Skip to content
hashcottPublic

About

One-click encrypted DNS (DoH/DoT/DoQ/DNSCrypt), DPI bypass with zapret2 or GoodbyeDPI, a local HTTP/SOCKS proxy with TLS fragmentation, and domain rules for Windows. ~30 MB RAM in the tray, no telemetry, always restores your original DNS. For research and educational use.

Topics

Resources

Contributing

Security policy

Stars

99 stars

Watchers

3 watching

Forks

Repository files navigation

Ghostline logo

Ghostline

One-click encrypted DNS and DPI bypass for Windows and Linux.

CI Release Downloads License: GPL v3 Platform

English · Tiếng Việt

Download Ghostline for Windows Download Ghostline for Linux


Ghostline runs a local DNS server on 127.0.0.1 / ::1, points the system's DNS at it (every network adapter on Windows; NetworkManager, systemd-resolved or /etc/resolv.conf on Linux), and forwards your queries over DoH, DoT, DoQ or DNSCrypt to the fastest healthy resolver. When your network interferes with encrypted connections by inspecting packets (DPI), it can also run a DPI bypass engine: zapret2 (recommended), or GoodbyeDPI on Windows. Above all, it is built to always give your original DNS back, even if the app crashes or the machine loses power.

Simple interface   Full interface

Table of contents

Features

  • Encrypted DNS for the whole system: DoH, DoT, DoQ and DNSCrypt upstreams, powered by AdGuard dnsproxy.
  • Automatic server choice: scans resolvers in parallel, rejects poisoned answers, and remembers the best servers per network.
  • Never lose the internet: the original DNS is snapshotted before any change and always comes back. On Windows there are five recovery layers: clean disconnect, a watchdog process, restore on next launch, a logon recovery task, and a network guard that works even if an antivirus quarantines ghostline.exe. On Linux a systemd service restores on disconnect, when it stops or crashes, and at boot.
  • Leak verification: after connecting, Ghostline checks that queries really go through it.
  • DPI bypass: bundled, hash-pinned zapret2 v1.0.5.2 (fake packets, more split methods, QUIC for YouTube/Google), through WinDivert on Windows and an nftables queue on Linux, plus GoodbyeDPI 0.2.3rc3 on Windows. zapret2 strategies come from a signed list refreshed daily, with auto-tune, a site blacklist, automatic detection of blocked sites, and DoH request fragmentation. On Windows, if antivirus blocks zapret2, Ghostline falls back to GoodbyeDPI and offers to retry.
  • Local proxy (HTTP / HTTPS / SOCKS4/5): runs with Connect, can become the system proxy (Windows, GNOME, KDE), and can be shared with phones and other devices on your Wi-Fi (QR code included). Names are always resolved through Ghostline's encrypted DNS.
  • Web fragmentation without a driver: traffic through the proxy gets its TLS ClientHello split automatically when a site is blocked by SNI, and the fix is remembered per network.
  • Rules and community lists: block, allow, fake DNS, fragment or route through an upstream proxy by domain, keyword, regexp or CIDR. Import hosts, AdBlock/AdGuard, dnsmasq, Unbound, RPZ, Clash, v2ray, sing-box or CIDR lists straight from a GitHub link, updated on a schedule.
  • DNS server for your home network: encrypted DNS for phones, TVs, consoles and routers on your Wi-Fi: plain DNS on port 53 (no certificate needed) or DNS-over-HTTPS, with a QR-code setup page and an iOS profile.
  • Fake SNI (advanced, off by default): for sites behind CDNs that allow domain fronting, the proxy sends a different, allowed domain name to the network. It decrypts HTTPS only for domains you choose, with a certificate that can sign only those domains and is removed on disconnect.
  • Diagnostic tools: DNS lookup that compares sources and spots DNS poisoning, an advanced scanner that grades servers on latency, loss, DNSSEC, ad filtering and poisoning, a Cloudflare clean-IP finder that turns results into ip= rules, and a DNS stamp reader and builder.
  • Backup and restore: export settings, rules, lists and your servers to one file and import them on another PC. Private and machine-bound values are never exported, and an import never turns on Fake SNI or sharing on the LAN.
  • Signed server list: updated daily and verified with ed25519; the DNSCrypt list is checked with minisign.
  • Simple and Full interfaces, a tray icon, Vietnamese and English UI, and a neon-terminal look.
  • Installer, portable or Linux packages: on Windows, an installer or a portable build that keeps all data in a data\ folder next to the exe; on Linux, .deb, .rpm, AppImage, tar.gz and a PKGBUILD.
  • Update notifications only: Ghostline tells you about a new version and never updates itself silently.

