Skip to content

Internet Blocking

An Internet intervention that prevents a selected user, endpoint, route, protocol, domain, or content object from reaching or acting on a network resource within a declared scope and duration.

Version
v2 · 2026-09-06 · History
Domain-specific #
2091
Origin domain
computer networking
Subdomain
Internet blocking and censorship
Aliases
Content blocking, Network blocking

Core Idea

Internet Blocking is an Internet intervention that prevents a selected user, endpoint, route, protocol, domain, or content object from reaching or acting on a network resource within a declared scope and duration. [1]

A blocking system resolves a target selector at an enforcement point and prevents a specified Internet capability: name resolution, packet delivery, connection establishment, content retrieval, account interaction, or platform visibility. The same target can be blocked at DNS, IP, transport, URL, application, account, or device layers, and each choice has different precision, observability, collateral effects, and circumvention paths.

The operative boundary is exact: The selector-to-enforcement mapping for denying Internet reachability or interaction remains uncovered. The abstraction is therefore not the topic named by its field, but the reusable role structure specified below.

Structural Signature

Sig role-phrases:

  • the target selector — domain, IP address, protocol fingerprint, URL, content signature, account, user, or device
  • the enforcement point — resolver, router, ISP middlebox, server, platform, client, or administrator
  • the denied capability — resolution, connection, retrieval, publication, messaging, viewing, or interaction
  • the scope — users, networks, jurisdictions, services, and time interval to which the rule applies
  • the matching and decision rule — the lookup or classifier connecting observed traffic or identity to a deny action
  • the failure presentation — timeout, reset, synthetic answer, error page, silent omission, or account notice
  • the collateral surface — legitimate resources sharing an identifier or dependency with the target
  • the circumvention path — alternative resolver, address, mirror, tunnel, protocol, or account route

Recognition test. A case qualifies only when its roles can be mapped to the declared the target selector, the enforcement point, the denied capability, the scope, and when the characteristic boundary conditions are preserved. Surface vocabulary or a loose analogy is insufficient.

What It Is Not

  • Not content removal. Blocking can deny a route while the content remains online elsewhere.
  • Not ordinary authentication failure. A block is an intentional deny intervention, not every inability to log in.
  • Not mere slowdown. Throttling is graded access friction unless the practical result is complete denial under a declared threshold.
  • Not one technical method. DNS, IP, URL, protocol, application, and account blocking have different semantics.
  • Not perfect target precision. Shared hosting, CDNs, encryption, and reused identifiers create over- and under-blocking.
  • Not a judgment that blocking is always legitimate or illegitimate. The abstraction describes the intervention; law and policy evaluate particular uses.

Scope of Application

The abstraction has a bounded but recurring habitat. These are literal applications of the same domain machinery, not cross-domain metaphors. [2]

  • Network censorship. states or access providers deny reachability to selected services or content.
  • Platform moderation. accounts or objects lose visibility or interaction capabilities under platform rules.
  • Security controls. malicious domains, command channels, and compromised endpoints are denied at resolvers, gateways, or clients.
  • Parental and institutional filtering. local policy constrains categories of destinations or applications.
  • Copyright and gambling enforcement. court or regulator orders are translated into ISP or resolver deny rules.
  • Abuse prevention. users block accounts from contacting, viewing, or following them within a platform.

Clarity

A complete blocking record names who cannot do what to which resource, where the deny rule is enforced, how the target is matched, and for how long. 'Website X is blocked' is incomplete when DNS returns a synthetic address for some resolvers but direct IP connections or mirrors remain reachable.

A useful audit proceeds in order: identify the candidate roles, verify their types and quantifiers, apply the recognition test, and then test every stated exclusion. If a case supplies only the broad parent pattern while dropping the domain accent, it is not Internet Blocking.

Manages Complexity

The abstraction separates policy intent from technical realization. It makes precision, collateral damage, transparency, and bypass properties comparable across layers, while preserving the distinction between removing a source and interfering with one access path.

The compression remains accountable because every simplification has a named validity condition. A user can ask which role is missing, which assumption fails, and which neighboring abstraction should replace the candidate instead of treating the label as an unanalyzed bundle.

Abstract Reasoning

R1. Name the denied capability rather than saying only 'access'.

R2. Resolve selector granularity and shared dependencies before predicting collateral effects.

R3. Locate the enforcement point and the observer who can verify the block.

R4. Test both over-blocking and under-blocking.

R5. Distinguish bypass of the rule from removal of the underlying restriction or content.

The reasoning pattern is deliberately typed: definitions establish identity, calculations or constructions establish consequences, and empirical or institutional evidence establishes whether a real case instantiates the roles. One kind of support cannot silently substitute for another.

Knowledge Transfer

Within Internet infrastructure and online platforms, the selector–enforcement–capability model transfers literally. Generic Access Control is the parent that travels to buildings, files, and organizations; Internet Blocking remains domain-specific because DNS, routing, protocols, platforms, encryption, and circumvention determine its operation.

The transfer boundary follows from the classification test: The denial relation recurs across platforms, networks, and censorship systems, while selector layer, enforcement point, affected capability, jurisdiction, observability, and circumvention remain Internet-specific semantics. The safe portable move is to name the broader parent when the home-domain machinery is absent and to retain the domain name only when literal recognition succeeds.

Examples

Canonical: DNS blocking

A resolver receives a query for a listed domain and returns an error or synthetic response rather than the authoritative answer. Users of that resolver lose ordinary name-based access, while the server and its content remain online. Changing resolvers or using a direct address may bypass the rule, and a whole domain can be affected when only one path was targeted. [1]

Mapped back: the target selector; the enforcement point; the denied capability; the failure presentation; the circumvention path.

