
How to check if website is accessible from Russia: test from a network inside Russia, not from your office or a European data center. Run a blocklist lookup, an HTTP request and a traceroute from a Russian vantage point, then compare with a check from the EU or US. The difference shows a block, throttling or your own infrastructure.
Is my site blocked in Russia, or just unreachable from there?
These are two different questions, and mixing them up is the most common mistake foreign site owners make. A site can be missing from every blocklist and still fail for Russian visitors, and a site can be listed in the register yet load for some users whose ISP has not applied the entry yet. In practice, "not reachable from Russia" comes from one of four layers:
- The legal layer — the domain, URL or IP address is in Roskomnadzor's Unified Register, and Russian ISPs are obliged to restrict access to it.
- The network filtering layer — deep packet inspection equipment on operator networks (TSPU) slows down or resets certain connections, even for sites that are not in the register.
- The infrastructure layer — your site shares an IP address or a hosting/CDN range with something that is blocked, so it goes down as collateral damage.
- Your own side — a geo-blocking rule, a WAF country rule, or a hosting or SaaS provider that refuses traffic from Russian IP addresses.
Each layer leaves a different fingerprint, and you can tell them apart with a few checks. The table below is the short version.
| What a Russian visitor sees | Most likely cause | How to confirm | What the owner can do |
|---|---|---|---|
| An ISP page saying access is restricted by law, often after a redirect | Entry in the Unified Register (domain, URL or IP) | Registry lookup on /en/rkn or the official register form | Find the basis of the decision in the entry and deal with that authority |
| Connection timeout or reset, the same URL works from the EU | IP-level block or DPI filtering on the path | HTTP check from Russia vs abroad, then a traceroute to see where packets stop | Check whether the IP is listed; if it is shared, ask the host for another one |
| TCP connects, the page starts loading and then hangs | Throttling by TSPU equipment | curl timings from a Russian network: connect is fast, the transfer stalls | Review which CDN or network your traffic goes through |
| A proper error page from your own CDN, for example Cloudflare error 1009, a 403 or a 451 | Your own geo-block or a provider's country restriction | Read the response headers and body from a Russian node | Remove the country rule if you want Russian traffic |
| The page opens but is broken: no styles, no checkout, spinning widgets | A third-party script, font or API host that is blocked or throttled | Browser dev tools or a HAR file captured from inside Russia | Self-host critical assets or load them asynchronously |
| Name does not resolve or resolves to an unexpected IP | DNS answers substituted by ISP resolvers, or a DNS problem of your own | Compare DNS answers from Russian ISP resolvers with public resolvers | Fix your records first; substituted answers point back to the register |
Why "available" is a regional concept
Availability depends on the check origin. The same URL can behave differently from different countries due to:
- routing and peering between networks;
- filtering at the provider or backbone level;
- geo-blocks on the site or CDN side;
- issues at a specific Russian telecom operator.
If your customers are in Russia, the only trustworthy "is the site up?" test runs from Russia. A green status from Germany guarantees nothing for a user in Novosibirsk.
This is also why most global uptime checkers are not enough here. They report from dozens of locations, but a Russian location may be missing entirely, and a single probe inside one Russian network does not represent all of them: filtering is applied by each operator, and results can differ between Rostelecom, MTS, Beeline and smaller regional ISPs.
How Russia restricts access to websites
For a foreign owner it helps to know the mechanics, because they explain the symptoms. The full picture is in how Roskomnadzor blocks websites; the parts that matter for diagnosis are below.
The blocklist: the Unified Register
Roskomnadzor (RKN) maintains the Unified Register of domain names, page addresses and network addresses containing information whose distribution is prohibited in Russia. An entry can name a whole domain, a single URL or an IP address, and each entry records which authority made the decision and on what legal basis. ISPs download the register and must restrict access to what is in it. The official lookup form is public: the Unified Register search at eais.rkn.gov.ru.
Two practical consequences. First, a URL-level entry on a site served over HTTPS often affects the whole domain in practice, because an ISP cannot see the path inside an encrypted connection. Second, the register is not the only reason a site is blocked, so "not in the register" does not prove "reachable".
