Network Resilience

MasterDNS VPN

DNS-tunnel VPN engineered against DPI.

The problem it solved

In heavily filtered networks, conventional VPNs are detected and blocked. This tunnels over DNS and adapts to deep-packet inspection in real time, so connectivity survives.

Similar problems it can solve

Resilient connectivity for restricted markets, censorship-resistant messaging and distribution, and anti-DPI transport for any app that must stay reachable.

A censorship-resistant VPN that tunnels traffic over DNS with adaptive anti-DPI: a Go server on Azure, .NET 10 WPF and native Android clients, MTU auto-discovery, forged-response filtering and Telegram (TDLib) integration.

Overview

MasterDNS is a censorship-resistant VPN engineered for the most hostile networks — it tunnels traffic over DNS and adapts to deep-packet inspection in real time, so it keeps working where ordinary VPNs are detected and blocked.

One platform, many components

It spans a Go server deployed on Azure, a .NET 10 WPF desktop client, a native Android client, a DNS-research toolkit, a config locker, and Telegram (TDLib) integration for distribution.

Engineering depth

The hard problems are detection and reliability over an adversarial channel: adaptive anti-DPI, bidirectional MTU auto-discovery, forged-response (ISP-injection) filtering with transaction-ID matching, an ARQ reliability layer with data-NACK and adaptive RTO, and SOCKS5 egress — co-engineered so the Go server and the Android client agree on identical discovery and validation logic.

Technology

Go (Azure server), .NET 10 WPF, native Android/Kotlin, TDLib, and a custom DNS-tunnel transport with anti-DPI.

.NET 10 WPF Android/Kotlin Go TDLib DNS-over-UDP