Ghostline runs a local DNS server on 127.0.0.1 / ::1, points the system's DNS at it (every network adapter on Windows; NetworkManager, systemd-resolved or /etc/resolv.conf on Linux), and forwards your queries over DoH, DoT, DoQ or DNSCrypt to the fastest healthy resolver. When your network interferes with encrypted connections by inspecting packets (DPI), it can also run a DPI bypass engine: zapret2 (recommended), or GoodbyeDPI on Windows. Above all, it is built to always give your original DNS back, even if the app crashes or the machine loses power.
- Features
- Video
- Screenshots
- Install
- Usage
- How it works
- Privacy
- Known limitations
- Building from source
- Project layout
- Contributing
- Security
- Disclaimer
- License and credits
- Donate
- Encrypted DNS for the whole system: DoH, DoT, DoQ and DNSCrypt upstreams, powered by AdGuard dnsproxy.
- Automatic server choice: scans resolvers in parallel, rejects poisoned answers, and remembers the best servers per network.
- Never lose the internet: the original DNS is snapshotted before any change and always comes back. On Windows there are five recovery layers: clean disconnect, a watchdog process, restore on next launch, a logon recovery task, and a network guard that works even if an antivirus quarantines
ghostline.exe. On Linux a systemd service restores on disconnect, when it stops or crashes, and at boot. - Leak verification: after connecting, Ghostline checks that queries really go through it.
- DPI bypass: bundled, hash-pinned zapret2 v1.0.5.2 (fake packets, more split methods, QUIC for YouTube/Google), through WinDivert on Windows and an nftables queue on Linux, plus GoodbyeDPI 0.2.3rc3 on Windows. zapret2 strategies come from a signed list refreshed daily, with auto-tune, a site blacklist, automatic detection of blocked sites, and DoH request fragmentation. On Windows, if antivirus blocks zapret2, Ghostline falls back to GoodbyeDPI and offers to retry.
- Local proxy (HTTP / HTTPS / SOCKS4/5): runs with Connect, can become the system proxy (Windows, GNOME, KDE), and can be shared with phones and other devices on your Wi-Fi (QR code included). Names are always resolved through Ghostline's encrypted DNS.
- Web fragmentation without a driver: traffic through the proxy gets its TLS ClientHello split automatically when a site is blocked by SNI, and the fix is remembered per network.
- Rules and community lists: block, allow, fake DNS, fragment or route through an upstream proxy by domain, keyword, regexp or CIDR. Import hosts, AdBlock/AdGuard, dnsmasq, Unbound, RPZ, Clash, v2ray, sing-box or CIDR lists straight from a GitHub link, updated on a schedule.
- DNS server for your home network: encrypted DNS for phones, TVs, consoles and routers on your Wi-Fi: plain DNS on port 53 (no certificate needed) or DNS-over-HTTPS, with a QR-code setup page and an iOS profile.
- Fake SNI (advanced, off by default): for sites behind CDNs that allow domain fronting, the proxy sends a different, allowed domain name to the network. It decrypts HTTPS only for domains you choose, with a certificate that can sign only those domains and is removed on disconnect.
- Diagnostic tools: DNS lookup that compares sources and spots DNS poisoning, an advanced scanner that grades servers on latency, loss, DNSSEC, ad filtering and poisoning, a Cloudflare clean-IP finder that turns results into
ip=rules, and a DNS stamp reader and builder. - Backup and restore: export settings, rules, lists and your servers to one file and import them on another PC. Private and machine-bound values are never exported, and an import never turns on Fake SNI or sharing on the LAN.
- Signed server list: updated daily and verified with ed25519; the DNSCrypt list is checked with minisign.
- Simple and Full interfaces, a tray icon, Vietnamese and English UI, and a neon-terminal look.
- Installer, portable or Linux packages: on Windows, an installer or a portable build that keeps all data in a
data\folder next to the exe; on Linux,.deb,.rpm, AppImage,tar.gzand a PKGBUILD. - Update notifications only: Ghostline tells you about a new version and never updates itself silently.
A narrated walkthrough of a little over 3 minutes: one-click connect, protection levels, servers, DPI bypass, the proxy, rules, the DNS server with the iPhone setup, Fake SNI, the diagnostic tools and backup. The preview below plays sped up and silent; click it for the full video with sound. A Vietnamese version is also available.
Short narrated clips, one per feature: Connect · Protection levels · Servers · DPI bypass · Proxy · Rules · DNS server and iPhone · Fake SNI · Tools · Test domain and backup · Disconnect. The user guide shows each one next to its step-by-step instructions.
| Servers | DPI bypass |
|---|---|
![]() |
![]() |
| Proxy | Rules and lists |
![]() |
![]() |
| Logs | Settings |
![]() |
![]() |
| DNS server | Fake SNI |
![]() |
![]() |
| Lookup | Cloudflare IP |
![]() |
![]() |
⬇ Download the latest release — or pick a file below. Older versions are on the Releases page.
| File | What it is | Download |
|---|---|---|
ghostline-amd64-installer.exe |
Installer (installs WebView2 if missing) | Direct download ⬇ |
Ghostline-<version>-portable.zip |
Portable: unzip and run | From latest release |
SHA256SUMS |
Checksums for both | Direct download |
Verify the download:
Get-FileHash .\Ghostline-0.1.0-portable.zip -Algorithm SHA256Requirements: Windows 10/11 x64 and administrator rights. Changing adapter DNS and loading the WinDivert driver both need admin. When Ghostline starts with Windows it runs through Task Scheduler, so there is no UAC prompt.
