masterking32/MasterDnsVPNPublic

Advanced DNS tunneling VPN for censorship bypass, optimized beyond DNSTT and SlipStream with low-overhead ARQ, resolver load balancing, high packet-loss stability and speed.

AI summary: A resilient DNS tunneling VPN designed to bypass total internet blackouts by disguising traffic as normal DNS queries.

Stars
6.9K
+11 today
Forks
789
Watchers
77
Open issues
15
Open PRs
6
Contributors
~16
Commits
1K
Branches
2

GoMITCreated Jan 18, 2026Last push 3d agoLatest release v2026.06.13.234407-7de2476+56 stars this week+61 this month

Star history

since Mar 8, 2026
02K4K6KMar 2026Apr 2026Jun 2026Aug 2026
6.9K stars as of Aug 7, 2026, tracked back to Mar 8, 2026. Historical curve reconstructed from public GitHub event archives, calibrated to the current total.

Contribution activity

commits per day, last 52 weeks
AugSepOctNovDecJanFebMarAprMayJunJulMonWedFri2025-08-02: 0 commits2025-08-03: 0 commits2025-08-04: 0 commits2025-08-05: 0 commits2025-08-06: 0 commits2025-08-07: 0 commits2025-08-08: 0 commits2025-08-09: 0 commits2025-08-10: 0 commits2025-08-11: 0 commits2025-08-12: 0 commits2025-08-13: 0 commits2025-08-14: 0 commits2025-08-15: 0 commits2025-08-16: 0 commits2025-08-17: 0 commits2025-08-18: 0 commits2025-08-19: 0 commits2025-08-20: 0 commits2025-08-21: 0 commits2025-08-22: 0 commits2025-08-23: 0 commits2025-08-24: 0 commits2025-08-25: 0 commits2025-08-26: 0 commits2025-08-27: 0 commits2025-08-28: 0 commits2025-08-29: 0 commits2025-08-30: 0 commits2025-08-31: 0 commits2025-09-01: 0 commits2025-09-02: 0 commits2025-09-03: 0 commits2025-09-04: 0 commits2025-09-05: 0 commits2025-09-06: 0 commits2025-09-07: 0 commits2025-09-08: 0 commits2025-09-09: 0 commits2025-09-10: 0 commits2025-09-11: 0 commits2025-09-12: 0 commits2025-09-13: 0 commits2025-09-14: 0 commits2025-09-15: 0 commits2025-09-16: 0 commits2025-09-17: 0 commits2025-09-18: 0 commits2025-09-19: 0 commits2025-09-20: 0 commits2025-09-21: 0 commits2025-09-22: 0 commits2025-09-23: 0 commits2025-09-24: 0 commits2025-09-25: 0 commits2025-09-26: 0 commits2025-09-27: 0 commits2025-09-28: 0 commits2025-09-29: 0 commits2025-09-30: 0 commits2025-10-01: 0 commits2025-10-02: 0 commits2025-10-03: 0 commits2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 4 commits2026-01-19: 0 commits2026-01-20: 1 commit2026-01-21: 10 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 4 commits2026-01-25: 7 commits2026-01-26: 7 commits2026-01-27: 2 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 14 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 1 commit2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 7 commits2026-03-02: 26 commits2026-03-03: 9 commits2026-03-04: 16 commits2026-03-05: 26 commits2026-03-06: 19 commits2026-03-07: 29 commits2026-03-08: 11 commits2026-03-09: 36 commits2026-03-10: 13 commits2026-03-11: 22 commits2026-03-12: 33 commits2026-03-13: 28 commits2026-03-14: 24 commits2026-03-15: 3 commits2026-03-16: 22 commits2026-03-17: 17 commits2026-03-18: 30 commits2026-03-19: 76 commits2026-03-20: 42 commits2026-03-21: 32 commits2026-03-22: 30 commits2026-03-23: 20 commits2026-03-24: 17 commits2026-03-25: 48 commits2026-03-26: 16 commits2026-03-27: 0 commits2026-03-28: 28 commits2026-03-29: 17 commits2026-03-30: 17 commits2026-03-31: 38 commits2026-04-01: 12 commits2026-04-02: 0 commits2026-04-03: 43 commits2026-04-04: 3 commits2026-04-05: 15 commits2026-04-06: 2 commits2026-04-07: 46 commits2026-04-08: 12 commits2026-04-09: 3 commits2026-04-10: 0 commits2026-04-11: 29 commits2026-04-12: 2 commits2026-04-13: 6 commits2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 2 commits2026-04-17: 0 commits2026-04-18: 3 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 0 commits2026-04-22: 0 commits2026-04-23: 0 commits2026-04-24: 1 commit2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 10 commits2026-05-05: 0 commits2026-05-06: 0 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 1 commit2026-05-10: 8 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 0 commits2026-05-20: 0 commits2026-05-21: 0 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 0 commits2026-05-26: 0 commits2026-05-27: 0 commits2026-05-28: 0 commits2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 1 commit2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 0 commits2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 0 commits2026-06-09: 4 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 0 commits2026-06-13: 1 commit2026-06-14: 6 commits2026-06-15: 1 commit2026-06-16: 0 commits2026-06-17: 0 commits2026-06-18: 0 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 0 commits2026-06-23: 0 commits2026-06-24: 0 commits2026-06-25: 0 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 0 commits2026-06-30: 0 commits2026-07-01: 0 commits2026-07-02: 0 commits2026-07-03: 0 commits2026-07-04: 0 commits2026-07-05: 0 commits2026-07-06: 1 commit2026-07-07: 0 commits2026-07-08: 0 commits2026-07-09: 0 commits2026-07-10: 0 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 0 commits2026-07-14: 0 commits2026-07-15: 0 commits2026-07-16: 0 commits2026-07-17: 0 commits2026-07-18: 0 commits2026-07-19: 7 commits2026-07-20: 0 commits2026-07-21: 0 commits2026-07-22: 0 commits2026-07-23: 0 commits2026-07-24: 0 commits2026-07-25: 0 commits2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 0 commits2026-07-29: 0 commits2026-07-30: 0 commits2026-07-31: 0 commits2026-08-01: 0 commits
1,021 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Very active

    1,021 commits in 52 weeks

  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

What MasterDnsVPN does

MasterDnsVPN is a circumvention tool built specifically for environments where international bandwidth is completely severed, not just filtered. It works by encrypting and splitting internet traffic into small packets and wrapping them inside standard DNS queries. By routing these queries through multiple resolvers, it bypasses firewalls that only allow local DNS traffic. This allows users to maintain a connection to the global internet even during a complete physical disconnect from outside networks.

Users in highly censored regions, activists, and privacy advocates facing extreme network restrictions. Requires a basic understanding of server setup and DNS record management (A and NS records) to deploy the server component.

  • DNS tunneling: Disguises encrypted data fragments as standard, legitimate DNS queries to evade deep packet inspection.
  • Multi-resolver routing: Uses various DNS resolvers to prevent the connection from relying on a single blockable path.
  • High resilience: Proven to work during extreme internet blackouts where standard VPNs and proxies fail entirely.
  • Automated server setup: Includes bash scripts for quick deployment on Linux servers without complex manual configuration.
  • MTU optimization: Encourages short domain names to maximize data payload space within DNS request limits.

Where teams use it

Bypassing extreme censorship

Essential for users in regions experiencing total internet blackouts or extreme national intranet isolation.

Maintaining critical communications

Allows journalists, activists, and citizens to access global news and messaging platforms during network shutdowns.

Circumventing captive portals

Can be used to access the internet on restricted public Wi-Fi networks that only permit DNS resolution.

Network administration

Useful for testing network configurations and the strictness of firewall rules regarding DNS traffic.

Getting started: bash <(curl -fsSL https://raw.githubusercontent.com/masterking32/MasterDnsVPN/main/install.sh)

README

main branch

MasterDnsVPN Project 🔐

| 🇮🇷 فارسی | 🇬🇧 English | 🇷🇺 Русский | 🇨🇳 中文 | 🇪🇸 Español | 🇮🇹 Italiano |

MasterDnsVPN is a scientific and research-oriented project for carrying TCP traffic through DNS queries and responses. In broad goal, it is similar to projects such as DNSTT or SlipStream, but it follows a fundamentally different structure and implementation approach. This system is designed around compatibility with many resolver behaviors and harsh network conditions, with the goal of preserving the highest possible stability and data delivery even in the worst cases.

