A new disclosure about an unusual traffic surge
Newly published research has provided a striking example of how DNS can be used to carry traffic when conventional connections are restricted. On October 9, 2026, DomainTools disclosed that it had observed an exceptional volume of DNS records beginning on March 1, during the 2026 conflict involving Iran. The company said it had shared information privately with disclosure partners since March before discussing the activity publicly.
The records were initially associated with supaghost[.]cc. According to DomainTools, observations involving that domain peaked at as many as 500,000 per second, temporarily adding about 50% to its normal intake. It recorded roughly 40 billion observations over several days before filtering the traffic from its processing system. Those figures come from DomainTools’ own infrastructure and have not been publicly replicated by an independent organization.
Researchers found large DNS TXT responses and unusually constructed subdomains. They assessed the pattern as highly consistent with bidirectional VPN-over-DNS traffic. Activity eventually extended across more than 100 domains, with .ir domains disproportionately represented. Technical indicators pointed toward an origin in or near Iran, but they did not establish who operated the system.
DomainTools Investigations | It Always Comes Back to DNS: Iranian VPN-over-DNS Activity in the 2026 Conflict
What VPN over DNS actually means
The Domain Name System normally translates human-readable names into information that computers can use to locate services. A DNS tunnel uses that channel for a different purpose: it encodes another protocol or data stream inside DNS questions and answers.
FIRST, an international incident-response forum, describes DNS tunneling as the encapsulation of another protocol within DNS. Depending on its design, a tunnel can move data between a device and a server that decodes it, then forwards the resulting traffic. Because some restricted networks still permit DNS requests, this approach may provide a narrow route through a firewall that blocks more recognizable VPN protocols.
That versatility is also why network observations alone can be difficult to interpret. DNS tunneling can support legitimate censorship circumvention, but similar techniques are used for command-and-control traffic and covert data transfer. A recognizable tunnel pattern does not, by itself, reveal the operator’s identity or intent.
VPN over DNS is also different from DNS over HTTPS or DNS over TLS. Those technologies encrypt DNS lookups between a device and a resolver. DNS tunneling instead uses DNS to transport other data. Encrypted DNS may conceal some tunnel indicators from intermediate observers, but it does not make the two concepts interchangeable.
DNS Abuse Detection: DNS Tunneling - Tunneling Another Protocol Over DNS
Connectivity and confidentiality are different tests
The most important lesson for VPN users is simple: a tool that successfully creates a connection has not necessarily created a private connection. DNS tunneling describes a transport method. It does not prove that the data inside the tunnel is strongly encrypted, authenticated or protected from the tunnel operator.
The official documentation for iodine, an open-source DNS tunneling project, illustrates the distinction. Iodine can route IP traffic through DNS where ordinary internet access is firewalled, but its underlying tunnel is not encrypted by default. Its maintainers recommend placing a VPN or SSH connection inside the tunnel when confidentiality is required. That limitation applies specifically to iodine; it should not be assumed to apply to every DNS-based tool. It nevertheless demonstrates why a label such as “DNS VPN” is not evidence of complete security.
Endpoint trust matters as well. Even when traffic is encrypted between a device and a tunnel server, the operator may control where it exits, what metadata is recorded and how accounts are managed. Users therefore need information about both the encryption design and the organization running the infrastructure.
GitHub - yarrick/iodine: Official git repo for iodine dns tunnel · GitHub
Why this matters under internet restrictions
DNS-based transport becomes especially relevant when authorities interfere with VPN websites, app downloads or recognizable protocols. A censorship monitor’s tests on October 9 found that websites associated with several VPN and circumvention services were inaccessible on the fixed Iranian networks it examined, including sites connected with Proton VPN, Psiphon, Mullvad, NordVPN and Tor.
Those results require careful interpretation. The monitor tested website availability on selected fixed connections. Its findings do not prove that every named service, application or protocol was unusable across all residential and mobile networks in Iran. They do show one practical problem: people may be unable to reach official download and support pages precisely when they most need a circumvention tool.
This environment can make unofficial APK files, configuration bundles and tools promoted through social media appear attractive. It also creates opportunities for impersonation, malware and services whose operators make vague privacy claims. There is no evidence in the reviewed research that customers of any named commercial VPN were compromised by the DomainTools activity.
What’s Blocked in Iran? Live List of Blocked Sites & Apps · DomainTools Investigations | It Always Comes Back to DNS: Iranian VPN-over-DNS Activity in the 2026 Conflict
Six checks before trusting an unfamiliar tool
People facing network restrictions may have limited options, and personal or legal risks vary by location. Without giving instructions for operating a tunnel, the following checks can reduce avoidable privacy risks:
- Verify the download source. Prefer a developer’s authenticated app-store listing, verified website or signed software repository. Treat files sent through private messages and newly created mirror sites as untrusted.
- Look for separate encryption. Do not assume that “tunnel,” “VPN” or “DNS” means the payload is confidential. Documentation should identify how traffic is encrypted and how the server is authenticated.
- Keep application protections enabled. Continue using HTTPS and end-to-end encrypted messaging. A transport tunnel should not replace encryption provided by the website or communication app.
- Check the project’s identity and record. Useful signals include public source code, security documentation, known limitations, update history and a clear operator. None is a guarantee, but their absence makes informed evaluation harder.
- Delay sensitive logins. Avoid entering important credentials until the software, server identity and download source have been checked. Use multi-factor authentication where it can be enabled safely.
- Prepare before restrictions begin. Keeping a previously verified and updated tool installed can be safer than searching for unfamiliar software during a block. Users should also understand applicable laws and consider their personal threat model.
GitHub - yarrick/iodine: Official git repo for iodine dns tunnel · GitHub · DNS Abuse Detection: DNS Tunneling - Tunneling Another Protocol Over DNS · What’s Blocked in Iran? Live List of Blocked Sites & Apps
What the research does—and does not—establish
DomainTools did not decrypt the observed traffic, and the operator, contents and final purpose remain unknown. The company discussed the possibility of a coordinated emergency transfer or backup operation and potential regime connections, but explicitly treated those ideas as speculation. The evidence does not justify calling the activity a government operation, military transfer, cyberattack or consumer VPN breach.
The disclosure is still valuable because it separates two ideas that are often blurred together. A circumvention technique may be effective at moving data through a restricted network while offering weak confidentiality, unclear authentication or an untrustworthy exit point. Conversely, an encrypted application can protect message content even when the surrounding connection remains observable.
For users, the practical conclusion is to evaluate unfamiliar tools with two questions: Can it connect? and what protects me after it connects? DNS tunneling may answer the first question under difficult network conditions. Only verifiable encryption, authenticated software and trustworthy operation can begin to answer the second.
DomainTools Investigations | It Always Comes Back to DNS: Iranian VPN-over-DNS Activity in the 2026 Conflict · GitHub - yarrick/iodine: Official git repo for iodine dns tunnel · GitHub · DNS Abuse Detection: DNS Tunneling - Tunneling Another Protocol Over DNS