Applied / In Practice: IP-address blocking

An ISP drops traffic to an address associated with a prohibited service. If several domains share that address, unrelated services can fail too; if the target changes addresses or uses a CDN, the rule may miss it or expand its collateral surface. Measurement from inside and outside the affected network distinguishes a local routing intervention from a global outage. [2]

Mapped back: the matching and decision rule; the scope; the collateral surface; the enforcement point; the denied capability.

Structural Tensions

T1: Precision versus deployability. Coarse DNS and IP selectors are easy to enforce but often cover more resources than intended. Diagnostic: What is the smallest stable identifier available at the enforcement point?

T2: Transparency versus resistance to evasion. Clear notices aid accountability, while silent failures can make circumvention and diagnosis harder. Diagnostic: Can affected users distinguish policy denial from outage?

T3: Effectiveness versus collateral damage. Broader rules catch more target routes but disrupt shared infrastructure and lawful content. Diagnostic: Which dependencies share the blocked identifier?

T4: Central enforcement versus architectural resilience. A centralized choke point makes policy enforceable but creates surveillance, failure, and fragmentation risks. Diagnostic: What new control surface does the blocking mechanism create?

T5: Immediate denial versus durable resolution. Blocking can reduce visibility without removing the source or addressing the behavior that motivated the rule. Diagnostic: Is success defined as temporary inaccessibility or elimination of the harmful source?

T6: Domain autonomy vs prime reduction. Access Control describes generic deny decisions, but it does not entail Internet-layer selectors, routing side effects, encryption, or bypass paths. Diagnostic: Can the case be diagnosed without naming the Internet layer? If not, retain the domain node.

Structural–Framed Character

The five-criterion aggregate is 0.65 (mixed-framed). The classification is reasoned rather than cosmetic:

  • Vocabulary travels — mixed (0.50). The operative vocabulary retains the home-domain types named in the Structural Signature even when a thinner parent pattern travels.
  • Evaluative weight — framed (0.75). The score records whether applying the abstraction requires a normative or interpretive judgment in addition to structural recognition.
  • Institutional origin — framed (1.00). The score records whether the abstraction is constituted by a scholarly, legal, technical, or administrative convention rather than merely discovered in nature.
  • Human-practice bound — framed (1.00). The score records how far the named roles depend on a human practice, measurement regime, language, or institution.
  • Import versus recognize — framed (0.75). Beyond its home habitat, use of the name increasingly becomes import by analogy rather than recognition of the same mechanism.

The portable skeleton is: a policy or safety decision maps an observed selector to denial of a capability at an enforcement point. That skeleton belongs to the related parent abstractions; it does not make the fully accented node a prime. Its character: mixed-framed, with a real structural core whose recognition remains bounded by domain-specific types and validity conditions.

Structural Core vs. Domain Accent

This section decides why Internet Blocking is a domain-specific abstraction rather than a prime.

Structural core: A policy or safety decision maps an observed selector to denial of a capability at an enforcement point. This relational skeleton can recur outside the home domain and is the part legitimately carried by broader primes.

Domain accent: Dns, ip routing, transport, urls, encrypted protocols, online accounts, shared hosting, jurisdiction, and circumvention. Remove those types and constraints and the result may still resemble the skeleton, but it is no longer recognized as this named abstraction.

Why it does not clear the prime bar: Generic denial travels under Access Control. Internet Blocking is recognized by where identifiers and enforcement sit in the network stack and platform architecture. Cross-domain transfer is therefore routed through the parents, while the named entry remains available for precise in-domain diagnosis.

  • Access Control. is the strict generic parent for allow/deny decisions.
  • Access Friction. covers degraded or costly access, of which complete blocking is a limiting case.
  • Proxy Pattern. can implement filtering but is an architecture, not the deny relation.

These are prose relations only. They do not create structured DAG edges, and placement must still pass the live endpoint, redundancy, and cycle checks recorded in the bundle's placement memo.

Relationships to Other Abstractions

Local relationship map for Internet BlockingParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Internet BlockingDOMAINPrime abstraction: Access Control — is a kind ofAccess ControlPRIME

Current abstraction Internet Blocking Domain-specific

Parents (1) — more general patterns this builds on

  • Internet Blocking is a kind of Access Control Prime

    Access Control. is the strict generic parent for allow/deny decisions.

Hierarchy paths (3) — routes to 3 parentless roots

Neighborhood in Abstraction Space

Internet Blocking sits in a sparse region of the domain-specific corpus (69th percentile for distinctiveness): few abstractions share its structure, so a faithful description tends to retrieve it precisely.

Family — Unclustered & Miscellaneous (1565 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-09-08

Not to Be Confused With

  • Content removal. deletion or takedown at the hosting source. Tell: Does the content still exist and remain reachable by another route?
  • Filtering. a broader selection process that may label, rank, or permit as well as deny. Tell: Is the output categorical denial?
  • Throttling. reduction in bandwidth or responsiveness. Tell: Is access impossible or merely degraded?
  • Internet shutdown. wide-area loss of connectivity rather than selective denial. Tell: Is the selector a resource or the network itself?
  • Account suspension. platform-level loss of account privileges. Tell: Which capabilities and audiences are denied, and is this one subtype of the broader block?

References

[1] J. L. Hall, M. D. Aaron, A. Andersdotter, B. Jones, N. Feamster, and M. Knodel, RFC 9505: A Survey of Worldwide Censorship Techniques, RFC Editor, November 2023. registry ↩a ↩b

[2] Internet Society, Perspectives on Internet Content Blocking: An Overview, 2017. registry ↩a ↩b