Ask DeepWiki

masterking32%2FMasterDnsVPN | Trendshift masterking32%2FMasterDnsVPN | Trendshift masterking32%2FMasterDnsVPN | Trendshift masterking32%2FMasterDnsVPN | Trendshift

📊 MasterDnsVPN Compared with Similar Projects

Feature SlipStream DNSTT MasterDnsVPN
Protocol type Advanced DNS tunnel Classic DNS tunnel Advanced DNS tunnel / VPN
Transport protocol QUIC KCP + Noise Custom protocol + ARQ
Transport header overhead 🟠 ~24B 🔴 ~59B 🟢 ~5–7B
≈88% lower than DNSTT
≈71% lower than SlipStream
Encryption style TLS 1.3 (inside QUIC) Noise (Curve25519) AES / ChaCha20 / XOR (if XOR is used: lightweight with lower security and no extra overhead)
Architecture Unified (QUIC handles everything) Multi-layered (KCP + SMUX + Noise) 🟢 Lightweight custom design optimized for DNS
Speed 🟡 High (up to ~5× faster than DNSTT) 🔴 Medium 🟢 Faster than others
Up to ~9× faster than DNSTT
Up to ~3.6× faster than SlipStream
Stability under packet loss 🟡 Good 🟠 Medium 🟢 Very high (Multipath + ARQ)
Multi-resolver support Yes (multipath) Yes — advanced (multi-resolver + duplication)
Resilience under heavy censorship Good Medium Very strong (a core project goal)
Setup complexity Medium Simple Easier installation
More complex only if you heavily customize advanced settings
SOCKS5 support Yes Yes Optimized for SOCKS5 / SOCKS4 with reduced SOCKS overhead
Shadowsocks support Indirectly: TCP Forwarding mode can carry TCP-based protocols
e.g. Shadowsocks, VLESS/VMess, etc.
Real multipath Yes (QUIC multipath) Yes (multi-resolver + duplication)
Adaptive routing Limited Advanced (latency/loss based)
Design goal High speed and efficiency Simplicity and stability Surviving the harshest networks — stability, speed, and efficiency
Implementation language Rust Go Main version is Go
Legacy Python version also exists
Built-in balancer 🔴 🟢 (8 built-in balancing modes)
Duplication system Yes — increases traffic to improve reliability (configurable or can be disabled)
MTU tolerance Better than DNSTT - Works even with very small MTU because protocol overhead is very low
Failover system
Download speed 10MB (Local) 🟡 0.978s 🔴 2.492s 🟢 0.270s
Upload speed 10MB (Local) 🟡 3.249s 🔴 16.207s 🟢 1.746s
Resolver health checks and auto-disable
Background reactivation of healthy resolvers
Local DNS service on client (to reduce DNS hijacking) ✅ (with strong DNS caching)
DNS resolving through SOCKS5 ✅ (with DNS caching)
Fine-grained professional configuration 🟠 🟠 🟢 Almost every subsystem is configurable
No external helper software required 🟢 No extra software is required; if needed, you can still combine it with SOCKS or tools such as Shadowsocks or OpenVPN

❌ Disclaimer

MasterDnsVPN is provided as an educational and research project only.

  • Provided without warranty: This software is provided “AS-IS”, without any express or implied warranty, including merchantability, fitness for a particular purpose, or non-infringement.
  • Limitation of liability: The developers and contributors of this project accept no responsibility for any direct, indirect, incidental, consequential, or other damages arising from the use of this software or the inability to use it.
  • User responsibility: Using this project outside test environments may disrupt or damage network behavior. The user alone is responsible for all consequences of installation, configuration, and use.
  • Legal compliance: Using this project to bypass local laws may result in civil or criminal consequences. Please review the laws and regulations of your country before use. The developers accept no responsibility for violations of local, national, or international laws by users.
  • License terms: Use, copying, distribution, or modification of this software is governed by the license in the LICENSE file of this repository. Any use outside those terms is prohibited.

Announcement and Support Channel 📢

For the latest news, releases, and project updates, follow our Telegram channel: Telegram Channel


If you like this project, please support it by starring it on GitHub (⭐). It helps the project get discovered.


Optional Financial Support 💸

  • TON network:

masterking32.ton

  • EVM-compatible networks (ETH and compatible chains):

0x517f07305D6ED781A089322B6cD93d1461bF8652

  • TRC20 network (TRON):

TLApdY8APWkFHHoxebxGY8JhMeChiETqFH

Every contribution and every piece of feedback is appreciated. Support directly helps ongoing development and improvement.


Key Features and Advantages ✨

A brief overview of the main capabilities of MasterDnsVPN:

  • Censorship resistance and harsh-network survivability: 🛡️ Designed to work on filtered networks, unstable links, and strict MTU environments.
  • Lightweight custom protocol: 🔄 Uses a custom protocol with retransmission logic to reduce overhead and increase usable DNS payload.
  • Multipath and packet duplication: 📡 Sends traffic through multiple paths and supports selective duplication to increase delivery probability on unstable networks.
  • Smart resolver selection and health checks: ⚡ Selects resolvers based on quality and health, and manages problematic resolvers automatically.
  • MTU discovery and synchronization: 🧰 Detects the practical MTU of working paths and aligns around it to reduce fragmentation and improve stability.
  • SOCKS5 / SOCKS4 support and optimization: 🧦 Optimized local proxy handling for common applications.
  • Packed control blocks and lower control overhead: 📦 Groups ACK/control traffic together to reduce control chatter.
  • Optional compression and request packing: 🗜️ Reduces request counts and improves efficiency under small-MTU conditions.
  • Flexible encryption: 🔐 Supports multiple encryption methods to balance speed and security.
  • Optional client-side local DNS and caching: 📛 Can expose a local DNS service, reduce latency, and limit hijacking opportunities.
  • Scalable resource control: ⚙️ Can run on small servers or be tuned for heavier loads.

This list is only a high-level summary. The related sections below explain each area in more detail.


🌐 Battle-Tested During a Total Internet Blackout

MasterDnsVPN isn't just a theoretical project. It is battle-tested and proven to work in environments where the global internet is completely severed.

Recently, during the 88-day internet blackout in Iran, authorities didn't just block VPNs or filter websites—they completely pulled the plug on international bandwidth. With 99% of the connection to the outside world physically cut off, users were trapped inside a closed, local intranet.

Standard circumvention tools are useless when there is no international internet to connect to. Yet, during this massive shutdown, MasterDnsVPN stood out as one of the very few lifelines that actually kept users connected to the global web.

How did it survive a total shutdown? Instead of acting like a standard VPN, MasterDnsVPN relies on smart DNS tunneling techniques to pierce through the blackout:

  • Multiple Resolvers: It routes traffic through various DNS resolvers, ensuring the connection never relies on a single, easily blockable path.
  • Encryption & Data Splitting: It encrypts your data and breaks it down into tiny, scattered pieces.
  • Disguised as Legitimate Traffic: It wraps these data pieces inside standard, perfectly normal DNS queries.
  • Bypassing Local Traps: Because the traffic looks exactly like basic, everyday DNS requests, firewalls allow it through. The data gets resolved and reaches the outside world—even if the network forces you to use their own restricted, government-controlled local resolvers.

This exact combination is what allowed MasterDnsVPN to maintain a stable connection when the outside world was completely blocked.


Setup and Getting Started 🧑‍💻

Section 1: 🖥️ Server Setup

Section 1.1: 🌐 Domain Setup and Preparation (Prerequisite)

To receive DNS requests directly on your server, you must delegate a subdomain to it. In short, create two records: one A record that points to your server IP, and one NS record that delegates the tunnel subdomain to that A record.

Step 1.1.1: 🅰️ Create an A Record (Server Address)

  • Type: A
  • Name: a short name such as ns
  • Value: your server IPv4 address

Example: ns.example.com -> 1.2.3.4

Cloudflare note: if the domain uses Cloudflare, open the DNS page and click the cloud icon next to the A record so it becomes gray (DNS only). It must not remain proxied.