Video

A narrated walkthrough of a little over 3 minutes: one-click connect, protection levels, servers, DPI bypass, the proxy, rules, the DNS server with the iPhone setup, Fake SNI, the diagnostic tools and backup. The preview below plays sped up and silent; click it for the full video with sound. A Vietnamese version is also available.

Ghostline video guide (sped up); click for the full video

Short narrated clips, one per feature: Connect · Protection levels · Servers · DPI bypass · Proxy · Rules · DNS server and iPhone · Fake SNI · Tools · Test domain and backup · Disconnect. The user guide shows each one next to its step-by-step instructions.

Screenshots

Servers DPI bypass
Servers DPI bypass
Proxy Rules and lists
Proxy Rules
Logs Settings
Logs Settings
DNS server Fake SNI
DNS server Fake SNI
Lookup Cloudflare IP
Lookup Cloudflare IP

Install

⬇ Download the latest release — or pick a file below. Older versions are on the Releases page.

File What it is Download
ghostline-amd64-installer.exe Installer (installs WebView2 if missing) Direct download ⬇
Ghostline-<version>-portable.zip Portable: unzip and run From latest release
SHA256SUMS Checksums for both Direct download

Windows

Verify the download:

Get-FileHash .\Ghostline-0.1.0-portable.zip -Algorithm SHA256

Requirements: Windows 10/11 x64 and administrator rights. Changing adapter DNS and loading the WinDivert driver both need admin. When Ghostline starts with Windows it runs through Task Scheduler, so there is no UAC prompt.

Note

Releases are not code-signed yet, so SmartScreen shows "Windows protected your PC". After checking the SHA-256, choose More info → Run anyway. Some antivirus products flag the WinDivert driver used by zapret2 and GoodbyeDPI. Ghostline verifies the engine's hash before every start; if your antivirus blocks zapret2, Ghostline runs GoodbyeDPI for now and the DPI page shows the bin\zapret2 folder to add to the exclusions.

Linux (x86_64)

Distribution File Install
Ubuntu 24.04+, Debian 13+ ghostline_<version>_amd64.deb sudo apt install ./ghostline_<version>_amd64.deb
Fedora 41+ ghostline-<version>-1.x86_64.rpm sudo dnf install ./ghostline-<version>-1.x86_64.rpm
Arch, CachyOS, Manjaro ghostline-<version>-linux-amd64.tar.gz Unpack it and run sudo ./install.sh, or build ghostline-bin from the PKGBUILD attached to the release (makepkg -si)
Other distributions Ghostline-<version>-x86_64.AppImage chmod +x and run it; it offers to install the background service

Verify the downloads: sha256sum -c SHA256SUMS --ignore-missing.

Ghostline on Linux is two parts: a background service (ghostline.service, root) that changes DNS, runs zapret2 and keeps protecting with the window closed and after a reboot, and the window, which runs as your user. Members of wheel, sudo, admin or the ghostline group can control it; to allow another account: sudo usermod -aG ghostline <user>, then log in again. The deb and rpm start the service right away; on Arch start it once with sudo systemctl enable --now ghostline (or the button in the window).

Requirements: systemd, GTK 4 and WebKitGTK 6.0 (the packages pull them in; the AppImage and the tar.gz use the system's).

Update: install the new .deb or .rpm, or rebuild ghostline-bin from the new PKGBUILD. If the service came from the AppImage, open the new AppImage: it finds the older service and updates it once you enter your password (cancelled, the banner at the top keeps an update the service button). From the tar.gz, unpack the new one and run sudo ./install.sh once (it replaces the service and restarts it).

Uninstall: sudo apt remove ghostline (apt purge also deletes the settings), sudo dnf remove ghostline, sudo pacman -R ghostline-bin; tar.gz: sudo ./uninstall.sh [--purge] in the unpacked folder; AppImage: sudo /var/lib/ghostline/bin/ghostlined --uninstall-system [--purge], then delete the AppImage file. DNS, the system proxy, certificates, firewall rules and the nftables table are restored first. rpm and Arch keep the settings: sudo rm -rf /var/lib/ghostline /var/log/ghostline removes them.

Usage

📖 A detailed user guide covering every screen, unblocking sites and troubleshooting: docs/user-guide.md (Tiếng Việt)

  1. Start Ghostline and press Connect. It picks a server, redirects DNS and verifies there is no leak.
  2. If some sites are still blocked, either turn on the proxy (Full → Proxy → enable proxy + use for this PC) so browsers get automatic fragmentation, or open Full → DPI bypass, pick an engine (zapret2 is recommended), turn it on and press auto-tune. To share with other devices, turn on share on LAN and scan the QR code on your phone (on Windows the network must be Private).
  3. Press Disconnect (or quit from the tray) to restore your original DNS.

