How is internet filtering and censorship actually implemented?
Through several techniques operating at different layers, each with different costs, different accuracy and different ease of circumvention — and most real systems combine them.
The techniques, in rough order of sophistication:
DNS filtering. The resolver returns a false answer or none for blocked domains. Cheap, fast and trivially circumvented by changing resolver or using encrypted DNS — which is exactly why encrypted DNS is contentious with filtering operators.
IP blocking. Dropping traffic to specific addresses. Blunt, and causes overblocking when many sites share an address behind a CDN — a single block can take down thousands of unrelated sites, which has happened repeatedly.
URL filtering, requiring inspection of the request. Encryption largely ended this for HTTPS traffic, since the path is no longer visible.
Deep packet inspection. Examining traffic characteristics to identify protocols and applications even when encrypted — using packet sizes, timing and handshake patterns rather than content. This is how VPN and circumvention protocols are detected.
SNI filtering. The server name in a TLS handshake was historically sent in the clear, so it could be read and blocked despite encryption. Encrypted Client Hello closes this, which is why its rollout is resisted in some jurisdictions.
Throttling to unusability, rather than blocking outright.
Search and platform-level removal, which is filtering by intermediary rather than by network.
Legal and platform compliance, where content is removed at source.
Who operates filtering, and this is worth separating. State-level censorship is one case. Filtering also exists at ISP level for legally mandated categories, in workplaces and schools, on parental control systems, and by hosting providers. The techniques are identical; the governance is not.
The recurring problems:
Overblocking, which is routine and rarely corrected.
Opacity. Users frequently see a timeout rather than an explanation, so blocking is indistinguishable from failure.
Scope creep, where systems built for one category are extended to others.
No appeal route in many implementations.
Circumvention is always possible for determined users, so filtering affects the casual majority.