Step 1.1.2: 🏷️ Create an NS Record (Delegate the Subdomain)

  • Type: NS
  • Name: the tunnel subdomain, for example v
  • Value / Target: ns.example.com

Example: v.example.com -> ns.example.com

Cloudflare note: add the NS record normally. Cloudflare does not proxy NS records, but make sure the ns A record is already set to DNS only.

Section 1.1.3: 💡 A Short Note About MTU

Shorter domain names leave more space for actual data inside each DNS request. For better throughput, keep names short. If you use Cloudflare, still keep the relevant records in DNS only mode.


Section 1.2: 🐧 Quick Linux Server Installation

Step 1.2.1: Automatic Installation (Script)

If you want to deploy the server on Linux, the easiest method is the automatic installer script. Run this command on the server:

bash <(curl -Ls https://raw.githubusercontent.com/masterking32/MasterDnsVPN/main/server_linux_install.sh)

The script handles installation and configuration automatically. When it finishes, the server starts and the encryption key is shown in the terminal log and also written to encrypt_key.txt next to the executable. Keep this key safe.

Step 1.2.2: Important Notes After Installation

  • During installation, you will be asked for a domain. It must be the same delegated subdomain you configured in the NS record, for example v.example.com.
  • After creating DNS records, wait for propagation. This may take from a few minutes to several hours, and in some cases up to 48 hours depending on TTL and the DNS provider.
  • To verify the DNS setup, you can use tools such as dig or nslookup, for example dig v.example.com NS or nslookup -type=ns v.example.com. For a direct query to the new nameserver: dig @ns.example.com v.example.com A.
  • If the server firewall is enabled, allow UDP port 53. Example for ufw:
sudo ufw allow 53/udp
sudo ufw reload

For firewalld:

sudo firewall-cmd --add-port=53/udp --permanent
sudo firewall-cmd --reload
  • If port 53 is already occupied by another service, such as systemd-resolved, see the troubleshooting section “Fixing Port 53 Already in Use”.
  • The encryption key (encrypt_key.txt) is shown after installation. Copy it and store it safely because the client needs it to connect.

Section 2: 🚀 Installation and Launch (Client and Server)

You can install and run this project in two ways:

  1. Use the prebuilt binaries (recommended for most users)
  2. Run directly from source with Go (recommended for developers)

Section 2.1: Use Prebuilt Releases (✅ Recommended)

For convenience, prebuilt client and server binaries are published in the release page. Download the correct archive for your operating system and extract it.

💡 Note: Release archives usually include the binary plus sample configuration files.

Client Download Links 📥

Operating System Architecture Suitable For Direct Download
Windows 🪟 AMD64 (64-bit) Windows 10 and 11 Download Windows Client ⬇️
Windows 🪟 x86 (32-bit) Older 32-bit Windows systems Download Windows x86 Client ⬇️
Windows 🪟 ARM64 Windows on ARM devices Download Windows ARM64 Client ⬇️
macOS 🍎 ARM64 Apple Silicon Macs (M1 / M2 / M3) Download macOS Client ⬇️
macOS 🍎 AMD64 Intel Macs Download macOS Intel Client ⬇️
Linux 🐧 AMD64 (64-bit) Modern distributions (Ubuntu 22.04+, Debian 12+) Download Linux Client ⬇️
Linux 🐧 x86 (32-bit) Older 32-bit Linux systems Download Linux x86 Client ⬇️
Linux (Legacy) 🐧 AMD64 (64-bit) Older distributions (Ubuntu 20.04, Debian 11) Download Linux Legacy Client ⬇️
Linux (Legacy) 🐧 ARM64 Older ARM64 Linux systems that need broader compatibility Download Linux Legacy ARM64 Client ⬇️
Linux (ARM) 🐧 ARM64 ARM servers, Raspberry Pi, and similar boards Download Linux ARM Client ⬇️
Linux (ARM) 🐧 ARMv7 32-bit ARM boards and older embedded Linux devices Download Linux ARMv7 Client ⬇️
Linux (ARM) 🐧 ARMv6 Older ARM boards and lightweight Linux devices Download Linux ARMv6 Client ⬇️
Linux (ARM) 🐧 ARMv5 Very old ARM devices and embedded Linux systems Download Linux ARMv5 Client ⬇️
Linux 🐧 RISCV64 RISC-V Linux boards and servers Download Linux RISCV64 Client ⬇️
Linux (MIPS) 🐧 MIPS Big-endian MIPS Linux and router platforms Download Linux MIPS Client ⬇️
Linux (MIPS) 🐧 MIPSLE Little-endian MIPS Linux and router platforms Download Linux MIPSLE Client ⬇️
Linux (MIPS) 🐧 MIPS64 64-bit big-endian MIPS Linux systems Download Linux MIPS64 Client ⬇️
Linux (MIPS) 🐧 MIPS64LE 64-bit little-endian MIPS Linux systems Download Linux MIPS64LE Client ⬇️
Termux / Android 📱 ARM64 Modern Android phones running Termux Download Termux ARM64 Client ⬇️
Termux / Android 📱 ARMv7 Older Android phones running 32-bit Termux environments Download Termux ARMv7 Client ⬇️

Server Download Links 📤

(Use these if you do not want the automated Linux installer.)

Operating System Architecture Suitable For Direct Download
Windows 🪟 AMD64 (64-bit) Windows Server, Windows 10 and 11 Download Windows Server ⬇️
Windows 🪟 x86 (32-bit) Older 32-bit Windows systems Download Windows x86 Server ⬇️
Windows 🪟 ARM64 Windows on ARM devices Download Windows ARM64 Server ⬇️
Linux 🐧 AMD64 (64-bit) Ubuntu 22.04+, Debian 12+ servers Download Linux Server ⬇️
Linux 🐧 x86 (32-bit) Older 32-bit Linux systems Download Linux x86 Server ⬇️
Linux (Legacy) 🐧 AMD64 (64-bit) Older servers (Ubuntu 20.04, Debian 11) Download Linux Legacy Server ⬇️
Linux (Legacy) 🐧 ARM64 Older ARM64 Linux systems that need broader compatibility Download Linux Legacy ARM64 Server ⬇️
Linux (ARM) 🐧 ARM64 ARM servers Download Linux ARM Server ⬇️
Linux (ARM) 🐧 ARMv7 32-bit ARM servers and embedded Linux devices Download Linux ARMv7 Server ⬇️
Linux (ARM) 🐧 ARMv6 Older ARM boards and lightweight Linux devices Download Linux ARMv6 Server ⬇️
Linux (ARM) 🐧 ARMv5 Very old ARM devices and embedded Linux systems Download Linux ARMv5 Server ⬇️
Linux 🐧 RISCV64 RISC-V Linux boards and servers Download Linux RISCV64 Server ⬇️
Linux (MIPS) 🐧 MIPS Big-endian MIPS Linux and router platforms Download Linux MIPS Server ⬇️
Linux (MIPS) 🐧 MIPSLE Little-endian MIPS Linux and router platforms Download Linux MIPSLE Server ⬇️
Linux (MIPS) 🐧 MIPS64 64-bit big-endian MIPS Linux systems Download Linux MIPS64 Server ⬇️
Linux (MIPS) 🐧 MIPS64LE 64-bit little-endian MIPS Linux systems Download Linux MIPS64LE Server ⬇️
macOS 🍎 ARM64 Apple Silicon Macs Download macOS Server ⬇️
macOS 🍎 AMD64 Intel Macs Download macOS Intel Server ⬇️
Termux / Android 📱 ARM64 Modern Android / Termux environments Download Termux ARM64 Server ⬇️
Termux / Android 📱 ARMv7 Older Android / 32-bit Termux environments Download Termux ARMv7 Server ⬇️

Section 2.2: 📦 MasterDnsVPN Docker Image


Section 2.2.1: ⚠️ Overview

This Docker image runs the MasterDnsVPN server in a containerized environment and supports multi-architecture builds.

