awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

17 Repos

Awesome GitHub RepositoriesDNS-over-HTTPS Servers

Runs a DNS-over-HTTPS server so external clients can resolve domain names through encrypted queries.

Distinct from DNS Servers: Distinct from DNS Servers: focuses specifically on serving DNS over HTTPS, not general DNS server functionality.

Explore 17 awesome GitHub repositories matching networking & communication · DNS-over-HTTPS Servers. Refine with filters or upvote what's useful.

Awesome DNS-over-HTTPS Servers GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • pymumu/smartdnsAvatar von pymumu

    pymumu/smartdns

    10,931Auf GitHub ansehen↗

    SmartDNS is a local recursive DNS resolver and server that manages granular query rules, dual-stack networking, and encrypted gateway proxying. It functions as a DNS traffic filter and DNS64 translator, allowing IPv6-only clients to communicate with IPv4 servers. The project distinguishes itself through parallel upstream querying, which sends requests to multiple servers simultaneously to return the response with the lowest network latency. It supports DNS server virtualization, enabling the operation of multiple independent server instances on different ports, each with its own configuration

    Functions as a proxy that encrypts DNS queries using HTTPS, TLS, or QUIC for secure delivery.

    Ccdnsdns-over-https
    Auf GitHub ansehen↗10,931
  • hiddify/configAvatar von hiddify

    hiddify/config

    9,066Auf GitHub ansehen↗

    This project is a centralized management interface and orchestrator for deploying censorship circumvention protocols and stealth proxies. It functions as a network censorship bypass tool that routes traffic through encrypted communication protocols to avoid internet firewalls and regional blocks. The system distinguishes itself through a multi-protocol VPN manager and an automated proxy server orchestrator that handles software updates and system backups. It utilizes content delivery networks to mask origin server identities and implements encrypted DNS over HTTPS to prevent DNS poisoning and

    Implements a DNS-over-HTTPS relay to protect user privacy and prevent DNS poisoning.

    Python
    Auf GitHub ansehen↗9,066
  • ogham/dogAvatar von ogham

    ogham/dog

    6,667Auf GitHub ansehen↗

    Dog is a command-line interface tool and network diagnostic utility used for querying DNS records and resolving domain names. It functions as a DNS query tool for retrieving domain information across various network transport protocols. The tool supports multi-protocol DNS transmission, allowing queries to be sent over UDP, TCP, TLS, and HTTPS. This enables secure DNS communication via encrypted channels to protect privacy and prevent interception. Capabilities include DNS query troubleshooting, record analysis, and network protocol testing to verify name server connectivity. The system prov

    Enables sending DNS queries over UDP, TCP, TLS, and HTTPS to ensure connectivity across diverse networks.

    Rustclientcommand-linedns
    Auf GitHub ansehen↗6,667
  • 0xerr0r/blockyAvatar von 0xERR0R

    0xERR0R/blocky

    6,653Auf GitHub ansehen↗

    Blocky is a stateless DNS proxy that functions as a network-wide ad-blocker and content filter. It operates as a single binary or Docker container with no database or persistent state, accepting DNS queries over UDP, TCP, HTTPS, TLS, QUIC, and HTTP/3 through a unified plugin-based query pipeline. The core of the system is a client-group policy engine that assigns devices to named groups and applies per-group blocklists, allowlists, and upstream resolvers, with all configuration changes applied through hot-reloading without requiring a restart. The project distinguishes itself through its modu

    Ships a DNS-over-HTTPS server that accepts encrypted queries from external clients.

    Goad-blockeradblockadblocker
    Auf GitHub ansehen↗6,653
  • bromite/bromiteAvatar von bromite

    bromite/bromite

    6,277Auf GitHub ansehen↗

    Bromite is a privacy-focused fork of the Chromium browser for Android that blocks advertisements and tracking scripts by default, enforces encrypted HTTPS connections, and prevents browser fingerprinting without requiring any extensions or manual configuration. It applies a patch-based build system to layer privacy and security modifications directly onto the upstream Chromium codebase during compilation, integrating a filter list engine for network-level ad blocking and adding noise to browser APIs to mask device identity. The browser distinguishes itself through comprehensive privacy harden

    Sends DNS queries through encrypted HTTPS connections to a user-specified endpoint.

    adblockadblockingandroid
    Auf GitHub ansehen↗6,277
  • browserworks/waterfoxAvatar von BrowserWorks

    BrowserWorks/waterfox

    5,958Auf GitHub ansehen↗

    Waterfox is a privacy-focused web browser built on a fork of the Gecko engine that removes all telemetry and tracking code while preserving full extension compatibility. It encrypts DNS queries through independent third-party resolvers to prevent centralized monitoring of browsing destinations, and organizes browser tabs into hierarchical parent-child trees with collapsible branches and keyboard-driven navigation. The browser maintains a backward-compatible runtime bridge that supports both legacy XUL-based add-ons and modern WebExtensions simultaneously, allowing users to keep using older or

    Encrypts DNS queries and routes them through independent third-party resolvers to prevent centralized tracking.

