Is that impossible? Isn't it just a matter of running a root nameserver for the new internet?
Sure they could: just disallow any "unknown" encrypted communication. For example requiring the en/decryption to happen at the ISP or only allowing traffic they can decrypt and check.
(I'm not saying this is likely, but it could be implemented and most folks wouldn't care)
Not particularly serious. A little maybe.
Even then, it's impossible to prevent arbitrary communication. You can always hide your message inside of allowed messages (steganography), or an even more basic albeit inefficient technique: just use the timing between allowed messages to encode your hidden message.