5 Repos
Client-side relays that wrap standard DNS queries into HTTPS requests for remote resolution.
Distinct from DNS-over-HTTPS Servers: Distinct from DNS-over-HTTPS Servers: implements the relay client logic rather than the server hosting the resolver.
Explore 5 awesome GitHub repositories matching networking & communication · DNS-over-HTTPS Relays. Refine with filters or upvote what's useful.
This project is a centralized management interface and orchestrator for deploying censorship circumvention protocols and stealth proxies. It functions as a network censorship bypass tool that routes traffic through encrypted communication protocols to avoid internet firewalls and regional blocks. The system distinguishes itself through a multi-protocol VPN manager and an automated proxy server orchestrator that handles software updates and system backups. It utilizes content delivery networks to mask origin server identities and implements encrypted DNS over HTTPS to prevent DNS poisoning and
Implements a DNS-over-HTTPS relay to protect user privacy and prevent DNS poisoning.
Waterfox is a privacy-focused web browser built on a fork of the Gecko engine that removes all telemetry and tracking code while preserving full extension compatibility. It encrypts DNS queries through independent third-party resolvers to prevent centralized monitoring of browsing destinations, and organizes browser tabs into hierarchical parent-child trees with collapsible branches and keyboard-driven navigation. The browser maintains a backward-compatible runtime bridge that supports both legacy XUL-based add-ons and modern WebExtensions simultaneously, allowing users to keep using older or
Encrypts DNS queries and routes them through independent third-party resolvers to prevent centralized tracking.
This project is a network security tool providing an application network firewall, a DNS blocklist manager, and a VPN client with multi-hop capabilities. It functions as a traffic controller that allows or blocks internet access for specific applications on a device. The system distinguishes itself through a DNS-over-HTTPS firewall and traffic obfuscation tools that inject random packets to mask communication patterns and bypass regional internet censorship. It utilizes multi-hop routing to hide the origin of network traffic by chaining connections through multiple remote servers. The softwa
Provides a DNS-over-HTTPS relay to encrypt domain resolution and bypass eavesdropping.
This project is a DNS privacy proxy and resolver that functions as a local bridge, converting plaintext DNS traffic into encrypted requests. It acts as a client for DNS-over-HTTPS and DNS-over-TLS protocols to prevent interception and spoofing of network requests. The system implements network privacy hardening by routing domain lookups through secure tunnels, which reduces the amount of plain text data leaked to internet service providers. It utilizes a profile-based connection management system to map security profiles to specific encrypted endpoints, preventing DNS hijacking and man-in-the
Converts plaintext DNS queries into encrypted DNS-over-HTTPS or DNS-over-TLS requests to prevent interception and spoofing.
NextDNS ist ein Netzwerk-DNS-Client und Proxy, der als lokaler Resolver, Forwarder und DNS-over-HTTPS-Proxy fungiert. Sein Hauptzweck ist das Routing lokaler Namensauflösungsanfragen an externe Anbieter über verschlüsselten HTTPS-Datenverkehr, um die Privatsphäre zu verbessern und Netzwerkeinschränkungen zu umgehen. Der Dienst zeichnet sich dadurch aus, dass er Client-Identitätsmetadaten – gesammelt via mDNS oder DHCP – in ausgehende Abfragen einbettet, was ein gerätespezifisches Tracking und die Anwendung individueller Filterprofile ermöglicht. Er bietet eine fortschrittliche Routing-Logik, einschließlich Split-Horizon-DNS für den Ausgleich zwischen öffentlicher und privater Auflösung, domänenbasiertes Query-Steering sowie einen Health-Check-Failover-Mechanismus, um den Datenverkehr bei Anbieterausfällen automatisch umzuleiten. Das Projekt deckt umfassend das DNS-Traffic-Management durch TTL-Rewriting und lokale Hosts-Datei-Integration ab sowie die Leistungsoptimierung durch In-Memory-Caching mit automatischer Invalidierung. Es enthält zudem Netzwerkmanagement-Funktionen wie Captive-Portal-Erkennung und Systemzeitsynchronisation zur Sicherstellung der Zertifikatsgültigkeit. Der Dienst kann als deklarative Systemkomponente in NixOS bereitgestellt oder direkt in die Firmware von Heimroutern integriert werden.
Translates standard UDP DNS requests into encrypted HTTPS traffic to improve privacy and bypass network restrictions.