If DNS ever looks wrong, Settings → Restore DNS now puts the system's DNS back to its saved state. From a terminal you can also run:

ghostline.exe --restore

On Linux, stopping the service restores DNS: sudo systemctl stop ghostline (then sudo systemctl start ghostline).

How it works

apps ──► system DNS ──► 127.0.0.1:53 (Ghostline / dnsproxy) ──► DoH · DoT · DoQ · DNSCrypt
         (Windows DNS client, NetworkManager,     │
          systemd-resolved or resolv.conf)        │
            zapret2 / GoodbyeDPI (optional) rewrites outgoing TLS/HTTP/QUIC to dodge SNI filtering

On Linux, Ghostline is a root service (ghostlined, run by systemd) that owns DNS, DPI and the proxy, and a window that runs as your user and talks to it over a local socket. Closing the window does not stop protection.

Safety net. Before changing DNS, Ghostline writes a snapshot (state.json) of it. On Windows, five layers make sure that snapshot gets restored:

  1. Clean disconnect: the normal path.
  2. Watchdog: a separate --watchdog process restores DNS within seconds if the app dies.
  3. Next launch: a leftover snapshot is restored at startup.
  4. Logon task: the Ghostline Recovery scheduled task runs --restore after a crash or power loss.
  5. Network guard: while connected, the Ghostline Network Guard task runs a PowerShell script as SYSTEM every minute, at boot and right after Microsoft Defender acts on a threat. If Ghostline is gone but DNS still points at 127.0.0.1, it restores DNS and the system proxy from state.json. It does not need ghostline.exe, so it still works when an antivirus kills and quarantines the app along with the layers above.

On Linux, systemd is the watchdog: the service restores on disconnect, ExecStopPost=--restore runs whenever it stops or crashes (even after kill -9), and at boot the service restores whatever a power cut left before anything else.

Design details live in docs/superpowers/specs, and docs/platforms.md maps each feature to its Windows and Linux code.

Privacy

  • No telemetry, no accounts, no analytics.
  • Visited domains are never written to disk. The optional query log lives in RAM only.
  • Network access is limited to your chosen DNS resolvers, bootstrap resolution of their hostnames, the signed server list, the DNSCrypt resolver list, the GitHub release check, and the community lists you add yourself.
  • The proxy never logs destinations to disk; its live connection view is RAM-only like the query log.

Known limitations

  • Fake SNI works only for browsers on this PC going through the proxy, only for domains with an sni= rule, and breaks apps that pin certificates. Firefox may need security.enterprise_roots.enabled.
  • Devices using this PC's DNS lose the internet when it is off or disconnected. iOS has no fallback: with the DoH profile, the iPhone has no internet on your home Wi-Fi until you choose Automatic in Settings › General › VPN & Device Management › DNS (mobile data is not affected). Disconnect asks first while LAN devices use the DNS server; if this PC is often off, set the iPhone's DNS manually instead of using the profile. Android's Private DNS cannot use Ghostline; set a static DNS for your Wi-Fi instead.

Windows

  • If you approve UAC with a different administrator account, %APPDATA% and the system proxy belong to that account, so "use for this PC" does not affect the signed-in user.
  • Web fragmentation only helps apps that go through the proxy. Apps that ignore the Windows proxy (some games, Firefox with its own proxy settings) need the DPI engine instead.
  • LAN sharing works only on networks marked Private in Windows; Ghostline never changes the network profile itself.

Linux

  • GNOME has no tray by default: with close to tray on, a closed window has no icon to click; open Ghostline again from the app menu to bring it back, or turn the setting off so ✕ quits. Protection keeps running in the background service either way.
  • The system proxy is set automatically only on GNOME and KDE; on other desktops set 127.0.0.1:<port> by hand.
  • Fake SNI in Chrome and Chromium on Ubuntu and Debian needs libnss3-tools (certutil).
  • A kernel without NFQUEUE (nfnetlink_queue, nft_queue) has no DPI bypass; the proxy's fragmentation still works.
  • No GoodbyeDPI (it is Windows-only); zapret2 is the engine.
  • Packages are not GPG-signed yet: check SHA256SUMS.
  • The AppImage needs glibc 2.39 or newer (Ubuntu 24.04, Debian 13, Fedora 40 and later).
  • SteamOS (Steam Deck) is not verified yet.