    JavaScriptbrowsergeckowaterfox
    Auf GitHub ansehen↗5,958
  • jinwyp/one_click_scriptAvatar von jinwyp

    jinwyp/one_click_script

    5,136Auf GitHub ansehen↗

    Dieses Projekt ist eine Sammlung von Linux-Server-Automatisierungsskripten zur Automatisierung der Installation und Konfiguration von Kern-Serversoftware. Es bietet spezialisierte Tools für das Deployment von Proxy-Servern, die Konfiguration von DNS-Servern, das Management von Container-Infrastruktur und die Optimierung des Linux-Kernels. Die Automatisierungssuite zeichnet sich durch die Integration von Funktionen zur Umgehung von Geo-Restriktionen mittels Proxy-Protokollen und die Implementierung fortgeschrittenen Netzwerk-Tunings aus, wie etwa die Aktivierung der BBR-Staukontrolle zur Verbesserung von Durchsatz und Latenz. Zudem bietet sie distributionsbewusste Automatisierung, die CPU-Architektur und Linux-Distributionen erkennt, um die korrekten Binärversionen und Paketmanager anzuwenden. Die breiteren Fähigkeiten des Projekts umfassen das Container-Setup mittels Docker und Portainer, die Härtung der Serversicherheit durch passwortloses Login und Konfiguration nicht-standardisierter Ports sowie automatisiertes Lifecycle-Management von SSL-Zertifikaten. Darüber hinaus deckt es DNS-Administration mit Ad-Blocking und Split-Tunnel-Routing, DHCP-Zuweisungsmanagement und das Deployment webbasierter Administrationspanels für Benutzer- und Servicemanagement ab.

    Deploys secure DNS servers featuring ad-blocking and encrypted resolution over HTTPS and TLS.

    Shellacmebbrbbrplus
    Auf GitHub ansehen↗5,136
  • sadeghhayeri/greentunnelAvatar von SadeghHayeri

    SadeghHayeri/GreenTunnel

    4,855Auf GitHub ansehen↗

    GreenTunnel is a network utility designed to circumvent deep packet inspection and bypass internet censorship. It functions as a tool that modifies outgoing network packets and encrypts DNS lookups to prevent internet service providers and network filtering systems from detecting and blocking specific web destinations. The project implements an HTTP fragmentation proxy and an HTTPS handshake fragmenter. These components split request headers and TLS handshake records across multiple segments to conceal hostnames and destination server names from inspection systems. The software also includes

    Implements a DNS-over-HTTPS client to securely resolve domain names and prevent ISP interception.

    JavaScript
    Auf GitHub ansehen↗4,855
  • celzero/rethink-appAvatar von celzero

    celzero/rethink-app

    4,580Auf GitHub ansehen↗

    This project is a network security tool providing an application network firewall, a DNS blocklist manager, and a VPN client with multi-hop capabilities. It functions as a traffic controller that allows or blocks internet access for specific applications on a device. The system distinguishes itself through a DNS-over-HTTPS firewall and traffic obfuscation tools that inject random packets to mask communication patterns and bypass regional internet censorship. It utilizes multi-hop routing to hide the origin of network traffic by chaining connections through multiple remote servers. The softwa

    Provides a DNS-over-HTTPS relay to encrypt domain resolution and bypass eavesdropping.

    Kotlinandroidandroid-appandroid-application
    Auf GitHub ansehen↗4,580
  • paulmillr/encrypted-dnsAvatar von paulmillr

    paulmillr/encrypted-dns

    4,415Auf GitHub ansehen↗

    This project is a DNS privacy proxy and resolver that functions as a local bridge, converting plaintext DNS traffic into encrypted requests. It acts as a client for DNS-over-HTTPS and DNS-over-TLS protocols to prevent interception and spoofing of network requests. The system implements network privacy hardening by routing domain lookups through secure tunnels, which reduces the amount of plain text data leaked to internet service providers. It utilizes a profile-based connection management system to map security profiles to specific encrypted endpoints, preventing DNS hijacking and man-in-the

    Routes DNS lookups through HTTPS connections to secure domain resolution against man-in-the-middle attacks.

