18 releases

✓ Uses Rust 2018 edition

new 0.1.18 Jun 15, 2019
0.1.17 Jun 11, 2019
0.1.16 May 27, 2019
0.1.13 Mar 16, 2019
0.1.5 Feb 12, 2018

#84 in Network programming

Download history 30/week @ 2019-03-01 21/week @ 2019-03-08 91/week @ 2019-03-15 75/week @ 2019-03-22 6/week @ 2019-03-29 22/week @ 2019-04-05 17/week @ 2019-04-12 9/week @ 2019-04-19 11/week @ 2019-04-26 25/week @ 2019-05-03 49/week @ 2019-05-10 62/week @ 2019-05-17 56/week @ 2019-05-24 30/week @ 2019-05-31 118/week @ 2019-06-07

176 downloads per month

MIT license

818 lines


A DNS-over-HTTP server proxy in Rust. Add a webserver and you get DNS-over-HTTPS, which is actually DNS-over-HTTP/2.


Without built-in support for HTTPS:

cargo install doh-proxy

With built-in support for HTTPS (requires openssl-dev):

cargo install doh-proxy --features=tls


A DNS-over-HTTP server proxy

    doh-proxy [FLAGS] [OPTIONS]

    -K, --disable-keepalive    Disable keepalive
    -P, --disable-post         Disable POST queries
    -h, --help                 Prints help information
    -V, --version              Prints version information

    -E, --err-ttl <err_ttl>                          TTL for errors, in seconds [default: 2]
    -l, --listen-address <listen_address>            Address to listen to [default:]
    -b, --local-bind-address <local_bind_address>    Address to connect from [default:]
    -c, --max-clients <max_clients>                  Maximum number of simultaneous clients [default: 512]
    -X, --max-ttl <max_ttl>                          Maximum TTL, in seconds [default: 604800]
    -T, --min-ttl <min_ttl>                          Minimum TTL, in seconds [default: 10]
    -p, --path <path>                                URI path [default: /dns-query]
    -u, --server-address <server_address>            Address to connect to [default:]
    -t, --timeout <timeout>                          Timeout, in seconds [default: 10]
    -I, --tls-cert-password <tls_cert_password>
            Password for the PKCS12-encoded identity (only required for built-in TLS)

    -i, --tls-cert-path <tls_cert_path>              Path to a PKCS12-encoded identity (only required for built-in TLS)

HTTP/2 termination

The recommended way to use doh-proxy is to use a TLS termination proxy (such as hitch or relayd), a CDN or a web server with proxying abilities as a front-end.

That way, the DoH service can be exposed as a virtual host, sharing the same IP addresses as existing websites.

If doh-proxy and the HTTP/2 front-end run on the same host, using the HTTP protocol to communicate between both is fine.

If both are on distinct networks, such as when using a CDN, doh-proxy can handle HTTPS requests, provided that it was compiled with the tls feature.

The identity must be encoded in PKCS12 format. Given an existing certificate cert.pem and its secret key cert.key, this can be achieved using the openssl command-line tool:

openssl pkcs12 -export -out cert.p12 -in cert.pem -inkey cert.key

A password will be interactive asked for, but the -passout command-line option can be added to provide it non-interactively.

Once done, check that the permissions on cert.p12 are reasonable.

In order to enable built-in HTTPS support, add the --tls-cert-path option to specify the location of the cert.p12 file, as well as the password using --tls-cert-password.

Once HTTPS is enabled, HTTP connections will not be accepted.


doh-proxy can be used with dnscrypt-proxy as a client.

doh-proxy is currently being used by the doh.crypto.sx public DNS resolver.

Other public DoH servers can be found here: public encrypted DNS servers.


~156K SLoC