It automatically:

  • Boots a default configuration if none exists
  • Injects your domain on first startup
  • Stores persistent data in /data

Section 2.2.2: 🖥 Supported Architectures

  • linux/amd64
  • linux/arm/v5
  • linux/arm/v7
  • linux/arm64/v8
  • linux/mips64le

Section 2.2.3: 🚀 Quick Start

Run the container with Docker:

docker run -d \
  --name masterdnsvpn \
  --restart unless-stopped \
  -e DOMAIN=v.example.com \
  -v $(pwd)/data:/data \
  -p 53:53/tcp \
  -p 53:53/udp \
  ghcr.io/masterking32/masterdnsvpn:latest

Section 2.2.4: 🧪 Example with docker-compose

services:
  masterdnsvpn:
    image: ghcr.io/masterking32/masterdnsvpn:latest
    restart: unless-stopped
    environment:
      - DOMAIN=v.example.com
    volumes:
      - ./data:/data
    ports:
      - "53:53/tcp"
      - "53:53/udp"

Section 2.2.5: ⚙️ Required Environment Variables

Variable Description
DOMAIN Your DNS domain (required on first run)

⚠️ If DOMAIN is not set on first boot, the container will stop with an error.


Section 2.2.6: 📁 Persistent Data

Stored in /data:

  • server_config.toml
  • encrypt_key.txt

You can mount it as volume:

-v ./data:/data

Section 2.2.7: 🔧 MikroTik / RouterOS Usage

For MikroTik containers:

Example:

/container mounts
add dst=/data list=MasterDnsVPN src=/containers/mounts/MasterDnsVPN

/container envs
add key=DOMAIN list=MasterDnsVPN value=v.example.com

/container add check-certificate=no dns=1.1.1.1 envlists=MasterDnsVPN hostname=MasterDnsVPN interface=MasterDnsVPN layer-dir="" mountlists=MasterDnsVPN name=MasterDnsVPN remote-image=ghcr.io/masterking32/masterdnsvpn:latest root-dir=/containers/data/MasterDnsVPN start-on-boot=yes

Section 2.2.8: 📌 Notes

  • DNS port 53 is required (UDP/TCP)
  • Do NOT run another DNS service on the same host
  • Designed for production use but still lightweight
  • No systemd or host modifications required

Section 2.3: 🪟 Preparing and Running the Client on Windows

  • After downloading the Windows package, extract it.
  • Open client_config.toml with a text editor such as Notepad.
  • Replace the default values with your real domain, encryption key, and resolver list.
  • Run the client executable.
  • Configure your browser or app to use the local SOCKS5 proxy at 127.0.0.1:18000 unless you changed the defaults.

Section 2.4: 🐧 Preparing and Running on Linux / macOS

After downloading the package on Linux:

sudo apt update
sudo apt install unzip nano

Extract the archive:

unzip MasterDnsVPN_Client_Linux_AMD64.zip
ls

Give execute permission if needed:

chmod +x MasterDnsVPN_Client_Linux_AMD64
chmod +x MasterDnsVPN_Server_Linux_AMD64

Edit the configuration:

nano client_config.toml
nano server_config.toml

Then run:

./MasterDnsVPN_Client_Linux_AMD64
./MasterDnsVPN_Server_Linux_AMD64

Section 2.5: 🧑‍💻 Run Directly from Source (Go)

⚠️ This section is intended for developers or users who want to run the current Go source directly.

Prerequisite

  • Go 1.24 or newer

Build from source

git clone https://github.com/masterking32/MasterDnsVPN.git
cd MasterDnsVPN

go build -o masterdnsvpn-client ./cmd/client
go build -o masterdnsvpn-server ./cmd/server

On Windows:

git clone https://github.com/masterking32/MasterDnsVPN.git
cd MasterDnsVPN

go build -o masterdnsvpn-client.exe .\cmd\client
go build -o masterdnsvpn-server.exe .\cmd\server

Create config files

On Linux and macOS:

cp client_config.toml.simple client_config.toml
cp server_config.toml.simple server_config.toml
cp client_resolvers.simple client_resolvers.txt

On Windows:

Copy-Item client_config.toml.simple client_config.toml
Copy-Item server_config.toml.simple server_config.toml
Copy-Item client_resolvers.simple client_resolvers.txt

Run the server and client

./masterdnsvpn-server -config server_config.toml
./masterdnsvpn-client -config client_config.toml

On Windows:

.\masterdnsvpn-server.exe -config server_config.toml
.\masterdnsvpn-client.exe -config client_config.toml

Command-line parameters

Both binaries support these arguments:

Parameter Description
-config Path to the configuration file
-log Optional path to a log file
-version Print version and exit

Example:

./masterdnsvpn-server -config server_config.toml -log server.log
./masterdnsvpn-client -config client_config.toml -log client.log

Section 3: Configuration Files and Structure 🛠️

Section 3.1: Important Project Files 📂

File Purpose
client_config.toml Main client configuration
server_config.toml Main server configuration
client_resolvers.txt Resolver list
encrypt_key.txt Shared server-side encryption key
client_config.toml.simple Full sample client config for the current Go version
server_config.toml.simple Full sample server config for the current Go version

Accepted formats in client_resolvers.txt:

  • IP
  • IP:PORT
  • CIDR
  • CIDR:PORT

Example:

8.8.8.8
1.1.1.1:53
9.9.9.0/24
208.67.222.0/24:5353

Section 3.2: Quick Client Checklist 🚀

These items are required on the client:

  1. ENCRYPTION_KEY must match the content of the server’s encrypt_key.txt
  2. DOMAINS must match the server domain
  3. client_resolvers.txt must contain working resolvers
  4. For normal use, keep PROTOCOL_TYPE = "SOCKS5"

Section 3.3: Quick Server Checklist ⚙️

These settings are critical on the server:

  1. Set DOMAIN to your delegated tunnel domain
  2. DATA_ENCRYPTION_METHOD must match the client
  3. ENCRYPTION_KEY_FILE defines the path to the server key file
  4. If you want direct outbound connections, keep USE_EXTERNAL_SOCKS5 = false
  5. If you want to chain through an upstream SOCKS5 proxy, set USE_EXTERNAL_SOCKS5 = true and fill FORWARD_IP / FORWARD_PORT

Section 3.4: 📘 Client Configuration Variables (client_config.toml)

3.4.1) 🧭 Tunnel Identity and Security

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
PROTOCOL_TYPE "SOCKS5" "SOCKS5" or "TCP" Chooses the local service mode exposed by the client.
SOCKS5 is the default and recommended mode for normal use.
TCP is useful when you want to forward traffic to one fixed remote target instead of giving applications a SOCKS proxy.
DOMAINS ["v.example.com"] Non-empty list of strings These are the tunnel domains used to build DNS requests.
Every domain here must belong to the same tunnel you configured on the server.
If this list is wrong, the client may build valid DNS queries that the server will simply ignore.
DATA_ENCRYPTION_METHOD 1 0..5 Must match the server.
0=None, 1=XOR, 2=ChaCha20, 3=AES-128-GCM, 4=AES-192-GCM, 5=AES-256-GCM.
XOR is lightweight but weaker. AEAD modes are stronger but have more overhead.
ENCRYPTION_KEY "" String Shared secret used by the client codec.
This must be exactly the same as the server-side encryption key.
If the key is wrong, packets may be parsed as garbage and the tunnel will not work.

3.4.2) 🧦 Local Proxy

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
LISTEN_IP "127.0.0.1" Valid IP string Address where the client listens for local proxy users.
Use 127.0.0.1 for normal local-only usage.
If some applications prefer IPv6 localhost on your system, using localhost can be a better local-only choice.
Use 0.0.0.0 only if you want to share the proxy on the network and understand the security implications.
LISTEN_PORT 18000 0..65535 Port for the local proxy.
Your applications must use this port to send traffic into the tunnel.
SOCKS5_AUTH false true/false Enables username/password authentication on the local SOCKS5 proxy.
If you bind to 0.0.0.0, enabling this is strongly recommended.
SOCKS5_USER "master_dns_vpn" Up to 255 bytes Username for the local SOCKS5 proxy.
Used only if SOCKS5_AUTH=true.
SOCKS5_PASS "master_dns_vpn" Up to 255 bytes Password for the local SOCKS5 proxy.
Used only if SOCKS5_AUTH=true.