Building from source

Prerequisites: Go 1.27+, Node.js 24, Wails v3 v3.0.0-beta.27, and NSIS for the Windows installer.

go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-beta.27

wails3 dev                     # live-reload dev build (connecting for real needs admin)
wails3 build                   # bin/ghostline.exe
wails3 package                 # NSIS installer
wails3 task windows:portable   # portable zip

On Linux (GTK 4 and WebKitGTK 6.0 development packages, plus squashfs-tools for the AppImage):

wails3 task linux:build                     # bin/linux/ghostline and bin/linux/ghostlined
wails3 task linux:package VERSION=0.6.1     # deb, rpm, AppImage and tar.gz in bin/

Tests:

go test ./...
cd frontend && npm test

Integration tests change real system settings, so run them in an admin terminal on Windows:

go test -tags integration ./internal/sysdns/... ./internal/startup/...

and as root on Linux (system DNS, the nftables queue with nfqws2, recovery after kill -9):

sudo -E env "PATH=$PATH" go test -tags integration_root ./internal/sysdns/ ./internal/dpi/ ./cmd/ghostlined/

Before a release, go through docs/release-checklist.md. Pushing a v* tag builds and publishes the release through GitHub Actions.

Project layout

Path Purpose
internal/app Orchestrator: connect, disconnect, health checks, DPI, recovery
internal/core Everything below the window, shared by the Windows app and the Linux service
internal/platform The one place that picks each OS's implementations
internal/engine Local DNS server built on dnsproxy
internal/sysdns System DNS: Windows adapters (Win32 + netsh fallback); NetworkManager, systemd-resolved and resolv.conf on Linux
internal/watchdog, internal/startup Recovery, watchdog process and scheduled tasks (Windows)
internal/dpi DPI engines (zapret2, GoodbyeDPI), signed strategy list, packet capture (WinDivert, nftables)
internal/sysproxy, internal/certstore, internal/firewall System proxy, certificate stores and firewall per OS
cmd/ghostlined, internal/rpc, internal/session Linux service, its socket protocol, and tasks run in the user's desktop session
internal/sysinstall, build/linux Linux systemd unit, service install, and the deb/rpm/AppImage/tar.gz/PKGBUILD packaging
internal/scanner, internal/probe Server latency scan and blocked-site probes
internal/servers, internal/upstreams Signed server list and DNSCrypt list
internal/shell Window, tray and OS events (Wails)
frontend/ React + TypeScript UI
lists/servers.json Signed server list, regenerated weekly by CI

Contributing

Bug reports, translations and pull requests are welcome. Please read CONTRIBUTING.md first.

Security

Please do not open a public issue for vulnerabilities. See SECURITY.md.

Disclaimer

Ghostline is provided for research and educational purposes, to study encrypted DNS, network filtering and DPI. Its main goals are privacy (keeping DNS queries from being read or logged), protection against DNS spoofing and hijacking, and network diagnostics. You are solely responsible for how you use it and for complying with the laws and regulations of your country and the terms of your network provider. Do not use Ghostline for any unlawful purpose, including:

  • reaching websites, services or content that a competent authority has ordered to be blocked under the law of your country;
  • online gambling, copyright infringement, fraud, or spreading content that is prohibited by law;
  • attacking, disrupting or getting unauthorized access to any network or system.

Ghostline does not ship, recommend or maintain lists of sites blocked by authorities. Lists and rules you add yourself are your own responsibility.

The software is provided "as is", without warranty of any kind. The authors are not liable for any damage, data loss, service disruption or legal consequences arising from its use. See LICENSE for the full terms.

License and credits

Ghostline is free software, released under the GNU General Public License v3.0 only. You may use, study, share and modify it; if you distribute a modified version, you must release its source code under the same license. Releases v0.1.0 and v0.1.1 were published under the MIT License.

It stands on the shoulders of dnsproxy, zapret2, GoodbyeDPI, WinDivert and Wails, and was inspired by DNSveil / SecureDNSClient. Third-party licenses are listed in NOTICE.

Donate

Ghostline is free and always will be. If you can, please support the projects it is built on first; they do the heavy lifting:

If you would also like to support Ghostline itself, you can send a tip through PayPal, stablecoins, or MoMo / VietQR. Thank you!

Donate with PayPal

Stablecoins (USDT or USDC):

0x3C0E297cC77416DA2Ac108F09360d7Bf7C4E2c8e

Warning

Send only through BNB Smart Chain (BEP20) or Arc. Coins sent through any other network, such as Ethereum (ERC20) or Tron (TRC20), will be lost.

MoMo / VietQR (click to show the QR code)
Scan with MoMo or any Vietnamese banking app (VietQR / Napas 247).

MoMo / VietQR donation QR code

About

One-click encrypted DNS (DoH/DoT/DoQ/DNSCrypt), DPI bypass with zapret2 or GoodbyeDPI, a local HTTP/SOCKS proxy with TLS fragmentation, and domain rules for Windows. ~30 MB RAM in the tray, no telemetry, always restores your original DNS. For research and educational use.

Topics

Resources

Contributing

Security policy

Stars

99 stars

Watchers

3 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages