Maintain connectivity via DNS tunneling during total internet outages
This tool allows web access during country-level internet blocks or in unstable network environments. It is a virtual private network (VPN) client and server that hides data inside DNS queries for transmission. Unlike existing tools, it is designed to withstand packet loss and high latency.
Survival strategy during complete blocks
This project was actually used during Iran's 88-day internet shutdown, proving its utility. Unlike standard VPNs that fail when international bandwidth is cut, this tool maintains a connection as long as DNS traffic is allowed. It splits data into small pieces, encrypts them, and transmits them disguised as normal DNS requests. It uses multiple DNS resolvers simultaneously and supports redundant transmission, ensuring data delivery through alternative paths if a specific route is blocked. This structure allows communication with the outside world even in extreme situations where firewalls permit only DNS traffic.
Lightweight protocol and efficiency
It has significantly less overhead than the protocol headers used by existing DNS tunneling tools. It boasts a header size approximately 88% lower than DNSTT and approximately 71% lower than SlipStream, meaning more actual data can be packed into DNS packets. Its proprietary protocol includes retransmission logic (ARQ) to deliver data stably even when packets are lost. It also supports eight built-in load balancing modes to check resolver status in real time and select the optimal path. It is designed to work in environments with very small MTU (Maximum Transmission Unit), making it advantageous in places with many network constraints.
Installation and configuration
On the server side, you must set up A records and NS records that delegate subdomains of your domain to the server IP. An automatic installation script is provided for Linux servers to simplify the complex setup process. Pre-built binaries are available for various platforms, including Windows, macOS, Linux, and Android (Termux). Written in Go, building from source requires Go 1.24 or higher. You must match the encryption key, domain, and resolver list in the configuration files (client_config.toml, server_config.toml), and the client provides a local SOCKS5 proxy (127.0.0.1:18000) by default. It can also be easily deployed in container environments via Docker images.
Things to check before use
This tool is provided for educational and research purposes and does not guarantee suitability for specific purposes or commercial viability. Any legal liability arising from users violating local laws by using this tool rests solely with the user. In particular, in regions where bypassing internet censorship is prohibited, serious civil and criminal disadvantages may occur, so you must review the laws and regulations of the relevant country before use. Additionally, while XOR encryption has low overhead, it has low security; therefore, in environments where security is critical, it is recommended to choose stronger encryption methods such as AES or ChaCha20. If the encryption keys and domain settings of the server and client do not match exactly, the tunnel will not form, so you must carefully verify this during the configuration stage.