3.4.3) 📛 Local DNS

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
LOCAL_DNS_ENABLED false true/false If enabled, the client exposes a local DNS service and can resolve DNS through the tunnel.
This is useful for reducing DNS hijacking or when you want applications to use the tunnel for DNS as well.
LOCAL_DNS_IP "127.0.0.1" Valid IP string Bind address for the local DNS listener.
LOCAL_DNS_PORT 53 0..65535 Port of the local DNS service.
Port 53 is standard, but on some systems it may already be used by another service.
LOCAL_DNS_CACHE_MAX_RECORDS 5000 If <1, fallback applies Maximum number of local DNS cache records.
A larger value reduces repeated DNS lookups but uses more memory.
LOCAL_DNS_CACHE_TTL_SECONDS 28800.0 If <=0, fallback applies How long successful DNS records stay in the local cache.
LOCAL_DNS_PENDING_TIMEOUT_SECONDS 300.0 If <=0, fallback applies If a local DNS query is in progress, follower queries can wait for it instead of launching another upstream request.
This value defines how long they may wait.
LOCAL_DNS_CACHE_PERSIST_TO_FILE true true/false If enabled, the local DNS cache can be written to disk for reuse between runs.
LOCAL_DNS_CACHE_FLUSH_INTERVAL_SECONDS 60.0 If <=0, fallback applies How often the persisted local DNS cache is flushed to disk.
DNS_RESPONSE_FRAGMENT_TIMEOUT_SECONDS 10.0 If <=0, fallback applies How long the client waits for missing DNS tunnel response fragments before giving up.

3.4.4) ⚡ Resolver Selection, Duplication, Health, and Failover

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
RESOLVER_BALANCING_STRATEGY 2 0..8 Chooses how resolvers are selected.
0/2 = Round Robin, 1 = Random, 3 = Least Loss, 4 = Lowest Latency, 5 = Hybrid Score, 6 = Loss Then Latency, 7 = Least Loss Top Random, 8 = Least Loss Top Round Robin.
The hybrid mode uses a weighted combined score. The loss-then-latency mode first shortlists by loss, then prefers lower latency inside that tier, and rotates among near-equal top candidates. The top-random mode picks randomly from the best loss tier so load does not stick to one resolver. The top-round-robin mode cycles through the same top loss tier with deterministic rotation.
PACKET_DUPLICATION_COUNT 2 clamp to valid range in code Normal outgoing packet duplication count.
Higher values increase traffic cost but improve survivability on weak links.
SETUP_PACKET_DUPLICATION_COUNT 2 clamp to valid range in code Similar to PACKET_DUPLICATION_COUNT, but used for setup-sensitive packets such as stream creation and other critical control events.
STREAM_RESOLVER_FAILOVER_RESEND_THRESHOLD 2 If <1, fallback applies If a stream accumulates repeated resend pressure on the same preferred resolver, the client may fail over that stream to another resolver.
This threshold controls how quickly that happens.
STREAM_RESOLVER_FAILOVER_COOLDOWN 2.5 If <=0, fallback applies Minimum delay between two failovers for the same stream.
This prevents unstable oscillation between resolvers.
RECHECK_INACTIVE_SERVERS_ENABLED true true/false Enables background rechecks for currently disabled or unhealthy resolvers.
If disabled, once a resolver becomes unusable, it will stay disabled until restart or manual rebuild.
AUTO_DISABLE_TIMEOUT_SERVERS true true/false Enables automatic disabling of resolvers that keep timing out and show no successful activity.
AUTO_DISABLE_TIMEOUT_WINDOW_SECONDS 30.0 If <=0, fallback applies Time window used to decide whether a resolver is timeout-only.
If all observations in this window are timeouts, it may be disabled.
BASE_ENCODE_DATA false true/false If enabled, payloads are encoded in a base-safe format before tunneling.
This usually reduces payload efficiency, but can help in strict resolver environments.

3.4.5) 🗜️ Compression

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
UPLOAD_COMPRESSION_TYPE 0 0..3 0=OFF, 1=ZSTD, 2=LZ4, 3=ZLIB.
Controls client-side compression for outgoing payloads.
DOWNLOAD_COMPRESSION_TYPE 0 0..3 Compression type expected or preferred for server-to-client payloads.
COMPRESSION_MIN_SIZE 120 If invalid, fallback applies Minimum payload size before compression is attempted.
Very small packets often grow instead of shrinking, so this avoids pointless compression work.

3.4.6) 🧪 MTU Discovery and Initial Testing

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
MIN_UPLOAD_MTU 38 positive integer Smallest upload MTU the client accepts during resolver testing. Minimum enforced is the session-init payload size (10).
MIN_DOWNLOAD_MTU 100 positive integer Smallest download MTU the client accepts during resolver testing. Minimum enforced is the session-accept payload size (20).
MAX_UPLOAD_MTU 150 positive integer Upper bound for upload MTU testing.
MAX_DOWNLOAD_MTU 500 positive integer Upper bound for download MTU testing.
MTU_TEST_RETRIES 2 if invalid, fallback applies Number of retries for each MTU probe.
MTU_TEST_TIMEOUT 2.0 if invalid, fallback applies Timeout for a single MTU probe.
MTU_TEST_PARALLELISM 16 if invalid, fallback applies Number of resolvers tested in parallel during MTU scanning.
Higher values scan faster but use more CPU/network and may produce more noisy failures.
SAVE_MTU_SERVERS_TO_FILE false true/false If enabled, successful resolver results are written to an output file.
MTU_SERVERS_FILE_NAME "masterdnsvpn_success_test_{time}.log" string Output file name template for successful MTU-tested resolvers.
MTU_SERVERS_FILE_FORMAT "{IP} ({DOMAIN}) - UP: {UP_MTU} DOWN: {DOWN-MTU}" string Output format used in the MTU results file.
MTU_USING_SECTION_SEPARATOR_TEXT "" string Optional separator text inserted into the MTU output file.
MTU_REMOVED_SERVER_LOG_FORMAT "Resolver {IP} ({DOMAIN}) removed at {TIME} due to {CAUSE}" string Log/output format when a resolver is removed from the valid set.
MTU_ADDED_SERVER_LOG_FORMAT "Resolver {IP} ({DOMAIN}) added back at {TIME} (UP {UP_MTU}, DOWN {DOWN_MTU})" string Log/output format when a resolver is restored.
MTU_REACTIVE_ADDED_SERVER_LOG_FORMAT "Resolver {IP} ({DOMAIN}) added back at {TIME} after reactive recheck (UP {UP_MTU}, DOWN {DOWN_MTU})" string Log/output format when a resolver is restored by background health checks.

3.4.7) 🧵 Runtime Workers, Queues, and Timers

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
RX_TX_WORKERS 4 if invalid, fallback applies Number of shared runtime workers used for both UDP tunnel reads and writes.
TUNNEL_PROCESS_WORKERS 6 if invalid, fallback applies Number of workers processing tunnel packets after read.
TUNNEL_PACKET_TIMEOUT_SECONDS 10.0 if invalid, fallback applies Overall timeout for tunnel packet handling.
DISPATCHER_IDLE_POLL_INTERVAL_SECONDS 0.020 if invalid, fallback applies When there is nothing to send, the dispatcher sleeps for this interval before polling again.
RX_CHANNEL_SIZE 4096 if invalid, fallback applies Capacity of the incoming tunnel packet channel.
SOCKS_UDP_ASSOCIATE_READ_TIMEOUT_SECONDS 30.0 if invalid, fallback applies Read timeout for SOCKS UDP associate mode.
CLIENT_TERMINAL_STREAM_RETENTION_SECONDS 45.0 if invalid, fallback applies How long terminal streams remain in client bookkeeping before full cleanup.
CLIENT_CANCELLED_SETUP_RETENTION_SECONDS 120.0 if invalid, fallback applies Retention time for setup streams cancelled before completion.
SESSION_INIT_RETRY_BASE_SECONDS 1.0 if invalid, fallback applies Base delay for session-init retries.
SESSION_INIT_RETRY_STEP_SECONDS 1.0 if invalid, fallback applies Step increment used in the retry schedule.
SESSION_INIT_RETRY_LINEAR_AFTER 5 if invalid, fallback applies After this many retries, the retry backoff becomes more linear.
SESSION_INIT_RETRY_MAX_SECONDS 60.0 if invalid, fallback applies Maximum retry delay for session initialization.
SESSION_INIT_BUSY_RETRY_INTERVAL_SECONDS 60.0 if invalid, fallback applies Retry delay when the server explicitly responds with SESSION_BUSY.

