Skip to content

Posting on mainland Chinese platforms

Assess the risk of reading this page

The environment described here applies to reading this page. Reaching this site from inside mainland China requires circumvention, and the access itself can leave a record. If your situation is sensitive, read on a device outside the jurisdiction, or use a browsing mode that leaves no local trace. If you save it offline, remember the file itself is a record: clear it along with your browsing history afterwards, and keep it out of cloud sync and your photo library.

This page does not argue about whether to post, and does not evaluate anyone's choice. Civil-society work pushes against existing boundaries by definition, and whether a specific action is worth it belongs to the person taking it. What this page does is lay out the cost: what the environment looks like now, where the risk lands, what the established practices actually buy and give up, and which work is already being carried by others.

It is a companion to speaking online from Singapore and Malaysia, which covers a different legal frame in the same region.

The environment

Accounts and identity

Accounts on major mainland platforms bind to a phone number, and the phone number binds to a national ID. That chain has existed for years. Since 2025 there is another layer: the National Online Identity Authentication Public Service took effect on 15 July 2025, built jointly by the Cyberspace Administration and the Ministry of Public Security, issuing a "network number" and "network credential" that a user presents to platforms for real-name verification, nominally on a voluntary basis1. Taobao and Xiaohongshu were among the platforms integrated during the initial rollout.

For anyone publishing, this changes the assumption that a new account is a new identity. As verification consolidates into one public service, the same natural person becomes easier to join across platforms.

How content is handled

Censorship is not one action. At least four operate at once: pre-publication filtering (the message never leaves), post-publication deletion, throttling (the content exists but almost nobody sees it, with no notification to you), and account penalties that can extend to other accounts under the same verified identity.

Citizen Lab's empirical work on WeChat has established several mechanics that cut against common assumptions:

  • Keyword filtering follows the registration origin. Accounts registered with a mainland phone number have censorship enabled, and it persists even after the account is later linked to an international number2.
  • Images are not a safe carrier. WeChat runs two filtering algorithms in parallel, one using OCR to catch text inside images, another matching visual similarity against a blacklist3.
  • Blocking is silent. The sender receives no indication that a message failed to arrive, so you believe it went through3.
  • Content between non-mainland accounts is analyzed too, and that content has been used to train the censorship system applied to mainland users4.

The last point deserves a pause: international users who assume they are outside the system have been supplying its training data.

Tightening since 2025

The target set is widening. Campaigns from 2025 onward have covered "spreading pessimism" and economic rumors alongside the established political categories, reaching trending topics, comment sections, and short video. Circumvention tool availability has declined over the same period. Current blocking conditions are in the mainland China section of cross-border travel and device searches.

Where the risk lands

  • Account level. Suspension, muting, throttling, plus knock-on effects to other accounts tied to the same verified identity.
  • Traceability. Deleted content is not gone. Platform-side records, your own device, cloud backups, and other people's screenshots are all copies. Deleting later limits further spread; it does not recall what already happened.
  • Personal. From a summons and a written undertaking through administrative measures to criminal process. Intensity varies sharply with topic, scale, and timing, and tolerance drops during sensitive periods.
  • Collective. Group administrators carry responsibility for group content. Family members and employers are contacted as a pressure route. Other members of the same group can be affected. Each person who forwards carries their own act.
  • Onward spread. Once others forward, screenshot, or remix your content, scale leaves your control while attribution can still return to the origin. This is routinely underweighted when deciding whether to post at all.

Reach and safety pull against each other

Most people want both "it spreads" and "nothing happens to me." In this environment those goals conflict at four specific points:

What you want What it costs
Ordinary people to believe you Anonymous accounts carry little credibility. Credibility comes from a real name, a track record, existing relationships, which are exactly the exposure
To evade keyword filtering Obfuscated language is hard to read, so only people who already agree decode it, which keeps you inside the bubble
The content to persuade Persuasiveness comes from specific, verifiable detail, and specificity is what points back at you
To reach more people The larger the spread, the closer it comes to the thresholds that trigger enforcement attention

There is no configuration that satisfies all four. The workable move is deciding, per action, which side you are on: preserving a record (prioritize getting the material archived outside the jurisdiction, keep the publisher's profile minimal), persuading specific people (go private and small, give up scale), or maximizing spread (accept higher exposure for the publisher, or route the material to a channel already carrying that risk).

Established practices and what each costs

These are described to make the trade-offs legible, not as an operational guide.

