87 Days Offline: What Cloudflare Radar Saw as Iran's Internet Flickered Back!
Hey everyone, it's Shiichan! Today's story is a heavy one, but I really want to share it with you: Iran's Internet has partially come back online after almost three months, and Cloudflare Radar caught the whole thing in its data.
Cloudflare Blog
What was announced?
On May 26, Iran's vice president announced that Internet access had started to be restored in the country. This was covered on Cloudflare's Blog, by the Cloudflare Radar team. The Internet had been almost entirely cut off since February 28, when U.S. and Israeli attacks began, and now, roughly three months later, Radar has confirmed signs that traffic is returning.
The story so far
Iran actually went through two nationwide Internet shutdowns in 2026.
The first began on January 8 around 16:30 UTC (20:00 local time). Traffic stayed near zero until January 21, briefly returned, then vanished again about 24 hours later. Another short recovery happened on January 25, and a fuller restoration finally began on January 27.
The second one was much longer. On February 28, around 10:30 local time (07:00 UTC), traffic dropped sharply, falling well under 1% of previous levels, with only tiny amounts of Web and DNS traffic leaving the country. That state lasted for nearly three months.
What changes
Then on May 26, 87 days after the second shutdown started, Radar observed a clear increase in both traffic and DNS queries starting around 11:00 UTC. Bytes transferred jumped to roughly 15x the levels from the week before.
That's a hopeful sign that people in Iran are gradually getting back online. For citizens who spent most of 2026 offline, this could be a real turning point.
Dive Deep
Still, the restoration is only partial. Even at its peak, traffic returned to just 40% of the maximum activity observed so far in 2026.
- Most of the new traffic is concentrated in Tehran: 91.6% of HTTP requests came from the capital.
- By network (measured per ASN), TCI, IranCell, RighTel, and MCCI each saw increases.
- Queries to Cloudflare's public DNS resolver (1.1.1.1) spiked too, a strong signal that users are requesting sites and services again.
- Traffic followed a daily rhythm, declining around 21:00 UTC and rising again on May 27 at 3:00 UTC (6:30 local time).
The most interesting part is IPv6. Since January, the announced IPv6 address space has been effectively zero, while IPv4 announcements stayed stable through both shutdowns. Because IPv4 addresses were never withdrawn from global routing tables yet actual traffic still disappeared, the shutdown was likely enforced through other means such as application filtering or whitelisting.
And we shouldn't celebrate too early. The original post adds a note of caution:
as demonstrated in January, brief periods of recovery can quickly reverse.
Wrap-up
- On May 26, Iran's Internet partially returned after almost three months, with Radar confirming a rise in traffic and DNS queries.
- Traffic recovered to about 15x the previous week, but only reached 40% of the 2026 peak.
- 91.6% of the new traffic came from Tehran, with increases on networks like TCI, IranCell, RighTel, and MCCI.
- IPv4 stayed stable in routing while IPv6 and real traffic vanished, pointing to filtering or whitelisting at the application layer.
- But just like in January, a brief recovery could still reverse.
This one is for engineers curious about networking and Internet measurement (BGP, DNS, ASNs), and for anyone who cares about freedom of access to information.