AnonymFlow
voyage-censureINFO

Russia Is Blocking VPNs by Address Range, Not by Protocol - and Why That Changes the Answer

Ahead of the September elections, Roskomnadzor is reported to be blacklisting whole hosting ranges rather than detecting VPN traffic. That is address-based blocking, and obfuscation does not solve it. What is documented, and what is not.

By Eric Gerard · Editor · AnonymFlow3 min readPhoto via Pexels

Most coverage of VPN blocking describes a cat-and-mouse game about traffic: the censor learns to recognise what a VPN connection looks like, the provider disguises it, and round it goes. What is reported in Russia this month is a different mechanism, and the difference matters more than the headline does.

What is reported, and how firmly

On 5 August 2026, Euronews reported that Roskomnadzor, the Russian communications regulator, is targeting encrypted connections ahead of the September elections, in an action described as the largest of recent years. The exact scale is not known, and the report says so plainly. We are not in a position to test anything from inside Russia, so what follows is what is documented, marked as such.

The reported method is the part worth understanding. Rather than identifying VPN traffic by its signature, the restrictions are said to have targeted the infrastructure directly: the IP addresses of the hosting providers where VPN services sit were added to a blacklist. Several dozen autonomous systems, the large blocks that networks are organised into, were identified, and all the prefixes attached to them were blocked.

For scale, Roskomnadzor confirmed in February 2026 that it had blocked 469 VPN services. Separately, a budget of 2.27 billion roubles, roughly 29 million dollars, was allocated to developing an AI-assisted filtering system intended to automate the detection and blocking of prohibited content and encrypted connections.

A server room aisle lit in blue, with a switched-off flat monitor on the floor between racks and dense bundles of pale network cables hanging above it.
A server room aisle lit in blue, with a switched-off flat monitor on the floor between racks and dense bundles of pale network cables hanging above it.

Why this defeats obfuscation

This is the point that gets lost. Obfuscated servers work by making VPN traffic look like ordinary HTTPS, so that a firewall inspecting the traffic cannot tell what it is. That is a good answer to signature-based blocking, and it remains a good answer to it.

It is not an answer to address-based blocking. If the destination range itself is unreachable, it no longer matters what the traffic looks like, because there is nothing at the other end to reach. Disguising a letter does not help when the entire postal district has been closed.

That is why a provider can advertise obfuscation honestly and still be unreachable in a country doing this. The two mechanisms are stacked, not alternatives, and a claim that one product defeats all blocking should be read with that in mind.

What actually tends to survive, and the honest caveat

Address-range blocking has a cost for the censor: hosting ranges carry more than VPNs, so blocking a whole prefix takes down unrelated services sitting in the same block. That cost is the practical limit on how far this method goes, and it is why blocks of this kind are often partial and shifting rather than total.

What follows from that is unglamorous. Infrastructure that is not concentrated in a few well-known hosting ranges is harder to sweep up in one action, which is an argument for self-hosted or less concentrated endpoints rather than for any particular commercial brand. We are not going to tell you a specific service currently works in Russia, because we cannot verify it from here and a claim like that goes stale within days.

Using a VPN is legal in most countries, and Russia is a case where the picture is more restrictive and moves. Our country-by-country look at VPN legality sets out what is documented rather than what is assumed. Anyone travelling to or living in a country that restricts these tools should check the current position rather than rely on an article, including this one.

The short version

The story is not that Russia found a cleverer way to spot VPN traffic. It is that it stopped trying to spot it, and went after the addresses instead. That is a blunter instrument with real collateral damage, and it is also the one that current consumer defences are least able to answer.

Reporting on the current wave: Euronews, 5 August 2026.

Editorial pick
4.6 / 5

Stay connected anywhere with NordVPN

Obfuscated servers for restrictive networks · 60+ countries · 30-day money-back

Deloitte audit 202430-day guarantee14M+ users
See the offer
Everything you need to know.

Frequently asked questions

Are VPNs blocked in Russia right now?

Roskomnadzor is reported to be conducting the largest such action in recent years ahead of the September 2026 elections, and the exact scale is not publicly known. Separately, the regulator confirmed in February 2026 that it had blocked 469 VPN services. What is documented is the direction and the method, not a working list of what still connects, and any such list would be out of date within days.

Does an obfuscated VPN get around this?

Not on its own. Obfuscation disguises what the traffic looks like, which answers blocking that works by recognising VPN signatures. The method reported here blocks the destination address ranges themselves, so there is nothing to reach regardless of how the traffic is disguised. The two are stacked defences on the censor's side, not alternatives.

What is an autonomous system, and why does it matter here?

It is a large block of IP addresses under one operator's control, which is how the internet is organised at the routing level. Blocking a whole autonomous system's prefixes takes out everything hosted in it at once, including services unrelated to VPNs. That breadth is both what makes the method effective and what limits how widely it can be applied.

Is it legal to use a VPN in Russia?

The position is restrictive and it changes, which is exactly why it should be checked against a current source rather than an article. Providers have faced blocking and legal pressure for years. Anyone living in or travelling to the country should look at the present rules before relying on any tool.

Why will you not recommend a service that works there?

Because we cannot verify it. Testing from outside the country does not tell you what a connection from inside does, and the situation moves week to week during a blocking campaign. Publishing a name we have not confirmed would be a guess presented as advice.