There are several issues that make blocking a website ineffective:
- if you intercept and replace DNS responses for these sites then users with DNS-over-HTTPS or DNS-over-TCP will bypass the block. So let's promote using DoH/DoT and enabling it by default instead of relying on ISP's DNS servers.
- if you examine the domain name in SSL Server Hello message then the site can switch to TLS 1.3 where it is encrypted.
- if you resolve domain names and block access to those IPs automatically without human review then the owner of the blocked site can block any other site by adding its IP address to their DNS server. This can be funny, and we had such cases in Russia.
- if you resolve domain names not very often, for example once every day, then the owner of the site can avoid blocking by regularly changing IP address.
Let me give a hint to French court: ordering the search engines and advertisement companies to stop dealing with the site is much more effective.