Website access explained

How website blocking works

A blocked website can fail before your browser finds its address, while connecting, or after the website receives your request. The point of failure determines whether changing DNS, using a VPN, or contacting the site owner can help.

If you need a next step now, use the DoVPN website unblocking assistant. This guide explains the mechanisms behind its suggestions.

Follow one request

Imagine opening https://docs.example/lesson, a fictional address. First, the browser needs an IP address for docs.example. It then reaches the server, establishes encryption, and requests /lesson. The name, address and page path are different pieces of information.

Four places a website request can fail
  1. Find the address

    DNS looks up the website hostname.

    A DNS filter can withhold or replace the answer.

  2. Reach the server

    Your device connects to the destination IP.

    An IP rule can drop the connection even with a correct DNS answer.

  3. Set up encryption

    TLS establishes the secure session.

    The server name may be visible unless ECH protects it.

  4. Request the page

    The browser sends the request inside HTTPS.

    The website itself can still reject your IP, session or account.

Simplified sequence for a fresh HTTPS connection without a VPN. Cached DNS answers and reused connections can skip steps. This illustration explains the process; it does not test your connection.

A filter needs both a signal and an action. The signal might be a DNS hostname or destination IP. The action might be a false answer, a dropped packet or a closed connection. Different filters can therefore produce the same browser error. OONI's blocking overview makes this useful distinction.

DNS filtering: changing the lookup answer

A DNS resolver answers hostname lookups. A filtering resolver checks a rule before replying: it can refuse the lookup, return an unusable address, or send the browser toward a block page. Filters may target malware, phishing, specific domains or categories such as gambling. Their purpose depends on the operator's policy.

In our example, a DNS rule sees docs.example, not the /lesson page path. It cannot allow one path and block another using the DNS query alone. Cloudflare's DNS filtering explanation documents this boundary.

What this means for you: changing to a different reachable resolver may help if DNS is the only restriction and the change is permitted. It will not solve a separate IP block. Typing a server IP into the browser is also unreliable: shared hosting and TLS name checks depend on the hostname, as the SNI specification explains.

DNS filtering is separate from a DNS leak. If your concern is where VPN lookups travel, see our DNS leak guide.

IP blocking: refusing the destination

A network can reject traffic to an IP address even when DNS returns the correct answer. It may silently drop packets or close a connection. The browser can show a timeout or reset without displaying a policy notice. These are among the mechanisms in OONI's overview.

Practical example: if the hostname resolves but the connection fails only on one network, an IP rule is one possible explanation. It is not a diagnosis. A routing fault or unavailable server can look similar; changing DNS repeatedly will not distinguish them.

HTTPS, SNI and ECH: encryption has layers

HTTPS protects the page request and response in transit. Setting up that protection can still reveal a server name through Server Name Indication, or SNI. SNI lets a server hosting multiple websites choose the appropriate service for the hostname. A network filter can use an exposed name without reading the encrypted page.

Encrypted Client Hello, or ECH, protects the real server name inside an encrypted part of the handshake. An outer name remains visible. Support depends on the browser, server and configuration, so it is inaccurate to say that TLS always exposes the destination hostname. Cloudflare's ECH documentation explains the inner and outer handshake.

The limit: ECH does not hide the destination IP address or stop every network policy. A connection can still be blocked by address. Conversely, a padlock does not prove that the network cannot infer which service you use.

Plain HTTP lacks this protection for the page request: a network intermediary can inspect or interfere with it. A managed device may also have trusted inspection software that changes the HTTPS trust arrangement. Do not dismiss certificate warnings as a normal unblocking step.

Sometimes the decision happens elsewhere

If a VPN connects and other websites work, the remaining site may be rejecting the VPN exit address or your account region. A browser extension, security app or device management policy can also prevent access before a useful request leaves your device. Neither case is fixed simply by hiding DNS queries.

Two illustrative cases: a streaming service displays an account-region message after login; a school laptop prevents installing a VPN app. The first calls for checking the service's account and access requirements. The second calls for the device administrator. Buying another VPN is not the first useful experiment in either case.

