Skip to main content

Multi‑protocol DNS resolver with full server and config support

Project description

dosev – Multi‑Protocol DNS Resolver & Server

CI PyPI version Python versions License: MIT

dosev is a high‑performance, asynchronous DNS resolver and forwarding server that speaks all major DNS protocols – both as a client and as a server.

  • Client protocols: DNS over UDP, TCP, TLS (DoT), HTTPS (DoH – HTTP/1.1, HTTP/2, HTTP/3), and QUIC (DoQ).
  • Server protocols: UDP, TCP, TLS (DoT), HTTPS (DoH – HTTP/2 and HTTP/3).
  • Features: EDNS0 (including Client Subnet), DNSSEC validation with automatic trust anchor updates, negative caching, optimistic caching (serve‑stale), blocklists, hosts overrides, upstream health checks, load balancing, Prometheus metrics, and more.

🚀 Quick Start

# Install via pip
pip install dosev

# Create a minimal config file
mkdir -p config
cat > config/dosev.conf <<EOF
[server]
listen_ip = 0.0.0.0
listen_port = 53

[resolver]
upstream_dns = 1.1.1.1
protocol = udp
EOF

# Start the server
dosev --config config/dosev.conf

For detailed instructions, see the Quick Start Guide.


✨ Features

Feature Description
Multi‑protocol client Forward queries via UDP, TCP, TLS, HTTPS (HTTP/1.1, HTTP/2, HTTP/3), and QUIC.
Multi‑protocol server Listen on UDP, TCP, TLS, and HTTPS (HTTP/2 & HTTP/3).
DNSSEC validation Validate responses with a built‑in root trust anchor (auto‑updated from IANA).
Caching Positive and negative caching with configurable TTLs; optimistic caching (serve‑stale).
Blocklists Filter domains using local files or remote lists (automatically refreshed).
Hosts overrides Custom A/AAAA records for local name resolution.
EDNS0 & Client Subnet Pass client subnet to upstreams for geo‑optimised responses.
Load balancing & health checks Distribute queries across multiple upstreams; automatically exclude unhealthy ones.
Rate limiting Token‑bucket limiter per client IP.
Rebinding protection Strip or block private IP addresses from responses.
Metrics Prometheus‑compatible metrics (requests, errors, latency, cache stats).
Privilege dropping Drop root privileges after binding to privileged ports.
Cross‑platform Works on Linux, macOS, and Windows.
Configuration Single INI file; can be reloaded without restarting.

📖 Documentation


🔧 Configuration Example

[server]
listen_ip = 0.0.0.0
listen_port = 53

[resolver]
upstream_dns = 1.1.1.1
protocol = udp

[security]
dnssec_enabled = true
auto_update_trust_anchor = true

[blocklists]
enabled = true
urls = https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
action = NXDOMAIN

See the full configuration reference for all options.


🧪 Running Tests

pip install dosev[test]
pytest --cov=dosev --cov-report=term-missing

🤝 Contributing

We welcome contributions! Please read our Contributing Guide before opening issues or pull requests.


📄 License

This project is licensed under the MIT License – see the LICENSE file for details.


🙏 Acknowledgements

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dosev-1.1.0.tar.gz (48.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dosev-1.1.0-py3-none-any.whl (37.4 kB view details)

Uploaded Python 3

File details

Details for the file dosev-1.1.0.tar.gz.

File metadata

  • Download URL: dosev-1.1.0.tar.gz
  • Upload date:
  • Size: 48.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.2

File hashes

Hashes for dosev-1.1.0.tar.gz
Algorithm Hash digest
SHA256 eeea04bdc7ffd6abfe281eced5ba29881790bc0e9e2f34e0fe94a79187560a9c
MD5 da51da78a725e934e1c7aa5bdb7e1d5a
BLAKE2b-256 6d8635611abaef2f43c1c82cc1b314f9dc0c47d2ec9d85c98e83b54148d08254

See more details on using hashes here.

File details

Details for the file dosev-1.1.0-py3-none-any.whl.

File metadata

  • Download URL: dosev-1.1.0-py3-none-any.whl
  • Upload date:
  • Size: 37.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.2

File hashes

Hashes for dosev-1.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 852304a83fea77e63cb47903b4cafe689176e92a7409c4ed041c406059405d6a
MD5 11913fdf631bbe00643e6e7f99723350
BLAKE2b-256 bb65bc197d20a7381cf5db050433ac5d73d4b473b6263f371d43b9c90eed107a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page