When a website refuses to load in one country and loads fine in another, the usual assumption is censorship. Often it is nothing of the kind. The block was put there by the website itself, or by the network it runs on, deciding who it will serve.
That practice, server-side geo-blocking, is common, rarely explained to the person blocked, and surprisingly hard to measure. Several peer-reviewed studies have measured it anyway. Together they give a clear answer to which countries are blocked most, and a more interesting one to who is doing it.
Key takeaways
- In the largest global measurement, Syria, Iran, Sudan and Cuba were geo-blocked far more than any other country, all of them under US sanctions at the time. The median country was blocked by 3 of 8,000 popular sites; Syria by 71.
- Most blocking runs through a handful of infrastructure providers. In that study, 40.7% of Google App Engine customers among top sites blocked at least one country, against 3.1% of Cloudflare and 1.4% of Amazon CloudFront customers.
- After the 2022 invasion of Ukraine, 444 foreign websites geo-blocked Russian users, including US news sites and universities.
- A 2023 measurement from Cuba found 546 blocked domains, and 88% of them gave no reason. Only 9 used the HTTP status code created for legal blocks.
- The global country ranking dates from 2018. No study since has repeated it worldwide, and US sanctions on Syria were revoked in July 2025.
Geo-blocking is not censorship
The distinction matters, because the two are caused by different actors and fixed by different people.
| Geo-blocking | Censorship | |
|---|---|---|
| Who acts | The website, or its hosting or CDN provider | A government, usually through local networks |
| Where it happens | At the server | Inside the visitor’s country |
| Typical signal | A 403 page, a notice, or a quiet refusal | DNS tampering, connection resets, blocked addresses |
| Usual motive | Sanctions, licensing, fraud, cost, legal risk | Political or legal control of information |
The two can look identical to a visitor, and they contaminate each other’s measurements. The 2018 study below found that 9% of domains on a widely used censorship test list returned a CDN block page in at least one country, meaning some “censorship” findings were really the website saying no.
The countries blocked most
The only worldwide ranking comes from “403 Forbidden: A Global View of CDN Geoblocking”, presented at the ACM Internet Measurement Conference in 2018 by a team led from the University of Michigan, with Cloudflare contributing its own customer rule data. They loaded 8,000 of the Alexa top 10,000 sites from vantage points in 177 countries, using residential connections, and counted explicit block pages.
| Country | Top-10K sites geo-blocking it |
|---|---|
| Syria | 71 |
| Iran | 67 |
| Sudan | 66 |
| Cuba | 66 |
| China | 11 |
| Nigeria | 11 |
| Russia | 10 |
| Brazil | 8 |
| Iraq | 6 |
| Pakistan | 5 |
The median country was blocked by 3 sites. The authors put it directly: the top four were Syria, Iran, Sudan and Cuba, “by a wide margin”, and all four were sanctioned by the United States. The blocking was concentrated in finance and banking sites, consistent with sanctions compliance.
A larger sample of CDN customers across the top million sites repeated the pattern, with Iran blocked by 178 domains, Sudan by 169, Syria by 168 and Cuba by 165, followed by China at 34, Russia at 28 and Ukraine at 22. Of 177 countries tested, only the Seychelles saw no blocking at all.
Two warnings before quoting this table. The measurement is from 2018, and nothing since has repeated it worldwide. And one of its top four has changed status: US sanctions on Syria were revoked effective 1 July 2025. How many sites have since removed their Syria rules has not been measured.
Who does the blocking
The infrastructure layer
Very few websites build geo-blocking themselves. They switch it on in their CDN or cloud platform, which is why the same few providers dominate every study. Among the top 10,000 sites in the 2018 measurement:
| Provider | Customers blocking at least one country |
|---|---|
| Google App Engine | 40.7% |
| Cloudflare | 3.1% |
| Amazon CloudFront | 1.4% |
App Engine’s figure was driven by sanctions: the authors report it blocked the same sanctioned set across its customers, rather than each site choosing. Elsewhere, blocking is a customer decision. Amazon’s documentation describes CloudFront’s allowlists and denylists and states that a blocked visitor receives a 403 Forbidden. Cloudflare’s documentation says block-by-country is available on Enterprise plans, and that other customers can block countries with WAF custom rules.
Cloudflare’s own rule data, published in the same paper for July 2018, shows who customers chose to block. Across all zones, Russia and China were each blocked by 0.22%, ahead of North Korea at 0.20% and Iran at 0.18%. Among Enterprise customers the order changed completely: North Korea 16.50%, Iran 15.57%, Syria 13.74%, Russia 4.90%. Large organisations block for sanctions; smaller ones block where they see abuse.
Platforms under trade controls
Some services state their restrictions openly. GitHub’s trade controls page says its services are not available to developers in North Korea, and that it holds a licence from the US Treasury’s Office of Foreign Assets Control to provide cloud services to developers in Iran. Policies like this change with sanctions, so the page itself, not a secondary summary, is the only reliable source.
Russia after 2022
A USENIX Security 2023 study measured the network in the weeks after the invasion of Ukraine, with daily measurements from 14 March to 22 April 2022 and a full scan on 10 May 2022.
Foreign websites moved quickly. The authors found 444 foreign sites geo-blocking Russian users. At the HTTP level, 286 of 8,763 popular domains (3.26%) returned block signatures to every Russian vantage point, and Russia was geo-blocked by significantly more domains than any other country tested. Most of that blocking ran through Cloudflare, 87 domains, and Akamai, 57. Among the blockers were 42 news and media domains, the majority US-based, national and local.
Blocking ran the other way too. More than 45% of Russian government domains tested blocked access from countries other than Russia and Kazakhstan.
