MasterDNS VPN
DNS-tunnel VPN engineered against DPI.
The problem it solved
In heavily filtered networks, conventional VPNs are detected and blocked. This tunnels over DNS and adapts to deep-packet inspection in real time, so connectivity survives.
Similar problems it can solve
Resilient connectivity for restricted markets, censorship-resistant messaging and distribution, and anti-DPI transport for any app that must stay reachable.
A censorship-resistant VPN that tunnels traffic over DNS with adaptive anti-DPI: a Go server on Azure, .NET 10 WPF and native Android clients, MTU auto-discovery, forged-response filtering and Telegram (TDLib) integration.
- Adaptive anti-DPI + MTU auto-discovery over DNS
- Go server (Azure) + WPF & Android clients
- Forged-response filtering · ARQ · SOCKS5
Overview
MasterDNS is a censorship-resistant VPN engineered for the most hostile networks — it tunnels traffic over DNS and adapts to deep-packet inspection in real time, so it keeps working where ordinary VPNs are detected and blocked.
One platform, many components
It spans a Go server deployed on Azure, a .NET 10 WPF desktop client, a native Android client, a DNS-research toolkit, a config locker, and Telegram (TDLib) integration for distribution.
Engineering depth
The hard problems are detection and reliability over an adversarial channel: adaptive anti-DPI, bidirectional MTU auto-discovery, forged-response (ISP-injection) filtering with transaction-ID matching, an ARQ reliability layer with data-NACK and adaptive RTO, and SOCKS5 egress — co-engineered so the Go server and the Android client agree on identical discovery and validation logic.
Technology
Go (Azure server), .NET 10 WPF, native Android/Kotlin, TDLib, and a custom DNS-tunnel transport with anti-DPI.