    JavaScriptcloudflareconfiguration-profiledns
    Auf GitHub ansehen↗4,415
  • timothymiller/cloudflare-ddnsAvatar von timothymiller

    timothymiller/cloudflare-ddns

    4,224Auf GitHub ansehen↗

    Dieses Projekt ist ein Rust-basiertes Netzwerk-Utility und dynamischer DNS-Client, der dazu dient, öffentliche IP-Adressen zu überwachen und automatisch Cloudflare-DNS-Einträge sowie Web Application Firewall (WAF) Zugriffslisten zu aktualisieren. Es identifiziert aktuelle IPv4- und IPv6-Adressen mithilfe einer Kombination aus HTTP-APIs und DNS-over-HTTPS-Anbietern. Das Tool zeichnet sich dadurch aus, dass es sowohl Domain-Einträge als auch WAF-IP-Listen verwaltet, um sicheren Zugriff für Hosts mit wechselnden Internetverbindungen zu gewährleisten. Es enthält einen DNS-Änderungsvorschau-Modus, um Updates zu simulieren, ohne Live-Einträge zu ändern, und nutzt Anycast-Bereichsfilterung, um fehlerhafte Datensatz-Updates aus Anbieter-Adressräumen zu verhindern. Das System handhabt die Zeitplanung über Cron-Ausdrücke oder feste Intervalle und implementiert jitter-basierte API-Anfrage-Timings, um Ratenbegrenzungen zu vermeiden. Es deckt breite Funktionsbereiche ab, einschließlich Dual-Stack-Netzwerkunterstützung, umgebungsbasierter Secret-Injection für Authentifizierungstoken, externer Statusbenachrichtigungen und herzschlagbasierter Gesundheitsüberwachung.

    Identifies current public IPv4 and IPv6 addresses using secure DNS-over-HTTPS providers.

    Rustamd64arm64armv7
    Auf GitHub ansehen↗4,224
  • nextdns/nextdnsAvatar von nextdns

    nextdns/nextdns

    4,072Auf GitHub ansehen↗

    NextDNS ist ein Netzwerk-DNS-Client und Proxy, der als lokaler Resolver, Forwarder und DNS-over-HTTPS-Proxy fungiert. Sein Hauptzweck ist das Routing lokaler Namensauflösungsanfragen an externe Anbieter über verschlüsselten HTTPS-Datenverkehr, um die Privatsphäre zu verbessern und Netzwerkeinschränkungen zu umgehen. Der Dienst zeichnet sich dadurch aus, dass er Client-Identitätsmetadaten – gesammelt via mDNS oder DHCP – in ausgehende Abfragen einbettet, was ein gerätespezifisches Tracking und die Anwendung individueller Filterprofile ermöglicht. Er bietet eine fortschrittliche Routing-Logik, einschließlich Split-Horizon-DNS für den Ausgleich zwischen öffentlicher und privater Auflösung, domänenbasiertes Query-Steering sowie einen Health-Check-Failover-Mechanismus, um den Datenverkehr bei Anbieterausfällen automatisch umzuleiten. Das Projekt deckt umfassend das DNS-Traffic-Management durch TTL-Rewriting und lokale Hosts-Datei-Integration ab sowie die Leistungsoptimierung durch In-Memory-Caching mit automatischer Invalidierung. Es enthält zudem Netzwerkmanagement-Funktionen wie Captive-Portal-Erkennung und Systemzeitsynchronisation zur Sicherstellung der Zertifikatsgültigkeit. Der Dienst kann als deklarative Systemkomponente in NixOS bereitgestellt oder direkt in die Firmware von Heimroutern integriert werden.

    Translates standard UDP DNS requests into encrypted HTTPS traffic to improve privacy and bypass network restrictions.

    Godnsdns-over-https
    Auf GitHub ansehen↗4,072
  • mr-karan/doggoAvatar von mr-karan

    mr-karan/doggo

    4,130Auf GitHub ansehen↗

    doggo is a multi-protocol DNS lookup client, performance analyzer, and diagnostic troubleshooting tool. It functions as a command-line utility for performing DNS queries across various transport protocols, including UDP, TCP, HTTPS, TLS, and QUIC. The project distinguishes itself through a focus on secure and distributed resolution. It implements encrypted DNS standards such as DNS over HTTPS, DNS over QUIC, and DNSCrypt, and provides DNSSEC validation to verify chains of trust for signed domains. Additionally, it can execute queries from global geographic locations via an external API to ana

    Encrypts queries and responses via HTTPS to prevent eavesdropping and manipulation of network traffic.