TSPU and throttling
Since the 2019 amendments often called the "sovereign internet" law, Russian operators have been required to install technical means of countering threats (TSPU) on their networks. This is deep packet inspection equipment managed centrally rather than by each ISP. Unlike classic register-based blocking, it can slow a connection down instead of cutting it, which is why a throttled site does not show a block page: it simply loads forever or breaks halfway. The throttling of Twitter in 2021 was the first widely noticed use of this approach.
The filtering can target protocols and features as well as destinations. Site owners behind Cloudflare, for example, have reported that connections using Encrypted Client Hello (ECH) fail from Russia, and Cloudflare itself has publicly reported throttling of traffic to its network by Russian ISPs. If your site sits behind a large foreign CDN, read Cloudflare in Russia before you start debugging your origin.
Hosting and CDN IP ranges
IP-level blocking is where innocent sites get hurt. When an IP address or a whole range is added to the register, every site on it becomes unreachable, whether or not it has anything to do with the reason for the block. The best-known example is 2018, when attempts to block Telegram took down large ranges of cloud provider addresses along with many unrelated services. Today the typical case is smaller: a cheap shared-hosting IP or a CDN edge address that also serves a blocked site. The RKN checker looks up the resolved IP as well as the domain, and shows the ISP and ASN, so you can see whether the problem is your name or your neighbors.
Blocks you set yourself
Sometimes the block is on your side. Common cases:
- a WAF or CDN country rule that denies Russia; on Cloudflare the visitor sees error 1009, "the owner of this website has banned the country or region your IP address is in";
- a hosting, payment or SaaS provider that refuses connections from Russian IP ranges to comply with sanctions, which you inherit without having configured anything;
- a server that answers HTTP 451 Unavailable For Legal Reasons, the status code defined in RFC 7725 for exactly this situation;
- anti-bot or rate-limit rules that treat Russian traffic as suspicious and serve challenges or 403 responses.
These are easy to spot because the response comes from your own stack: you get a real HTTP status and your CDN's headers, not a timeout.
How to check
enterno.io runs checks from Russia (ru-msk, Moscow). This is the baseline node, available on the free plan too. Use three tools, in this order:
- RKN blocklist checker — enter the domain or IP. It looks the entry up in a consolidated register export, resolves the name through Rostelecom, MTS and SkyDNS resolvers to catch substituted answers, shows the IP, ISP, ASN and country of the host, and runs a live reachability probe from nodes in Moscow and St. Petersburg.
- HTTP checker — enter the full URL and get the status code, response time and headers exactly as a Russian user receives them. A real status code with your own headers means the request reached you; a timeout means it did not.
- Traceroute — if the HTTP check fails, trace the route to see the last hop that answers. A path that dies inside a Russian operator's network points to filtering; a path that reaches your provider and stops there points to your firewall or host. How to read traceroute output explains the asterisks and latency jumps.
To tell whether a problem is local or global, compare three regions:
- ru-msk — Russia (Moscow);
- eu-de — Europe (Germany);
- us-east — United States (East).
The free plan includes the Russia check. Full multi-region monitoring (RU + EU + US simultaneously) is on paid plans.
| What to check | Tool | What it shows |
|---|---|---|
| Blocklist status | RKN checker | register entry, DNS via Russian ISPs, host ISP and ASN |
| HTTP availability | HTTP checker | status code, time, headers |
| Network path | Traceroute | hops, latency, where packets stop |
| Network reachability | ping | host reachability, loss |
| SSL channel | SSL checker | certificate validity |
| DNS | DNS checker | A/AAAA/MX/NS records |
Manual check: curl, traceroute and ping
If you have a server or VPS in Russia, you can run the same checks by hand. A machine you control inside a Russian data center is a legitimate test point, but remember that data-center networks are often filtered differently from home broadband and mobile networks, so treat it as one sample, not the whole country.
# HTTP code and response time
curl -o /dev/null -s -w "code=%{http_code} time=%{time_total}s\n" \
--connect-timeout 10 https://example.ru/
# network reachability
ping -c 4 example.ru
For a throttling investigation you need the timing of each stage, not only the total. curl can print them with its -w write-out variables:
curl -sS -o /dev/null --max-time 30 -w \
"ip=%{remote_ip} code=%{http_code}
dns=%{time_namelookup} tcp=%{time_connect} tls=%{time_appconnect}
ttfb=%{time_starttransfer} total=%{time_total} bytes=%{size_download}\n" \
https://example.com/
Then trace the path. mtr sends repeated probes and shows loss per hop; -z adds the AS number of each hop, which tells you whose network the packets die in. A TCP traceroute to port 443 follows the same path as real HTTPS traffic, which matters when ICMP is filtered differently from TCP:
# 50 probes, wide report, AS numbers per hop
mtr -rwzc 50 example.com
# TCP traceroute to the HTTPS port (Linux, needs root)
sudo traceroute -T -p 443 example.com
But a manual check is a single snapshot. Availability can flicker, and that is hard to catch by hand.
