.1%(6)0.0%(0) Frankfurt 34 97.4%(4,453)2.1%(95)0.4%(17)0.1%(6)0.0%(0) Istanbul 33 97.2%(4,444)2.1%(97)0.5%(24)0.1%(6)0.0%(0) New York 34 96.5%(4,410)2.1%(97)1.2%(57)0.1%(6)0.0%(1) Singapore 34 97.4%(4,451)2.1%(94)0.4%(20)0.1%(6)0.0%(0)

## 8. Conclusions

We presented a three-plane characterization of two Iranian Internet shutdowns in January and March 2026, combining BGP analysis, active TCP reachability probing, and Censys scans. We find a shift toward pure forwarding plane null routing at centralized international gateways. This leaves BGP-only monitors blind to outages. Passive scans show that Censys misrepresents shutdown dynamics in two ways: a 72-hour eviction window that masks forwarding plane onset, and an inter-event host surge that reflects a pipeline artifact, not recovery, driven by re-injection and transient DPI changes at TIC. More broadly, each measurement technique has inherent limitations and can mislead in isolation; only a careful multi-measurement approach enables accurate identification of shutdown onset and severity.

## References

* G. Aceto, V. Persico, and A. Pescapè (2026)Iran’s January 2026 Internet shutdown: Public data, censorship methods, and circumvention techniques. arXiv preprint arXiv:2603.28753. External Links: [Link]( by: [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * C. Anderson (2013)Dimming the Internet: Detecting throttling as a mechanism of censorship in Iran. arXiv preprint arXiv:1306.4361. Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§2.1]( "2.1. Iranian Internet Architecture ‣ 2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * S. Aryan, H. Aryan, and J. A. Halderman (2013)Internet censorship in Iran: A first look. In USENIX Workshop on Free and Open Communications on the Internet (FOCI), Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§2.1]( "2.1. Iranian Internet Architecture ‣ 2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * A. Dainotti, C. Squarcella, E. Aben, K. C. Claffy, M. Chiesa, M. Russo, and A. Pescapé (2011)Analysis of country-wide Internet outages caused by censorship. In ACM Special Interest Group on Data Communication (SIGCOMM) Conference, Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * Z. Durumeric, D. Adrian, P. Stephens, E. Wustrow, and J. A. Halderman (2024)Ten years of Zmap. In ACM Internet Measurement Conference (IMC), Cited by: [§3.2]( "Vantage Points. ‣ 3.2. Active TCP Reachability Probing ‣ 3. Methodology ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§3.4]( "3.4. Ethical Considerations ‣ 3. Methodology ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * Z. Durumeric, H. Clark, J. Cody, E. Cubit, M. Ellison, L. Izhikevich, and A. Mirian (2025)Censys: A map of Internet hosts and services. In ACM Special Interest Group on Data Communication (SIGCOMM) Conference, Cited by: [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§3.1]( "3.1. Passive Measurement (Censys) ‣ 3. Methodology ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§4]( "4. Passive Scan Measurements: Censys Host Visibility ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * K. Elmenhorst, B. Schütz, N. Aschenbruck, and S. Basso (2021)Web censorship measurements of HTTP/3 over QUIC. In ACM Internet Measurement Conference (IMC), Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * A. Filasto and J. Appelbaum (2012)OONI: Open Observatory of Network Interference. In USENIX Workshop on Free and Open Communications on the Internet (FOCI), Cited by: [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * [9]Internet Outage Detection and Analysis (IODA). Note: [ March 2026 External Links: [Document]( by: [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * ipverse contributors (2026)as-metadata: Autonomous System metadata dataset. Note: [ April 2026 Cited by: [§5]( "5. AS-Level Host Composition ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * D. Madory (2026)From stealth blackout to whitelisting: inside the iranian shutdown. Note: [ on 2026-01-22 Cited by: [§2.1]( "2.1. Iranian Internet Architecture ‣ 2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"), [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * Mehr News Agency (2016)Iran launches national information network. Note: Original publication date: 28 August 2016; Archived on 18 March 2025 External Links: [Link]( by: [§2.1]( "2.1. Iranian Internet Architecture ‣ 2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * P. Pearce, R. Ensafi, F. Li, N. Feamster, and V. Paxson (2017a)Augur: Internet-wide detection of connectivity disruptions. In IEEE Symposium on Security and Privacy (S&P), Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * P. Pearce, B. Jones, F. Li, R. Ensafi, N. Feamster, N. Weaver, and V. Paxson (2017b)Global measurement of DNS manipulation. In USENIX Security Symposium, Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * R. Ramesh, R. S. Raman, A. Virkud, A. Dirksen, A. Huremagic, D. Fifield, D. Rodenburg, R. Hynes, D. Madory, and R. Ensafi (2023)Network responses to Russia’s invasion of Ukraine in 2022: A cautionary tale for internet freedom. In USENIX Security Symposium, Cited by: [§2]( "2. Background and Related Work ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * RIPE NCC (2024)RIPE Routing Information Service (RIS): Route Collectors. Note: [ 2024 Cited by: [§3.3]( "3.3. BGP Routing Table Analysis ‣ 3. Methodology ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * J. Tai, K. N. Sengottuvelavan, P. Whiting, and N. P. Hoang (2025)IRBlock a large-scale measurement study of the great firewall of Iran. In USENIX Security Symposium, Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran"). * J. Verkamp and M. Gupta (2012)Inferring mechanics of web censorship around the world. In USENIX Workshop on Free and Open Communications on the Internet (FOCI), Cited by: [§1]( "1. Introduction ‣ A Multi-Perspective Study of the Internet Shutdown in Iran").

Share this fact check

← Check another article or image