    Godnsdns-clientdoh
    Auf GitHub ansehen↗4,130
  • serverless-dns/serverless-dnsAvatar von serverless-dns

    serverless-dns/serverless-dns

    3,704Auf GitHub ansehen↗

    This project is a serverless DNS resolver and DNS over HTTPS gateway that translates domain names into IP addresses. It functions as an edge computing DNS filter designed to encrypt queries, prevent tampering, and improve user privacy on browsers and mobile devices. The system distinguishes itself by operating as an edge DNS traffic monitor that logs and analyzes request patterns in real time. It utilizes curated blocklists at the network edge to block malicious domains and trackers. The software provides capabilities for private DNS filtering, network traffic monitoring, and the management

    Functions as a secure gateway that serves DNS queries over HTTPS to prevent tampering.

    JavaScriptadblockcloudflarecloudflare-workers
    Auf GitHub ansehen↗3,704
  • irinesistiana/mosdnsAvatar von IrineSistiana

    IrineSistiana/mosdns

    3,672Auf GitHub ansehen↗

    mosdns is a DNS forwarding server and traffic filter that routes DNS queries to multiple upstream providers. It functions as a rule-based DNS router and a proxy for DNS-over-HTTPS and DNS-over-TLS to ensure secure DNS resolution. The system utilizes a pipeline-based request processing model and rule-based query routing to direct specific domain queries to different upstream servers. It implements pluggable transport layers and forwarding protocols, including HTTPS, TLS, and QUIC, to encrypt traffic and prevent eavesdropping. The project includes capabilities for upstream load balancing to di

    Implements pluggable forwarding protocols including DNS-over-HTTPS, DNS-over-TLS, and QUIC for secure upstream communication.

    Godnsdns-over-httpdns-over-https
    Auf GitHub ansehen↗3,672
  • adguardteam/dnsproxyAvatar von AdguardTeam

    AdguardTeam/dnsproxy

    2,997Auf GitHub ansehen↗

    dnsproxy is an encrypted DNS proxy and traffic router that translates and forwards DNS requests between clients and upstream resolvers. It functions as a server for multiple secure protocols, including DNS-over-HTTPS, DNS-over-TLS, DNS-over-QUIC, and DNSCrypt, to protect queries from eavesdropping and tampering. The project differentiates itself through advanced routing and optimization capabilities. It utilizes a domain-based routing engine to direct queries to specific upstream servers via wildcard rules and employs parallel querying to return responses from the fastest responding network a

    Provides a multi-protocol server supporting DNS-over-HTTPS, TLS, QUIC, and DNSCrypt.

    Godnsdns-over-httpsdns-over-quic
    Auf GitHub ansehen↗2,997
  • tenta-browser/tenta-dnsAvatar von tenta-browser

    tenta-browser/tenta-dns

    1,604Auf GitHub ansehen↗

    Tenta DNS is a recursive and authoritative domain name server implementation written in Go. It provides secure network resolution services by translating human-readable domain names into machine addresses while enforcing cryptographic standards to ensure data privacy and authenticity. The software distinguishes itself through a focus on secure transport and integrity verification. It utilizes encrypted tunnels for upstream communication to prevent eavesdropping and incorporates a validation engine to verify digital signatures on resource records. To manage global traffic, the system supports

    Implements a recursive and authoritative DNS server supporting multiple encrypted transport protocols.

    Go
    Auf GitHub ansehen↗1,604
  1. Home
  2. Networking & Communication
  3. DNS Servers
  4. DNS-over-HTTPS Servers

Unter-Tags erkunden

  • DNS-over-HTTPS Clients2 Sub-TagsClient implementations that wrap DNS queries in HTTPS for secure transmission. **Distinct from DNS-over-HTTPS Servers:** Focuses on the client-side implementation of DoH rather than the server-side hosting.
  • DNS-over-HTTPS RelaysClient-side relays that wrap standard DNS queries into HTTPS requests for remote resolution. **Distinct from DNS-over-HTTPS Servers:** Distinct from DNS-over-HTTPS Servers: implements the relay client logic rather than the server hosting the resolver.
  • Multi-Protocol Encrypted DNS Servers1 Sub-TagDNS servers supporting multiple secure transport protocols like DoH, DoT, DoQ, and DNSCrypt. **Distinct from DNS-over-HTTPS Servers:** Extends single-protocol servers to include a broad suite of encrypted DNS standards.
  • Pluggable Forwarding ProtocolsModular implementations of multiple DNS transport protocols for upstream communication. **Distinct from DNS-over-HTTPS Servers:** Focuses on the ability to swap different forwarding protocols (DoH, DoT, QUIC) rather than just hosting a single protocol server.
  • Secure Resolution DeploymentInstallation of DNS servers supporting encrypted protocols like DoH and DoT with ad-blocking. **Distinct from DNS-over-HTTPS Servers:** Combines the deployment of multiple secure DNS protocols and ad-blocking into a single setup, rather than just providing a DoH server.