3.4.8) 📡 Ping / Keepalive

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
PING_AGGRESSIVE_INTERVAL_SECONDS 0.100 positive number Fastest ping interval used in the hottest activity state.
PING_LAZY_INTERVAL_SECONDS 0.750 positive number Normal operating ping interval.
PING_COOLDOWN_INTERVAL_SECONDS 2.0 positive number Ping interval during cooldown.
PING_COLD_INTERVAL_SECONDS 15.0 positive number Ping interval when the session is cold/mostly idle.
PING_WARM_THRESHOLD_SECONDS 8.0 positive number Threshold after which the session is treated as warm.
PING_COOL_THRESHOLD_SECONDS 20.0 positive number Threshold after which the session is treated as cooling down.
PING_COLD_THRESHOLD_SECONDS 30.0 positive number Threshold after which the session is treated as cold.

3.4.9) 🔄 ARQ and Packet Packing

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
MAX_PACKETS_PER_BATCH 8 if invalid, fallback applies Maximum number of control items the client tries to batch in one packet turn.
ARQ_WINDOW_SIZE 600 valid positive range ARQ send/receive window size per stream.
ARQ_INITIAL_RTO_SECONDS 1.0 clamped in code Initial retransmission timeout for data packets.
ARQ_MAX_RTO_SECONDS 5.0 clamped in code Maximum retransmission timeout for data packets.
ARQ_CONTROL_INITIAL_RTO_SECONDS 0.5 clamped in code Initial retransmission timeout for control packets.
ARQ_CONTROL_MAX_RTO_SECONDS 3.0 clamped in code Maximum retransmission timeout for control packets.
ARQ_MAX_CONTROL_RETRIES 400 clamped in code Maximum number of retries for control packets.
ARQ_INACTIVITY_TIMEOUT_SECONDS 1800.0 clamped in code Stream inactivity timeout.
ARQ_DATA_PACKET_TTL_SECONDS 2400.0 clamped in code TTL for data packets before they are abandoned.
ARQ_CONTROL_PACKET_TTL_SECONDS 1200.0 clamped in code TTL for control packets.
ARQ_MAX_DATA_RETRIES 1200 clamped in code Maximum retries for data packets.
ARQ_DATA_NACK_MAX_GAP 16 clamped in code Maximum gap size for NACK generation when packets arrive out of order.
ARQ_DATA_NACK_INITIAL_DELAY_SECONDS 0.1 clamped in code Initial delay before sending a NACK for missing data packets. Controls how eagerly the system requests retransmissions.
ARQ_DATA_NACK_REPEAT_SECONDS 1.0 clamped in code Minimum interval before repeating a NACK for the same missing sequence.
ARQ_TERMINAL_DRAIN_TIMEOUT_SECONDS 120.0 clamped in code After a stream becomes terminal, how long the client waits for queue drain.
ARQ_TERMINAL_ACK_WAIT_TIMEOUT_SECONDS 90.0 clamped in code How long the client waits for the final terminal ACK.

3.4.10) 🪵 Logging

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
LOG_LEVEL "INFO" usually DEBUG, INFO, WARN, ERROR Controls client log verbosity.
INFO is usually enough for normal operation.
Use DEBUG when investigating resolver health, failover, ARQ, or packet paths.

Section 3.5: 📖 Server Configuration (server_config.toml)

ℹ️ Note: the sample server config contains a key named CONFIG_VERSION, but the current Go code does not read it into ServerConfig. For that reason it is not included in the table below and has no effect on real server behavior.

3.5.1) 🌐 Tunnel Policy and Protocol Acceptance

Parameter Sample Value in server_config.toml.simple Allowed Values / Real Behavior Full Explanation
DOMAIN ["v.domain.com"] list of strings Domain or domains that this server treats as belonging to its tunnel.
They must match the client DOMAINS, otherwise tunnel packets will not be recognized correctly.
PROTOCOL_TYPE "SOCKS5" only "SOCKS5" or "TCP" Determines what kind of setup the server accepts for new streams.
In SOCKS5 mode, the server expects PACKET_SOCKS5_SYN and takes the target from the client payload.
In TCP mode, setup happens through PACKET_STREAM_SYN and the server connects to FORWARD_IP:FORWARD_PORT.
MIN_VPN_LABEL_LENGTH not shown in sample if <=0, fallback to 3 Minimum tunnel data label length.
This helps avoid confusing ordinary DNS queries with tunnel queries.
If this parameter is missing from your old README or config, it is worth adding because the code supports it.
SUPPORTED_UPLOAD_COMPRESSION_TYPES [0, 1, 2, 3] valid compression IDs only Compression modes the server allows clients to request for upload traffic.
SUPPORTED_DOWNLOAD_COMPRESSION_TYPES [0, 1, 2, 3] valid compression IDs only Same idea for download traffic from server to client.

3.5.2) 📥 UDP Listener and Front-Door Capacity

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
UDP_HOST "0.0.0.0" if empty, this value is used Address where the DNS server binds.
0.0.0.0 means listen on all interfaces.
UDP_PORT 53 1..65535 UDP port used by the server.
In most deployments this should remain 53 so resolvers can query it directly.
UDP_READERS 4 auto-default if <=0 Number of goroutines reading directly from the UDP socket.
A larger number may help on very busy servers, but beyond a point it only increases context switching.
DNS_REQUEST_WORKERS 8 auto-default if <=0 Number of workers that take requests from the front-door queue and pass them into the session/decode layer.
MAX_CONCURRENT_REQUESTS 16384 fallback if <=0 Capacity of the incoming request queue.
If this queue fills up, packets are dropped and the server emits rate-limited overload logs.
SOCKET_BUFFER_SIZE 4194304 fallback if <=0 Operating-system socket buffer size request for the UDP listener.
This matters for heavy bursts of incoming traffic.
MAX_PACKET_SIZE 65535 fallback if <=0 Size of the largest packet buffer that the packet pool allocates.
DROP_LOG_INTERVAL_SECONDS 2.0 fallback if <=0 Minimum interval between repeated overload/drop logs, to avoid log spam during pressure.

3.5.3) 🧠 Deferred Session Runtime

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
DEFERRED_SESSION_WORKERS 4 clamped up to 128 Number of deferred-session workers.
These workers handle ordering-sensitive and setup-heavy tasks such as stream setup, SOCKS connect, and some DNS assembly tasks.
Too few can slow down stream setup; too many can create unnecessary contention.
DEFERRED_SESSION_QUEUE_LIMIT 4096 clamped to 256..14336 Queue capacity for deferred-session work.
If it fills up, new setup or deferred tasks may be rejected.
SESSION_ORPHAN_QUEUE_INITIAL_CAPACITY auto derived internally Initial orphan/control queue sizing is derived automatically from server worker counts and batching pressure.
STREAM_QUEUE_INITIAL_CAPACITY auto derived internally Per-stream queue initial capacity is derived automatically from ARQ window size and packing pressure.
DNS_FRAGMENT_STORE_CAPACITY auto derived internally DNS tunnel fragment store capacity is derived automatically from request concurrency and worker count.
SOCKS5_FRAGMENT_STORE_CAPACITY auto derived internally SOCKS5 setup fragment store capacity is derived automatically from deferred-session pressure and concurrency.

