AnyProxy
Get Pro
Glossary · Circumvention

Keyword filtering

Also calledcontent keyword block
Definition

Keyword filtering scans traffic contents for banned words or phrases and drops connections that carry them — requires DPI or MITM.

Explanation

In depth

To filter by keyword, the firewall must see the request contents — which means either the traffic is unencrypted (plain HTTP), the firewall is doing TLS MITM with an installed root cert (enterprise scenario), or the filter is reading TLS SNI and URLs from HTTP-plaintext fallbacks. National censors have used keyword filtering historically against plain HTTP; enterprise DLP systems use it heavily on inspected TLS. Web proxies over HTTPS to a mainstream domain defeat keyword filtering because the request contents are encrypted between your browser and the proxy, and the network sees only the proxy hostname.

Related terms

DPI (Deep Packet Inspection)Deep packet inspection reads not just packet headers but payload contents to identify and filter specific protocols, applications, or destinations.MITM (Man-in-the-Middle)A man-in-the-middle intercepts traffic between two parties — reading, modifying, or blocking the communication without either endpoint knowing.IP blockingIP blocking drops packets destined for specific IP addresses at the network firewall level — bypasses DNS entirely.DNS filteringDNS filtering blocks websites by making the DNS resolver return a fake response — the cheapest and most common first-line censorship tool.

Put the concept to work

Try AnyProxy free — no install, no signup, six regions.

Open a blocked page