Squawk DNS — Authenticated DNS-over-HTTPS

A secure, scalable DNS-over-HTTPS (DoH) proxy with token-based authentication and fine-grained, per-domain access control — merging into Tobogganing as the netsvcs module, standalone v2.1.1 today.

  • DNS-over-HTTPS (RFC 8484) resolution with HTTP/3 support, replacing cleartext UDP/TCP port 53 DNS.
  • Bearer-token authentication scoped to specific domains — exact names, subdomain wildcards, or a full wildcard for unrestricted resolution.
  • DNS blackholing via Maravento blackweb list integration plus admin-managed custom blacklists, with an IOC/threat-intelligence view in the admin console.
  • Optional mutual TLS (ECC P-384 client certificates) for dual authentication alongside the bearer token.
  • Valkey/Redis-backed response caching with automatic in-memory fallback if the cache is unavailable.
  • Local DNS forwarding lets a client run as a UDP/TCP port 53 forwarder, so existing applications and OS resolvers need no changes.
Squawk DNS admin console dashboard

← Back to all features

Full technical documentation →