Russia Blocks GrapheneOS Infrastructure, Forcing Two Server Moves

Russia’s filtering system is turning ordinary hosting decisions into collateral damage

GrapheneOS is reporting that Russia has started blocking the infrastructure that carries its services, forcing the project to move the traffic of its users in country to different servers twice in a matter of weeks.

The first time, Russian traffic was rerouted from a DataPacket server in Frankfurt to a Cherry Servers machine in Amsterdam. But then Russia started filtering that IP address space as well, and the traffic had to be moved again, this time to a Zare server in London.

The GrapheneOS project said that near the end of May 2026, Russia began filtering DataPacket IP space through an enforced domain allowlist for HTTP and TLS Server Name Indication (SNI). SNI is a way for a client to tell a server the hostname it is trying to connect to during the initial setup of a TLS (HTTPS) connection. This information can be used by a filter to decide whether the connection should be allowed or blocked.

The allowlist of domains that are allowed to connect through DataPacket IP space did not include those belonging to GrapheneOS, the project said.

After the first rerouting, Russia started blocking the new IP space, and GrapheneOS had to move the traffic again. The project said that Zare is the last of its sponsored European server providers that it can use as a workaround, and if this IP space is also blocked, the traffic will be routed through a Xenyth server in Toronto.

But unlike the previous two, this IP space is controlled by GrapheneOS itself, and the project expects this to be a more permanent solution for its users in Russia.

In fact, GrapheneOS does not expect Russia to block its own IP space directly, but it is also unlikely to be added to the allowlist. As a result, the project's services will "gradually going to become inaccessible in Russia via the IP space of major cloud services." On the other hand, "our own IP space will still work fine," GrapheneOS said.

The services that were affected by the blocking include the project's website, OS updates, the app repository, connectivity checks, network time, network-based location, geocoding, and other main services.

All this should work again for users in Russia after the move to the London server, and if Zare's IP space is also blocked, GrapheneOS will fall back to using its own non-anycast IPv4 /24 in Toronto.

GrapheneOS said that the filtering affects not only its services but also those of many other organizations that use the same hosting providers.

In fact, the project believes that Russia is using a domain blocklist for most of the internet, and an allowlist for the IP space of many VPS and dedicated server providers, specifically to block VPN services. This allowlist is expected to expand to every major server host, the project said, adding that this is "far more aggressive than China's filtering."

What this means is that a lawful project like GrapheneOS, which does not offer VPNs, can still end up blocked in Russia simply because it shares a hosting network with services that the authorities want to suppress.

However, the project's authoritative DNS was not affected by the recent filtering, because it runs on two anycast networks using its own autonomous system number and IP space. GrapheneOS believes that it can avoid the restrictions imposed by Russia for other services as well by using its own IP space.

And if Russia starts filtering the IP space of netcup, another server provider, GrapheneOS said it can create a reverse proxy to those services from Toronto.

There is also a workaround that users in Russia can implement by themselves, namely by changing the connectivity check from "Disabled" to "Standard" in the settings, which will use Google's servers instead of GrapheneOS's. This will allow the OS to continue to automatically select networks with internet access, handle captive portals, and prevent the job scheduler from treating every network as offline.

Explore more on these topics