3.5.4) 🍪 Session / Stream Lifecycle and Invalid Cookie Tracking

Parameter Sample Value Allowed Values / Real Behavior Full Explanation
INVALID_COOKIE_WINDOW_SECONDS 2.0 fallback if <=0 Time window used to count invalid-cookie errors.
This helps the server detect broken sessions or clients repeatedly using a wrong cookie.
INVALID_COOKIE_ERROR_THRESHOLD 10 fallback if <=0 If invalid-cookie errors reach this threshold inside the window above, the server responds more aggressively.
SESSION_TIMEOUT_SECONDS 300.0 fallback if <=0 If a session has no activity for this long, the server times it out and cleans it up.
SESSION_CLEANUP_INTERVAL_SECONDS 30.0 fallback if <=0 How often th

(README truncated)

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

38 total
  1. Release v2026.06.13.234407-7de2476v2026.06.13.234407-7de2476Jun 13, 202611.2K downloads

    Changes since v2026.05.10.180256-27c7e11: Automated release created by workflow run 27482590364 for commit 7de2476f1c33e69eec35360c52810dab43c5c986 ### Commits - Update README.MD ([17e3df8](https://github.com/masterking32/MasterDnsVPN/commit/17e3df89a3ec6b7da21d4dde0afa01c193457fab)) - Add russian localization for README.MD (#185) ([e40f0b7](https://github.com/masterking32/MasterDnsVPN/commit/e40f0b7a8f4fc9595fbf733faed1e5c05eb5862a)) - Update README.MD ([4da2ae4](https://github.com/masterking32/MasterDnsVPN/commit/4da2ae4f6e4031a24120ee019ed6025bd14b11e4)) - Update README.MD ([aae8b2f](https://github.com/masterking32/MasterDnsVPN/commit/aae8b2ff987b5067877e85522561e63158d76701)) - Add GitHub Sponsors username to FUNDING.yml ([db4aa3f](https://github.com/masterking32/MasterDnsVPN/commit/db4aa3fdbd81124a362dfed973cab303b2feec77)) - Fixed a possible apt-get update error (#188) ([81f3d29](https://github.com/masterking32/MasterDnsVPN/commit/81f3d29b66e164516953580d7905fff6447d8904)) - Add support for Russian README in build workflow ([7de2476](https://github.com/masterking32/MasterDnsVPN/commit/7de2476f1c33e69eec35360c52810dab43c5c986)) ### Merged PRs - [#185](https://github.com/mas

  2. Release v2026.05.10.180256-27c7e11v2026.05.10.180256-27c7e11May 10, 202639.7K downloads

    Changes since v2026.05.04.123456-38b73de: Automated release created by workflow run 25635856673 for commit 27c7e11ce9eb51d7db36b34188502e524a3184db ### Commits - Add badges to README for project visibility ([ae4a40d](https://github.com/masterking32/MasterDnsVPN/commit/ae4a40db27a514b12388afa23a88b67d82bdecaf)) - Update README.MD ([dd1c223](https://github.com/masterking32/MasterDnsVPN/commit/dd1c223ca26be7ab043b2b3701a04482ca3088ab)) - Added new balancers to logs. ([4c45fe6](https://github.com/masterking32/MasterDnsVPN/commit/4c45fe60a913f716c95658c3288d5022b31dd99f)) - Update some of default configs. ([a6bad63](https://github.com/masterking32/MasterDnsVPN/commit/a6bad6339ca7f064c3cab98143e01aa515ddd789)) - Change limits. ([665f8bf](https://github.com/masterking32/MasterDnsVPN/commit/665f8bf02ded3a019e06fb49eee0fe25637d91a8)) - Add GitHub Trend Badge from Trendshift ([45f24f9](https://github.com/masterking32/MasterDnsVPN/commit/45f24f9a03d5c5be367c7d19da80421225cb9279)) - Update logos. ([4068fa4](https://github.com/masterking32/MasterDnsVPN/commit/4068fa41bcf4b8def5b1aa9d535736f69e3b407d)) - Update logos. ([c746810](https://github.com/masterking32/MasterDnsVPN/commit/c74681059f50d

  3. Release v2026.05.04.123456-38b73dev2026.05.04.123456-38b73deMay 4, 202615.5K downloads

    Changes since v2026.04.12.234117-978faee: Automated release created by workflow run 25319270649 for commit 38b73de5993fc2d208e5df2c1765ddc8397d5222 ### Commits - Update README.MD ([a7aef64](https://github.com/masterking32/MasterDnsVPN/commit/a7aef648497b9dc40b052ccd9e459ca60a415480)) - Update README.MD ([f9dee92](https://github.com/masterking32/MasterDnsVPN/commit/f9dee9224dd6ba87979c61acac484d5a6751c7da)) - Ignore injected executable path in client positional args ([49cd565](https://github.com/masterking32/MasterDnsVPN/commit/49cd5657f85fd7c83323c0a49b34c0196244ed1b)) - Merge branch 'main' of https://github.com/masterking32/MasterDnsVPN ([768ec46](https://github.com/masterking32/MasterDnsVPN/commit/768ec46e17d09a290e35fa4e4adc349fa2ba2d93)) - Compact recently-closed heap to prevent stale entry accumulation (#134) ([e6bd8e3](https://github.com/masterking32/MasterDnsVPN/commit/e6bd8e3ae9983ae970f1c6d3799c96cc34526dfb)) - MasterDNSWeb Added (#138) ([aff170e](https://github.com/masterking32/MasterDnsVPN/commit/aff170eee0ad829519f60c56432e2f45d0dacc11)) - Add KevinNet DNS project details to README (#147) ([f466bf8](https://github.com/masterking32/MasterDnsVPN/commit/f466bf8c408036c60

  4. Release v2026.04.12.234117-978faeev2026.04.12.234117-978faeeApr 12, 202641.1K downloads

    Changes since v2026.04.11.044523-0639f8b: Automated release created by workflow run 24319218457 for commit 978faeec4c4e2d79f07842c28d97ef46614e775f ### Commits - Log resolver timeouts to MTU output and tidy MTU handling ([137b919](https://github.com/masterking32/MasterDnsVPN/commit/137b9192fd220cd193d00018b6aab0cdb1b2ae7e)) - Adjust auto-disable thresholds for large timeout windows ([bc3c57e](https://github.com/masterking32/MasterDnsVPN/commit/bc3c57e46ac887ed30506182db577bcc5f054dbc)) - Reactive log. ([243a634](https://github.com/masterking32/MasterDnsVPN/commit/243a634f05a5ef0109e8481aaf990da6f4961a5b)) - Confirm resolver down before auto-disable on small pools ([28b0cb8](https://github.com/masterking32/MasterDnsVPN/commit/28b0cb821dd30597ab3a65ac26ab6b3d66d9126f)) - Align minimum MTU floors with session payload sizes ([86972d5](https://github.com/masterking32/MasterDnsVPN/commit/86972d542a572b60e5ffc03fd0f37fd50ff20499)) - Update Readme files. ([6591c8b](https://github.com/masterking32/MasterDnsVPN/commit/6591c8b73f2a7a058b4cf29b1ade51a23d51d8dc)) - Update Readme (How to use with 3x-ui) ([eba217c](https://github.com/masterking32/MasterDnsVPN/commit/eba217c7998d491b84a4cb64c30f

  5. Release v2026.04.11.044523-0639f8bv2026.04.11.044523-0639f8bApr 11, 20265.4K downloads

    Changes since v2026.04.09.020149-a788a98: Automated release created by workflow run 24274940943 for commit 0639f8bb1a501c521308bc8a68dd24f023dc2b4a ### Commits - Update config file to allow limit clients by server. ([8c4dd9f](https://github.com/masterking32/MasterDnsVPN/commit/8c4dd9fbf0e1e3617f77a4640ab64cd867eca906)) - Sync server and client with new session init response. ([ee169b3](https://github.com/masterking32/MasterDnsVPN/commit/ee169b37441990f2aba67dd1f904ff0926e50343)) - Sync server client-policy limits in SESSION_ACCEPT and warn on enforced clamps ([2c14b22](https://github.com/masterking32/MasterDnsVPN/commit/2c14b22252a0796a8832ff80fd74161cb896b310)) - Enforce server MTU policy during session init and sync SESSION_ACCEPT limits ([c00c068](https://github.com/masterking32/MasterDnsVPN/commit/c00c0687707333c625a6de5942b3b041c3608da1)) - Fully sync client runtime state with server session policy limits ([cb12d8f](https://github.com/masterking32/MasterDnsVPN/commit/cb12d8f7331502a8fe8dbd0a06b4c96661d21b90)) - Sync client session policy from SESSION_ACCEPT, enforce server init limits, and fully align runtime worker/state updates ([092c77d](https://github.com/masterking32/Ma

