How Censorship Events Appear on Tor Metrics
Tor Metrics visualizes censorship events primarily through interactive, country-specific time-series graphs that track daily user connection trends. By displaying fluctuations in direct connections alongside the adoption of censorship-circumvention bridges, the platform provides clear visual indicators of when access is blocked, which protocols are targeted, and how users adapt to circumvent restrictions.
Direct Connection Drops
The most immediate indicator of censorship on Tor Metrics is a sharp, sudden decline in the “Directly connecting users” graph for a specific country. Under normal circumstances, connection volumes follow predictable, recurring patterns based on local time zones and daily routines. When a government or Internet Service Provider (ISP) deploys a network-wide block targeting default Tor relays, the graph displays an unnatural, cliff-like drop toward near-zero levels within hours.
Spikes in Bridge and Pluggable Transport Usage
When direct access is restricted, the “Bridge users by transport” graphs typically show an inverse reaction. Users who can no longer connect directly configure bridges—unlisted relays—or use pluggable transports such as obfs4, Snowflake, or WebTunnel. Censorship events appear on these charts as sudden upward spikes in transport adoption, visually tracking the migration of users from standard connections to circumvention tools.
Transport-Specific Blocking Patterns
Tor Metrics allows traffic to be filtered by individual pluggable transports, showing the targeted nature of specific censorship mechanisms. If an authority specifically blocks the IP addresses of standard bridges, obfs4 numbers may plummet while domain-fronted or ephemeral transports like Snowflake surge. Comparing these transport lines over the same timeline highlights the cat-and-mouse dynamic between blocking techniques and evasion methods.
Distinguishing Protocol Blocks from Complete Internet Outages
The visualizations help differentiate between targeted application blocks and broader infrastructure shutdowns. A targeted Tor block shows an asymmetry: direct relay connections collapse while bridge traffic rises. In contrast, a full regional internet shutdown displays a simultaneous drop across all metrics—both direct connections and all bridge transports fall to zero and remain flat until physical connectivity is restored.