What changing DNS and using a VPN actually change

DNS over HTTPS (DoH) encrypts DNS messages between a client and its chosen resolver. It does not tunnel the subsequent website connection. The resolver still processes the query. RFC 8484 separates protection on the network path from privacy at the resolver.

  • Another resolver: changes who answers the lookup. Its own filtering policy and reachability still matter.
  • Encrypted DNS: protects the lookup in transit to that resolver. It does not change the website's destination IP.
  • A VPN tunnel: carries covered traffic through a VPN server. The local network sees that server as the destination; the website sees the exit IP. DNS handling depends on the app, browser and split-tunnel settings.

A VPN can therefore help with several local network filters, but its own connection may be blocked. It also cannot guarantee that the destination will accept its exit IP. Use our restricted-network VPN settings comparison when the tunnel itself fails, and the IP and DNS leak test to inspect what your browser exposes after connecting.

Check symptoms without treating them as proof

OONI compares DNS, connection and web responses to look for interference. Its Web Connectivity methodology also explains false positives: location-dependent responses and ordinary failures can differ from a reference connection.

  1. Record the exact result. A named policy block page is more informative than “it does not work.” Note whether the failure appears before login, after login or when starting the VPN.
  2. Compare carefully. On another permitted connection, keep the device, browser and VPN settings consistent. A change narrows the possibilities but does not identify the filtering mechanism.
  3. Change one variable. For a connected VPN with one failing site, try another exit server. For a tunnel that will not connect, follow the provider's documented fallback settings.
  4. Choose the appropriate owner. Report an incorrect category block to the network administrator; report an account error to the website. Keep VPN protection enabled when disconnecting would expose sensitive activity.

The unblocking assistant turns these distinctions into a short checklist. It uses your answers to suggest next steps; it does not probe a website or prove censorship.

Website blocking questions

No. DNS filtering applies a rule to a hostname lookup, for example to block malware or a restricted category. A DNS leak concerns whether your lookups travel through the resolver or route you intended while using a VPN. The two issues can occur separately.

HTTPS encrypts the page request and response, but a network can still block destination IP addresses. Without Encrypted Client Hello, the TLS handshake can also expose the server name. ECH reduces that exposure where it is supported; it does not make the connection unblockable.

No. A different reachable resolver may help with a DNS-only restriction. It does not change the destination IP or remove device controls, website account restrictions, or rules that block the connection itself.

Sources and further reading

Original DoVPN explanation, examples and diagram. Technical sources checked September 8, 2026.

  1. Cloudflare: DNS filtering — resolver rules and hostname-level limits.
  2. OONI: How is website blocking implemented? (PDF) — detection signals and blocking actions. Its SNI explanation needs the ECH qualification discussed above.
  3. RFC 6066, section 3: Server Name Indication — hostname selection for TLS.
  4. Cloudflare: Encrypted Client Hello — protection and deployment limits.
  5. RFC 8484, section 8: DNS over HTTPS privacy — encrypted transport and resolver visibility.
  6. OONI: Web Connectivity — measurements, comparisons and false positives.

Compare VPN options

Check whether your existing VPN works first. If you need another provider, compare current offers and renewal terms.

Proton VPN Logo
4.6

Proton VPN

70% OFF
$2.99 /mo equivalent
Provider reference $9.99/mo equivalent

Swiss-based • Open-source apps • Secure Core

  • 20,000+ servers in 140+ countries
  • 10 simultaneous connections
Get Proton VPN deal →
NordVPN Logo
4.7

NordVPN

69% OFF +3 Months Free
$3.49 /mo equivalent
Provider reference $11.59/mo equivalent

Broad server coverage • 10 devices • Extra privacy tools

  • 8,400+ servers in 126 countries
  • NordLynx (WireGuard) protocol
Get NordVPN deal →
Surfshark Logo
4.6

Surfshark

85% OFF +3 Months Free
$2.49 /mo equivalent
Provider reference $16.45/mo equivalent

Unlimited devices • Low introductory price • MultiHop

  • 4,500+ RAM-only servers in 100 countries
  • Unlimited simultaneous connections
Get Surfshark deal →