How to read the results
| Result from Russia | What it means |
|---|---|
| DNS resolves to an IP that is not yours | An ISP resolver substitutes the answer, typically pointing to a block page |
tcp never completes, curl reports a connect timeout | The IP is dropped on the way: IP block or a firewall that rejects the source |
TCP connects, tls hangs or the connection resets during the handshake | Filtering on TLS metadata such as the server name or ECH |
TLS completes, then bytes stops growing and curl hits --max-time | Throttling: the connection is alive but data barely flows |
| A normal status code and your own headers, only slower than from the EU | No block; long routes or congested peering between networks |
| 403, 451 or a CDN error page with your provider's headers | A block on your own side: geo rule, WAF or provider policy |
What to do if your site is blocked or throttled in Russia
The fix depends on the layer. None of it involves asking your visitors to change how they connect; the goal is to make the site itself reachable.
- Your domain or URL is in the register. The entry shows which authority made the decision and on what basis. Removal goes through that authority: typically the flagged content is taken down and the owner notifies RKN, or the decision is challenged in court. The step-by-step process is in How to check if a site is blocked in Russia.
- Your IP is blocked because of a neighbor. Ask your host for a dedicated IP that is not in the register, or move the site. Check the new address before you switch DNS.
- Traffic through your CDN is throttled. This is not something you can appeal. Owners with a large Russian audience usually serve it from infrastructure that is not affected, for example hosting inside Russia, which also brings data localization rules into scope.
- The block is your own. Review country rules in your WAF and CDN, and ask your hosting and SaaS vendors whether they restrict Russian IP ranges.
- Pages break halfway. Find the third-party hosts that fail from Russia in a HAR capture and self-host what is critical: fonts, scripts, checkout widgets.
Continuous availability monitoring
Set up monitors on the monitors page so enterno.io checks availability from Russia on a schedule: every 5 minutes on Free, down to 1 minute / 30 seconds on paid plans. On an outage the system records an incident and sends an alert.
Monitoring answers not "is the site up right now?" but the more important question — "how often and when is it unreachable from Russia?".
A history of checks matters here more than for ordinary uptime. A new register entry, a change in filtering or a new CDN edge address tends to show up as a sudden step: green from the EU, red from Russia, starting at a specific moment. Having that timestamp makes the conversation with your host or CDN much shorter.
Alerts and status pages
enterno.io notifies via Telegram, Slack, email and webhook. You can publish a public status page where customers see your services' current availability themselves. For Telegram alert setup see Telegram monitoring alerts.
FAQ
How do I check if my website is blocked in Russia?
Look the domain and its IP up in the Unified Register (the RKN checker does this and also tests DNS through Russian ISPs), then run an HTTP check from a Russian node. A register entry plus a failing check from Russia is a block.
Can I check from Russia for free?
Yes, the ru-msk check is available on enterno.io's free plan, and the RKN checker and traceroute are free to use.
Why does my site open from Europe but not from Russia?
Because availability is regional. The usual causes are an IP-level block, throttling by TSPU equipment, a shared IP or CDN range affected by someone else's block, or a geo-rule on your own side. Compare regions and trace the route to see which one it is.
My site is not in the register. Can it still be unreachable from Russia?
Yes. Throttling does not require a register entry, and neither does collateral damage from a blocked IP range or a provider's own country restriction.
Why is monitoring better than a one-off check?
A one-off check is a moment. Monitoring records downtime periods, duration and timing, and alerts you immediately on failure.
What if it's unreachable from Russia but fine from the EU?
That is a typical sign of network filtering or a block. Compare regions and check DNS, then follow the owner's steps above; the register article has the removal process.
Check your site's availability from Russia now: run the RKN blocklist check and an HTTP check on enterno.io, then set up continuous ru-msk monitoring with Telegram alerts. Also useful: SSL and DNS.