Linguistic and format variation (homophones, character splitting, coded terms, text rendered as images) is the best-known family. It costs readability, which keeps it inside the bubble, and its effectiveness is declining, since the OCR and visual-similarity matching described above already cover most variants. Treating it as reliable protection produces false confidence, and the person acting on that confidence carries the consequence.

Private and small-scale distribution exposes far less than public posting and is the most balanced option on risk against effect, bounded by limited scale and by group administrator liability.

Delay. Scrutiny and attention both peak during a news cycle, so waiting reduces risk at the cost of the timeliness that gives material its reach.

Reframing in officially acceptable terms (consumer rights, public safety, regulatory enforcement) improves survival and reception, at the cost of narrowing the issue until some of it can no longer be said.

Routing to an existing channel. Giving material to an account or outlet that already carries this risk keeps the original source out of view. It is among the lowest-exposure options, provided you trust their operational security and understand that the material itself may carry markers pointing to you. See journalists and source protection on consent and on keeping sources apart.

Archiving outside the jurisdiction before publishing, so a copy survives deletion. Lowest cost, most certain effect, and the subject of the next section.

Talking to people you know

The "with ordinary people" half of the question mostly happens offline and one to one. It is a different situation from public posting, with a different risk structure.

Exposure is far smaller than public posting, though not zero: their handset, their retelling to a third person, their mention of it in a group chat are all routes out, and the only end you control is your own. Think about their position before you start, since their job, family, and political exposure differ from yours, and some people feel burdened by what they are told. One-way persuasion also changes nobody's mind, so when someone signals they don't want the conversation, stop.

A few specifics: - In person beats online, provided you have chosen both the venue and who else is present. Their workplace is unsuitable, and both handsets, the car, and any smart speaker are present too. Don't use WeChat for the conversation or for arranging it, for the reasons in the mechanics section above. - Leave no record of who. Names of people you have talked to belong on no list, including on your own device. - Agree the terms beforehand. Ask them not to raise it in group chats, not to forward, and what to say if asked. This is the cheapest step in the whole scenario and the one with the most certain effect. - Work out in advance how to answer "where did you see this". That question almost always comes, and the answer exposes what you read and what you use to read it. Grounding it in something they can look up themselves is safer than describing your channel. - One person at a time beats broadcasting. Group forwarding puts everyone in the same risk pool and usually works less well.

For the effective half, the reframing described under established practices applies here too: starting from something they already care about, and using material from official outlets or verifiable local facts, works better than citing foreign reporting and exposes less.

Work already being carried

Archiving and research do not have to be re-attempted from scratch by each person at their own risk:

Submitting material to these projects usually preserves it more reliably than reposting it into domestic platforms, at far lower exposure.

What this page does not do

  • No circumvention playbook. Variation techniques change quickly and date badly, and a specific list leads people to overestimate their safety while they, not we, carry the outcome.
  • No judgment of anyone's choice. Whether and how to publish belongs to the person in the situation.
  • No safety guarantee. This describes known mechanisms and observed responses in an environment that keeps changing.

Three things you can do now

  1. Decide which side you're on before acting — preserving a record, persuading specific people, or maximizing spread — because the costs differ
  2. To make material survive, submit it to the archiving projects above. That step also needs circumvention and its exposure has to be counted in, but it is more reliable than reposting into domestic platforms yourself
  3. Save the help contacts below in advance, because there is no time to look them up when it matters

Getting help

  • Access Now Digital Security Helpline — 24/7, multilingual; the first contact for a compromised account, a seized device, or a targeted attack
  • Citizen Lab — device forensics, if you suspect surveillance software
  • If you have already been summoned, told to delete a post, or asked to sign an undertaking, the records are evidence. Don't clear them first; see activists and protest digital safety on preserving material when legal process is plausible

Where to go from here


  1. China: Centralized Internet ID System Officially Launched — US Library of Congress, Global Legal Monitor, July 2025. Translated measures at China Law Translate. Verified 2026-08. 

  2. One App, Two Systems — The Citizen Lab, on keyword filtering being enabled only for mainland-registered accounts and persisting after relinking to an international number. 

  3. How WeChat Filters Images for One Billion Users and (Can't) Picture This 2 — The Citizen Lab, on the OCR and visual-similarity algorithms and on filtering being invisible to the sender. 

  4. We Chat, They Watch — The Citizen Lab, May 2020.