Here's my personal experience with this:
Germany does exactly what you describe, the bare minimum to say "we're blocking" --- DNS omitting certain sites.
Spain is doing deep packet inspection, blocking DNS requests that lookup RT, so DNS over HTTPS or through a VPN is a must. Additionally, they're also reading the SNI in TLS requests and blocking that way. If you try accessing RT in pure unencrypted HTTP you're get some fortigate blocking message back.