Squawk DNS — Authenticated DNS-over-HTTPS
A secure, scalable DNS-over-HTTPS (DoH) proxy with token-based authentication and fine-grained, per-domain access control — merging into Tobogganing as the netsvcs module, standalone v2.1.1 today.
- DNS-over-HTTPS (RFC 8484) resolution with HTTP/3 support, replacing cleartext UDP/TCP port 53 DNS.
- Bearer-token authentication scoped to specific domains — exact names, subdomain wildcards, or a full wildcard for unrestricted resolution.
- DNS blackholing via Maravento blackweb list integration plus admin-managed custom blacklists, with an IOC/threat-intelligence view in the admin console.
- Optional mutual TLS (ECC P-384 client certificates) for dual authentication alongside the bearer token.
- Valkey/Redis-backed response caching with automatic in-memory fallback if the cache is unavailable.
- Local DNS forwarding lets a client run as a UDP/TCP port 53 forwarder, so existing applications and OS resolvers need no changes.
