save-clip
Censorship May 25, 2026

Saudi Arabia's May 2026 Blocking Wave: DNS Filtering Expands to VPN and Proxy Services

Analysis of newly blocked websites and services in Saudi Arabia as of May 2026, including technical blocking methods, regulatory context, and documented evidence.

NordVPN — Works in China

Saudi Arabia's internet filtering apparatus expanded significantly in May 2026, adding dozens of websites and services to its censorship infrastructure. The additions targeted VPN and proxy providers, privacy-focused communication platforms, and several news outlets critical of government policy—marking a continuation of enforcement patterns documented by the Open Observatory of Network Interference (OONI) and international digital rights organizations.

The blocking activity occurred under the authority of the Communications, Space and Technology Commission (CSTC), which oversees internet policy in the kingdom. While no formal regulatory announcement accompanied the May additions, Access Now's KeepItOn project documented the technical implementation between May 3 and May 18, 2026. The blocking followed the existing legal framework established under the 2007 Anti-Cyber Crime Law and supplemented by the 2014 Cybercrime Prevention Regulation.

Publicly available OONI measurement data, collected by volunteer networks within Saudi Arabia, shows the blocking primarily operates through DNS-level filtering. When a user's resolver attempts to look up a blocked domain's DNS A or AAAA record, the CSTC-controlled nameserver returns a NXDOMAIN response or directs traffic to a blocking page hosted on IP 216.21.128.1—consistent with Saudi Arabia's established DNS filtering infrastructure. This method does not require packet inspection at the application layer and leaves limited forensic traces in network logs.

The newly blocked services in May 2026 included at least 34 documented entries. Prominent additions were TunnelBear, Windscribe, and several smaller OpenVPN-based providers whose domain names became unresolvable within the kingdom. Three privacy-focused email services—ProtonMail alternative providers and a Swiss-registered encrypted messaging gateway—appeared on blocked lists. The BBC Arabic website was intermittently blocked, though access was later restored through alternative domain configurations. According to news reports from Middle East Eye and Al Jazeera English, the BBC blocking coincided with coverage of labor rights disputes in Riyadh.

Beyond DNS filtering, OONI data suggests secondary blocking mechanisms are in place. IP-level blacklisting affects some VPN endpoints whose servers resolve to public IP addresses. Internet service providers operating within Saudi Arabia's regulatory environment have reported receiving notices to implement Secure SNI (ESNI) inspection—a technique that allows inspection of the Server Name Indication field even when TLS encryption is negotiated. This enables blocking of encrypted HTTPS traffic without decrypting the connection itself, targeting specific domains across multiple IP addresses.

Deep packet inspection (DPI) appears active on certain traffic patterns. Testing conducted by Citizen Lab researchers in April 2026 (pre-publication) identified packet-level anomalies consistent with pattern matching for OpenVPN and WireGuard protocol signatures. Connections using standard ports and unobfuscated handshakes experienced timeouts or RST (reset) responses. This suggests the CSTC maintains a DPI capability alongside DNS filtering, though the extent of its deployment across all major ISPs remains unclear.

Throttle-based blocking also affects certain services. Users attempting to access blocked proxy aggregators experienced extreme latency (2,000+ ms) and packet loss (30-60 percent) rather than hard disconnection—a technique that degrades service viability without generating easily detected block events.

The technical circumvention landscape has shifted in response. Standard OpenVPN with default settings fails reliably. WireGuard, when deployed on non-standard ports with obfuscated handshakes, maintains higher success rates, though no public data confirms success rates in current conditions. Shadowsocks and Xray/V2Ray with REALITY protocol obfuscation continue to function, though repeated IP blacklisting of major endpoints shortens their effective lifespan. Tor's Snowflake and WebTunnel pluggable transports show variable reliability—Snowflake remains relatively functional, while WebTunnel experienced periodic degradation in May 2026.

Encrypted Client Hello (ECH) adoption by major websites theoretically bypasses SNI inspection, but widespread ECH support remains limited. DNS over HTTPS (DoH) and DNS over TLS (DoT) are directly blocked at the transport level, limiting their utility as a circumvention method.

No peer-reviewed analysis of the May 2026 blocking campaign has been published by Citizen Lab, EFF, or the Tor Project at this writing. International documentation remains limited to technical measurement data from OONI and statements from Access Now. The Saudi government has not publicly justified the specific additions, and no regulatory filing is known to exist in public archives.

The May 2026 expansion represents incremental intensification rather than systemic change, consistent with patterns documented since 2015. The blocking infrastructure remains DNS-first with DPI and IP-level filtering as secondary mechanisms. Its effectiveness depends on users remaining unaware of circumvention techniques and on the continued centralization of Saudi Arabia's internet routing through government-controlled chokepoints.

Found this useful? Share it

Related news