Commits per week

last 52 weeks
2220Week of 2025-08-02: 0 commitsWeek of 2025-08-09: 0 commitsWeek of 2025-08-16: 0 commitsWeek of 2025-08-23: 0 commitsWeek of 2025-08-30: 0 commitsWeek of 2025-09-06: 0 commitsWeek of 2025-09-13: 0 commitsWeek of 2025-09-20: 0 commitsWeek of 2025-09-27: 0 commitsWeek of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 19 commitsWeek of 2026-01-25: 30 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 1 commitsWeek of 2026-03-01: 132 commitsWeek of 2026-03-08: 167 commitsWeek of 2026-03-15: 222 commitsWeek of 2026-03-22: 159 commitsWeek of 2026-03-29: 130 commitsWeek of 2026-04-05: 107 commitsWeek of 2026-04-12: 13 commitsWeek of 2026-04-19: 1 commitsWeek of 2026-04-26: 0 commitsWeek of 2026-05-03: 11 commitsWeek of 2026-05-10: 8 commitsWeek of 2026-05-17: 0 commitsWeek of 2026-05-24: 0 commitsWeek of 2026-05-31: 1 commitsWeek of 2026-06-07: 5 commitsWeek of 2026-06-14: 7 commitsWeek of 2026-06-21: 0 commitsWeek of 2026-06-28: 0 commitsWeek of 2026-07-05: 1 commitsWeek of 2026-07-12: 0 commitsWeek of 2026-07-19: 7 commitsWeek of 2026-07-26: 0 commitsAug 2, 2025Jul 26, 2026
1K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 4 commitsSun 1:00 — 7 commitsSun 2:00 — 14 commitsSun 3:00 — 4 commitsSun 4:00 — 4 commitsSun 5:00 — 3 commitsSun 6:00 — 3 commitsSun 7:00 — 5 commitsSun 8:00 — 4 commitsSun 9:00 — 3 commitsSun 10:00 — 2 commitsSun 11:00 — 2 commitsSun 12:00 — 1 commitsSun 13:00 — 2 commitsSun 14:00 — 3 commitsSun 15:00 — 2 commitsSun 16:00 — 13 commitsSun 17:00 — 2 commitsSun 18:00 — 6 commitsSun 19:00 — 5 commitsSun 20:00 — 10 commitsSun 21:00 — 15 commitsSun 22:00 — 4 commitsSun 23:00 — 0 commitsMon 0:00 — 3 commitsMon 1:00 — 5 commitsMon 2:00 — 8 commitsMon 3:00 — 5 commitsMon 4:00 — 9 commitsMon 5:00 — 6 commitsMon 6:00 — 7 commitsMon 7:00 — 2 commitsMon 8:00 — 6 commitsMon 9:00 — 2 commitsMon 10:00 — 13 commitsMon 11:00 — 3 commitsMon 12:00 — 1 commitsMon 13:00 — 4 commitsMon 14:00 — 7 commitsMon 15:00 — 10 commitsMon 16:00 — 14 commitsMon 17:00 — 5 commitsMon 18:00 — 6 commitsMon 19:00 — 6 commitsMon 20:00 — 7 commitsMon 21:00 — 1 commitsMon 22:00 — 9 commitsMon 23:00 — 9 commitsTue 0:00 — 7 commitsTue 1:00 — 2 commitsTue 2:00 — 6 commitsTue 3:00 — 5 commitsTue 4:00 — 14 commitsTue 5:00 — 3 commitsTue 6:00 — 7 commitsTue 7:00 — 7 commitsTue 8:00 — 8 commitsTue 9:00 — 5 commitsTue 10:00 — 9 commitsTue 11:00 — 8 commitsTue 12:00 — 12 commitsTue 13:00 — 3 commitsTue 14:00 — 4 commitsTue 15:00 — 6 commitsTue 16:00 — 9 commitsTue 17:00 — 9 commitsTue 18:00 — 8 commitsTue 19:00 — 5 commitsTue 20:00 — 2 commitsTue 21:00 — 2 commitsTue 22:00 — 1 commitsTue 23:00 — 5 commitsWed 0:00 — 10 commitsWed 1:00 — 9 commitsWed 2:00 — 9 commitsWed 3:00 — 6 commitsWed 4:00 — 7 commitsWed 5:00 — 4 commitsWed 6:00 — 11 commitsWed 7:00 — 10 commitsWed 8:00 — 7 commitsWed 9:00 — 2 commitsWed 10:00 — 6 commitsWed 11:00 — 3 commitsWed 12:00 — 7 commitsWed 13:00 — 2 commitsWed 14:00 — 6 commitsWed 15:00 — 3 commitsWed 16:00 — 2 commitsWed 17:00 — 6 commitsWed 18:00 — 9 commitsWed 19:00 — 7 commitsWed 20:00 — 1 commitsWed 21:00 — 5 commitsWed 22:00 — 7 commitsWed 23:00 — 12 commitsThu 0:00 — 3 commitsThu 1:00 — 4 commitsThu 2:00 — 6 commitsThu 3:00 — 9 commitsThu 4:00 — 19 commitsThu 5:00 — 18 commitsThu 6:00 — 18 commitsThu 7:00 — 6 commitsThu 8:00 — 7 commitsThu 9:00 — 3 commitsThu 10:00 — 4 commitsThu 11:00 — 6 commitsThu 12:00 — 11 commitsThu 13:00 — 5 commitsThu 14:00 — 0 commitsThu 15:00 — 0 commitsThu 16:00 — 2 commitsThu 17:00 — 3 commitsThu 18:00 — 14 commitsThu 19:00 — 3 commitsThu 20:00 — 1 commitsThu 21:00 — 5 commitsThu 22:00 — 5 commitsThu 23:00 — 5 commitsFri 0:00 — 3 commitsFri 1:00 — 0 commitsFri 2:00 — 10 commitsFri 3:00 — 4 commitsFri 4:00 — 3 commitsFri 5:00 — 3 commitsFri 6:00 — 4 commitsFri 7:00 — 12 commitsFri 8:00 — 9 commitsFri 9:00 — 10 commitsFri 10:00 — 5 commitsFri 11:00 — 4 commitsFri 12:00 — 4 commitsFri 13:00 — 5 commitsFri 14:00 — 2 commitsFri 15:00 — 1 commitsFri 16:00 — 4 commitsFri 17:00 — 10 commitsFri 18:00 — 3 commitsFri 19:00 — 7 commitsFri 20:00 — 11 commitsFri 21:00 — 7 commitsFri 22:00 — 6 commitsFri 23:00 — 6 commitsSat 0:00 — 12 commitsSat 1:00 — 5 commitsSat 2:00 — 9 commitsSat 3:00 — 9 commitsSat 4:00 — 8 commitsSat 5:00 — 16 commitsSat 6:00 — 12 commitsSat 7:00 — 23 commitsSat 8:00 — 9 commitsSat 9:00 — 8 commitsSat 10:00 — 4 commitsSat 11:00 — 2 commitsSat 12:00 — 1 commitsSat 13:00 — 2 commitsSat 14:00 — 7 commitsSat 15:00 — 5 commitsSat 16:00 — 1 commitsSat 17:00 — 5 commitsSat 18:00 — 4 commitsSat 19:00 — 11 commitsSat 20:00 — 5 commitsSat 21:00 — 4 commitsSat 22:00 — 1 commitsSat 23:00 — 5 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.

Who is committing

last 52 weeks
Maintainer commits988 (96%)
Community commits42 (4%)

1,030 commits in total over the last year.

DateListRankStars gained
May 9, 2026daily#18+118
  • avelino/awesome-go

    A curated list of awesome Go frameworks, libraries and software

    180.4K stars · Go

  • kubernetes/kubernetes

    Production-Grade Container Scheduling and Management

    124.3K stars · Go

  • usememos/memos

    Open-source, self-hosted note-taking tool built for quick capture. Markdown-native, lightweight, and fully yours.

    62K stars · Go

  • hashicorp/terraform

    Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.

    49.4K stars · Go

  • router-for-me/CLIProxyAPI

    Wrap Antigravity, ChatGPT Codex, Claude Code, Grok Build as an OpenAI/Gemini/Claude/Codex compatible API service, allowing you to enjoy the free Gemini 3.1 Pro, GPT 5.6 Series, Grok 4.5, Claude model through API

    46.3K stars · Go

  • multica-ai/multica

    Assign issues to Claude Code, Codex, Cursor, and 17 more coding agents like teammates — open-source and self-hostable.

    44.7K stars · Go