First, You Got To Get Mad: How Spanish Football Rules Spain's Internet
A football league and a broadcaster decide what Spain can reach online during matches. No higher court has ever reviewed it.
"I'm as mad as hell, and I'm not going to take this anymore!"
Howard Beale - Network, 1976 written by Paddy Chayefsky

Quick translation to English, for those who need it:
Access to this IP address has been blocked in compliance with the ruling of 18 December 2024, issued by Commercial Court No. 6 of Barcelona in ordinary proceedings 1005/2024-H, brought by the Liga Nacional de Fútbol Profesional and Telefónica Audiovisual Digital, S.L.U.
It then links to a LaLiga press release explaining whose fault this is.
This is not a regulator, nor a ministry. Here we have a football league and a broadcaster, informing you that the address you were trying to reach is not available to you right now, linking to their side of the story.
Digi (ISP) at least tells you. On Movistar (another ISP) the connection simply hangs and you get the exclusive privilege of spending your afternoon chasing connectivity issues.
I live in Spain. I build things on the internet for a living. This has been going on since February 2025, and I have gone from "hmmm weird" to basically forgetting about it over the summer break to "wait, how is this still standing?" since the beginning of the 2026/2027 football season.
What actually happens
During matches, Spain's main network operators block a list of IP addresses. Not domains. IP addresses.
The ruling everything rests on is the one quoted on that block page. bandaancha published it, so you can read it yourself rather than take my word for it. It lists 123 IP addresses, and it allows "successor" addresses to be added at the applicants' own discretion.
How many get blocked in practice? According to bandaancha's FAQ, LaLiga president Javier Tebas has said the current figure is up to 3,000, of which 35-45% belong to Cloudflare. An independent measurement inside Digi's network during one match found nearly 800.
Then, in June 2026, the Open Observatory of Network Interference (OONI) published an actual measurement study. This is the report to send people who think this is a niche phenomenon and that it doesn't affect the wider public.
Full disclosure: Cloudflare sponsored part of this work. OONI states that the research was conducted independently and that all findings and conclusions are its own.
OONI compared connectivity from Spanish networks against a control point in Frankfurt, between 1 January and 1 June 2026, across a DNS scan of 9.2 million domains. What they found:
- 554,507 domains blocked at least once during match broadcasts - 5.8% of the domains tested
- 7,441 unique IP addresses across 36 infrastructure providers, including Cloudflare, AWS, Akamai, Microsoft and Meta
- Cloudflare accounted for 501,305 affected domains - 90.4% of the total - sitting behind just 2,218 addresses
- A single blocked Squarespace address took out 18,592 sites on its own
- Blocking as few as 4 to 20 addresses during a one-hour window was enough to make over 400,000 unrelated domains unreachable
Read that last bullet point again. As few as four IP addresses. Four hundred thousand sites.
The casualty list is concerning, to say the very least. Amnesty International, human rights organisations, environmental groups, government institutions and news outlets, none of which have ever streamed a football match.
On Sunday 14 December 2025, the website of Madrid Salud, the City of Madrid's public health and food safety authority, was unreachable during the afternoon's matches. A month before that, hospital websites and pedidosis.app, a tool used in emergency departments to calculate paediatric medication doses, went down.
And OONI found something else: On Digi Mobil's network (AS57269) they detected a TLS man-in-the-middle interception - a substituted certificate - affecting 7,334 addresses and 10,759 domains. A piracy block that very quickly turns into a severe privacy problem.
OONI is explicit that its methodology has limits and that these numbers are conservative. They are very likely the floor, not the ceiling.
How this survived 20 months without a higher court asking "how is this proportionate?"
This part had me scratching my head several times.
The applicants were LaLiga and Telefónica Audiovisual Digital. The defendants were the ISPs. One of those ISPs, Movistar, actually belongs to Telefónica.
The defendants didn't just decline to appeal - they conceded. The ISPs formally submitted to the claim (allanamiento), and the judge recorded that their submission "does not harm third parties". With no appeal from anyone with standing, a first-instance ruling becomes final and no appellate court ever sees it.
Third parties can't appeal. Cloudflare and RootedCON, the association behind Spain's largest cybersecurity conference, weren't parties, so they each filed a nullity motion, decided by the same court that issued the ruling. Both were rejected in March 2025. RootedCON's director described the issue in an interview with Genbeta as being about fundamental rights rather than about being offline for an afternoon.
Which leaves the Constitutional Court. RootedCON announced on 16 May 2025 that it had filed. Cloudflare followed in June 2025, asking the court to establish that disproportionate blocking is unlawful and alleging, this is Cloudflare's allegation as reported, not a finding, that the original court was not told the addresses in question are shared by thousands of websites. Cloudflare has also set out its position in its own transparency reporting.
As of April 2026, neither appeal had been resolved. At the time of writing, the blocks were running again for the 2026/27 season - the last one covered by the original ruling.