Cuba, from the inside
The most recent country study came from a single residential vantage point in Cuba, published at USENIX Security 2024. Between 11 and 22 May 2023 the researchers tested 10,093 popular domains and found 546 geo-blocking Cuban visitors, including well-known services in technology, business and finance.
| How the block appeared | Domains |
|---|---|
| HTTP response with a block page | 395 |
of which 403 Forbidden | 347 |
of which 200 OK, a block page presented as success | 32 |
of which 451 Unavailable For Legal Reasons | 9 |
| Failed at the DNS, TCP, TLS or HTTP stage without serving a page | the remainder, some domains at more than one stage |
The finding that matters most for anyone affected: 88% of the blocked domains gave no informative notice of why. And HTTP status 451, created specifically to signal a legal block, remained a rarity. The 2018 study saw it only twice in its entire run.
The EU: blocking inside a single market
Europe offers a different picture, because it legislated against geo-blocking between member states. The Geo-blocking Regulation has applied since December 2018. The Commission’s 2020 short-term review found only 0.2% of roughly 9,000 surveyed websites blocking access, and location requirements falling from 26.9% to 14%. Audiovisual content is excluded from the Regulation, and it shows: the same review found a European consumer could access 14% of the films available online in the EU on average, from 1.3% in Greece to 43.1% in Germany. The Commission opened a formal evaluation of the Regulation in February 2025.
Blocking also ran into Europe from outside. When GDPR took effect in 2018, a number of US news sites blocked EU visitors rather than change their data practices. A peer-reviewed study of four of them, the Los Angeles Times, Chicago Tribune, USA Today and Us Weekly, found unique monthly visitors from the EU fell by between 82% and 96% during the blocks, and that audiences did not fully return once access was restored. The same question now recurs with consent walls, which vary sharply by country.
Why this is hard to measure
Every study above says the same thing about method: you cannot measure geo-blocking from one place.
- You need a vantage point inside each country. A block aimed at Russia is invisible from Germany.
- Status codes lie. Block pages served as
200 OKpass any check that looks only at the status. - Silent failures look like bad networks. A timeout from a blocked country and a timeout from a slow one are the same event until you compare against a control.
- Censorship and geo-blocking overlap. Researchers separate them by where in the path the failure happens, and still flag the ambiguous cases.
Measurement also carries ethical weight. The 2018 researchers, testing through residential connections, refrained from probing high-risk site categories to protect the people whose connections carried the traffic. That restraint belongs in any serious measurement design, and the same thinking runs through the case for recording where web data was observed.
What international teams should take from this
If you publish, sell or operate across borders, the question is less “which countries get blocked” and more “what does my audience in each market actually get”.
- Test your own properties from each market you serve. CDN and WAF rules are easy to add and easy to forget. A rule added for an abuse spike three years ago may still be refusing an entire country.
- Check the page, not just the status. Look for block text in the body as well as the code.
- If you must block, say why. A clear notice, and ideally a
451where the reason is legal, turns a mystery into an answer. - Record the vantage point alongside any result you publish.
For the first point, a country-targeted request through Shifter’s residential gateway shows what a visitor in that market receives, without changing anything else in your test:
curl -s -o /dev/null -w "%{http_code}\n" \
-x customer-USERNAME-country-br:PASSWORD@p.shifter.io:443 \
https://www.example.com/
Country codes are ISO 3166-1 alpha-2. The geo-targeting documentation covers region, city and ASN targeting, and how testing your own releases this way extends to geo-compliance checks.
One line is not negotiable. Geo-blocking for sanctions compliance is a legal obligation on the business that applies it, and residential proxies must not be used to get around it, or around licensing restrictions, from anywhere. The use described here is observation of your own properties and public measurement, and if you are unsure where that line falls for your situation, take legal advice before you test.
The bottom line
The countries blocked most are the ones under sanctions, and the blocking happens mostly because infrastructure providers make it a checkbox. Around that core sits a larger, looser layer: sites blocking Russia after 2022, US publishers blocking Europe after GDPR, smaller businesses blocking wherever they saw abuse. Almost none of it tells the blocked visitor why.
The biggest gap is the data itself. The only worldwide country ranking is eight years old, and one of its top four is no longer under US sanctions. Anyone who needs a current answer for their own markets has to measure it, from inside those markets.
Sources and references
- McDonald, Bernhard, Valenta, VanderSloot, Scott, Sullivan, Halderman and Ensafi, 403 Forbidden: A Global View of CDN Geoblocking, ACM Internet Measurement Conference 2018. Country counts, provider rates and Cloudflare rule data.
- Ramesh, Sundara Raman, Virkud, Dirksen, Huremagic, Fifield, Rodenburg, Hynes, Madory and Ensafi, Network Responses to Russia’s Invasion of Ukraine in 2022: A Cautionary Tale for Internet Freedom, USENIX Security 2023. Measured March to May 2022.
- Ablove, Chandrashekaran, Le, Sundara Raman, Ramesh, Oppenheimer and Ensafi, Digital Discrimination of Users in Sanctioned States: The Case of the Cuba Embargo, USENIX Security 2024. Measured 11 to 22 May 2023.
- US Department of the Treasury, Office of Foreign Assets Control, Recent actions, 30 June 2025. Revocation of Syria sanctions effective 1 July 2025.
- Amazon Web Services, Restrict the geographic distribution of your content. CloudFront geographic restrictions.
- Cloudflare, IP Access rules. Country blocking by plan.
- GitHub, GitHub and Trade Controls.
- European Commission, Short-term review of the Geo-blocking Regulation, 30 November 2020, and evaluation launch, 11 February 2025.
- Thurman, Sly, Fletcher and Wilczek, The International Communication Gazette, summarised by the Reuters Institute: Many EU visitors shut out of US sites in response to GDPR never came back, 19 July 2022.