Now, I know how this sounds. The "Leave the multimillion dollar company alone" meme comes to mind.
But that reflex doesn't work here, and it's worth being precise about why. Cloudflare is not the sympathetic victim in this story, the 554,507 domains are. Cloudflare is the measuring instrument. It has the lawyers, the money and the standing to test whether the mechanism has a functioning check on it.
The answer, after more than a year of waiting for a court to decide whether it will even hear the case, is seemingly no.
Meanwhile the authorisation runs until the rights agreement ends, expected on 20 June 2027.
It is already spreading
If you're reading this from outside Spain and filing it under "ah... Spain": don't.
In March 2026 a second ruling in favour of Telefónica Audiovisual Digital extended the mechanism to other competitions: Champions League, tennis, golf.
Italy has been running the same principle for longer, as Piracy Shield: a portal through which rightsholders can compel providers to block domains and IP addresses within 30 minutes, without judicial oversight. It took Google Drive offline for Italian users for over 12 hours, and a September 2025 study by the University of Twente found it routinely blocks legitimate sites for months. The Italian authorities' response to the evidence was to extend the system to public DNS resolvers and VPNs, and to fine Cloudflare €14 million for refusing to join. Cloudflare appealed on 8 March 2026.
France went further and legislated it, though the practice came first. An agreement between the rightsholders' association and the French ISPs moved French blocking from DNS to IP level, and the automated real-time system was tested at Roland Garros in May 2026 before running operationally through the World Cup. Both ran on ordinary court orders under Article L.333-10 of the Code du sport. Then, on 21 July 2026, parliament adopted a law reforming that same article, so that Arcom, the French media regulator, no longer has to certify each site individually before it is blocked. Blocking can now follow the broadcast in real time without waiting for a fresh judicial decision. Four days earlier, on 17 July, the Paris court had issued fourteen orders naming not just the ISPs but Google Public DNS, Cloudflare, Quad9, DNS4EU, Proton VPN, CyberGhost, ExpressVPN, Google Search and Bing. The mechanism was built and run first; the statute ratified it afterwards.
And it has moved past ISPs entirely. A commercial court in Córdoba ordered NordVPN and Proton VPN to block access from Spain to 16 streaming sites, on the reasoning that VPN providers are intermediaries under the EU Digital Services Act.
In May 2026, that campaign hit its first friction. LaLiga asked the Córdoba court to fine NordVPN for allegedly failing to comply; on 19 May the court refused, noting that a genuine technical dispute existed and that the IP lists supplied changed too rapidly to implement. The blocking order itself still stands, and the main proceedings continue, but it is the first time a Spanish court has looked at the practical side of this and not simply signed off.
It has also stopped being a domestic matter. Cloudflare has told the United States Trade Representative that measures like these amount to digital trade barriers that fall disproportionately on US technology providers. LaLiga has gone to the same office, and to the European Commission, to argue the reverse: that Cloudflare is the principal facilitator of unauthorised broadcasts worldwide. Two private parties, both lobbying Washington over what people in Spain can reach on a Saturday afternoon. The USTR did not comment when the AP asked.
Another instance that made international news: During one match weekend, users in Spain could not reach Freedom.gov, a US State Department and CISA initiative built to help Europeans get around content blocking. Whilst I don't want to give that project more attention than it deserves, it is an anti-censorship portal run by a foreign government, unreachable in Spain, because of football.
European ISP associations are now arguing that rightsholders should carry the liability for collateral damage, which tells you how the last 20 months have gone.
What worries me most
There is a detail in bandaancha's FAQ that drew my attention. In the Vercel case, the pattern suggests addresses get blocked when their owners don't respond quickly enough, or in the expected way, to notifications sent to them. Other companies say they weren't notified at all.
If that reading holds, this is leverage over infrastructure providers, with their customers as the collateral.
Does it work? Do customers leave providers on the banned IP list?
The wrong lesson - this bit is opinion, clearly labelled
I recently read a well-argued post from a CTO saying he can no longer pick Cloudflare for his projects, because in Spain the experience degrades to the point of not working.
I understand the reasoning. I just think the conclusion is wrong, and I think a lot of people are quietly arriving at the same one, so it's worth spelling out. There are good reasons to migrate away from Cloudflare or not choose it in the first place... but this probably isn't a good one.
In this case, availability is not a property of Cloudflare. It's a property of Spanish enforcement practice. OONI counted 36 affected providers. Moving vendors moves the target; it doesn't remove it.
It gets the causation backwards. The site that went down did nothing wrong. Switching vendors because someone else's enforcement broke your site means accepting the fault was yours.
It quietly improves the numbers on the other side. LaLiga's position, as reported by Newtral, is that no formal claim for third-party damages has reached the courts, and that the blocks are temporary. Every company that migrates silently instead of documenting the damage keeps that first statement true.
And there's a version of this that defeats its own purpose. A company in the Canary Islands moved its infrastructure to AWS to get out from under the blocks. That's the actual landing zone when you optimise for "not being blocked in Spain": the hyperscalers, whose scale and legal weight make them the safest place to sit. I spent a whole post on how much deliberate work it takes to build on European infrastructure. Enforcement like this pushes in precisely the opposite direction; and if your original reason for looking at alternatives to a US provider was sovereignty, ending up at AWS because of a Spanish football ruling is a strange place to arrive.
Routing around the problem is the response the system is optimised for. It costs the people doing the blocking nothing at all.
Nobody voted for this
As a German, I love order. So, naturally, two things bother me, and only the first one is about football.
The first: the trade-off was made openly.
Nobody stumbled into this. In a public statement in February 2025, LaLiga responded to the disruption by putting the responsibility on Cloudflare. Tebas has since put the figure at up to 3,000 blocked addresses himself. The collateral damage isn't a surprise anyone is still discovering. It's a known, quantified, published cost, and the answer has been that the enforcement continues. Meanwhile the damages platform had collected around €2 million in reported losses by May 2026 - self-reported and documented, which makes it a floor rather than a total.
You can think piracy is a real and expensive problem, it is, and still notice that "a private rights holder decides which parts of the internet are reachable on a match day, and gets to define the list itself" is an enormous amount of power to hand to a party whose only accountability is to its members and not the public.
The second, and the one I actually find harder: how relatively contained the reaction has been.
Take a look at the majority of the domestic sources that I have presented thus far. A broadband consumer forum and a hacker conference. bandaancha does the measurement and the documentation. RootedCON took it to the Constitutional Court and teamed up with HackBCN to give affected businesses expert and legal support. The tech press, like Xataka, Genbeta or Newtral, has covered it consistently and well. What I have not found is major news outlets treating this as an ongoing story rather than a recurring incident. I'd be glad to be corrected on that.
Spanish politics seems to be, let's say, only mildly interested in the matter as well.
The Spanish parliament has moved slowly. An earlier motion to contain the blocks went nowhere. Then on 29 April 2026 the Economy and Digital Transformation Committee approved a non-binding motion, tabled by ERC and agreed with the PSOE, asking the government to write technological proportionality, a graduated scale of measures and "adequate consideration of third parties" into the Ley de Servicios Digitales, Spain's domestic implementation of the EU DSA, which is still working its way through parliament and has not been passed. PP and Vox voted against.
Which is where it gets a bit weird: The blocks were authorised on the premise that they were neither unlawful nor harmful to third parties - the existing law already said so. The principle Parliament is now asking for was in the file from day one. It would not have changed the December 2024 ruling by a single word.
The condition was never the problem. What was missing was anyone in the room who could tell the court it wasn't being met.
Nobody in Spain voted to hand a private company this power. That's the point. It never had to be voted on. It just had to not be stopped.
What actually helps
Beale's speech, the one I quoted in the intro, is a TV segment in a film about how rage gets monetised and defused. Anger by itself is exactly what a system like this absorbs. So, concretely:
Check whether you're affected. bandaancha's live status page lists currently blocked IPs per operator, and hayahora.futbol tracks it in real time. Resolve your domain, compare.
Document it properly. Screenshots aren't enough. Traceroute showing where packets die inside your operator's network, timestamps in UTC, the kickoff time of the parallel match, and a control test over a different connection. That's the difference between "my site was down" and evidence.
Report it. Xataka has a rundown of the available channels.
Consider actually filing. RootedCON and HackBCN provide technical, expert-witness and legal support, including a template claim.
One small claim doesn't fix anything. But "no formal damage claims have reached the courts" is currently one of the strongest sentences available in defence of all this, and it only stays true as long as everyone keeps quietly moving to AWS.
Read that block page one more time. My internet provider wrote it. Not a court, not a regulator - the company I pay for access, explaining why it is cutting me off, and pointing me at a football league's press release instead of at the ruling itself.
On sources
Everything factual here is linked. Where I describe an allegation by a party to the proceedings rather than an established finding, I say so. Where I'm giving an opinion, the heading says so. The ruling is public and linked above, as is LaLiga's own statement of its position - read both rather than trusting my summary.
On use of AI
Claude helped write this article. I also wanted Kimi K3 on NeuralWatt to do a second pass of fact-checking, but couldn't reach it: RC Deportivo were playing Valencia CF, and NeuralWatt is - surprise, surprise - on Cloudflare. Which is to say: the blocks tried to stop me from checking the facts about the blocks.
Yes, I know how to use a VPN. I have one. But split-tunnelling it around my existing Tailscale setup on a Sunday afternoon is not work I signed up for, so someone else can fight their piracy fight. I wrote this article instead.