Note
Releases are not code-signed yet, so SmartScreen shows "Windows protected your PC". After checking the SHA-256, choose More info → Run anyway.
Some antivirus products flag the WinDivert driver used by zapret2 and GoodbyeDPI. Ghostline verifies the engine's hash before every start; if your antivirus blocks zapret2, Ghostline runs GoodbyeDPI for now and the DPI page shows the bin\zapret2 folder to add to the exclusions.
| Distribution | File | Install |
|---|---|---|
| Ubuntu 24.04+, Debian 13+ | ghostline_<version>_amd64.deb |
sudo apt install ./ghostline_<version>_amd64.deb |
| Fedora 41+ | ghostline-<version>-1.x86_64.rpm |
sudo dnf install ./ghostline-<version>-1.x86_64.rpm |
| Arch, CachyOS, Manjaro | ghostline-<version>-linux-amd64.tar.gz |
Unpack it and run sudo ./install.sh, or build ghostline-bin from the PKGBUILD attached to the release (makepkg -si) |
| Other distributions | Ghostline-<version>-x86_64.AppImage |
chmod +x and run it; it offers to install the background service |
Verify the downloads: sha256sum -c SHA256SUMS --ignore-missing.
Ghostline on Linux is two parts: a background service (ghostline.service, root) that changes DNS, runs zapret2 and keeps protecting with the window closed and after a reboot, and the window, which runs as your user. Members of wheel, sudo, admin or the ghostline group can control it; to allow another account: sudo usermod -aG ghostline <user>, then log in again. The deb and rpm start the service right away; on Arch start it once with sudo systemctl enable --now ghostline (or the button in the window).
Requirements: systemd, GTK 4 and WebKitGTK 6.0 (the packages pull them in; the AppImage and the tar.gz use the system's).
Update: install the new .deb or .rpm, or rebuild ghostline-bin from the new PKGBUILD. If the service came from the AppImage, open the new AppImage: it finds the older service and updates it once you enter your password (cancelled, the banner at the top keeps an update the service button). From the tar.gz, unpack the new one and run sudo ./install.sh once (it replaces the service and restarts it).
Uninstall: sudo apt remove ghostline (apt purge also deletes the settings), sudo dnf remove ghostline, sudo pacman -R ghostline-bin; tar.gz: sudo ./uninstall.sh [--purge] in the unpacked folder; AppImage: sudo /var/lib/ghostline/bin/ghostlined --uninstall-system [--purge], then delete the AppImage file. DNS, the system proxy, certificates, firewall rules and the nftables table are restored first. rpm and Arch keep the settings: sudo rm -rf /var/lib/ghostline /var/log/ghostline removes them.
📖 A detailed user guide covering every screen, unblocking sites and troubleshooting: docs/user-guide.md (Tiếng Việt)
- Start Ghostline and press Connect. It picks a server, redirects DNS and verifies there is no leak.
- If some sites are still blocked, either turn on the proxy (Full → Proxy → enable proxy + use for this PC) so browsers get automatic fragmentation, or open Full → DPI bypass, pick an engine (zapret2 is recommended), turn it on and press auto-tune. To share with other devices, turn on share on LAN and scan the QR code on your phone (on Windows the network must be Private).
- Press Disconnect (or quit from the tray) to restore your original DNS.
If DNS ever looks wrong, Settings → Restore DNS now puts the system's DNS back to its saved state. From a terminal you can also run:
ghostline.exe --restoreOn Linux, stopping the service restores DNS: sudo systemctl stop ghostline (then sudo systemctl start ghostline).
apps ──► system DNS ──► 127.0.0.1:53 (Ghostline / dnsproxy) ──► DoH · DoT · DoQ · DNSCrypt
(Windows DNS client, NetworkManager, │
systemd-resolved or resolv.conf) │
zapret2 / GoodbyeDPI (optional) rewrites outgoing TLS/HTTP/QUIC to dodge SNI filtering
On Linux, Ghostline is a root service (ghostlined, run by systemd) that owns DNS, DPI and the proxy, and a window that runs as your user and talks to it over a local socket. Closing the window does not stop protection.
Safety net. Before changing DNS, Ghostline writes a snapshot (state.json) of it. On Windows, five layers make sure that snapshot gets restored:
- Clean disconnect: the normal path.
- Watchdog: a separate
--watchdogprocess restores DNS within seconds if the app dies. - Next launch: a leftover snapshot is restored at startup.
- Logon task: the
Ghostline Recoveryscheduled task runs--restoreafter a crash or power loss. - Network guard: while connected, the
Ghostline Network Guardtask runs a PowerShell script as SYSTEM every minute, at boot and right after Microsoft Defender acts on a threat. If Ghostline is gone but DNS still points at 127.0.0.1, it restores DNS and the system proxy fromstate.json. It does not needghostline.exe, so it still works when an antivirus kills and quarantines the app along with the layers above.
On Linux, systemd is the watchdog: the service restores on disconnect, ExecStopPost=--restore runs whenever it stops or crashes (even after kill -9), and at boot the service restores whatever a power cut left before anything else.
Design details live in docs/superpowers/specs, and docs/platforms.md maps each feature to its Windows and Linux code.
- No telemetry, no accounts, no analytics.
- Visited domains are never written to disk. The optional query log lives in RAM only.
- Network access is limited to your chosen DNS resolvers, bootstrap resolution of their hostnames, the signed server list, the DNSCrypt resolver list, the GitHub release check, and the community lists you add yourself.
- The proxy never logs destinations to disk; its live connection view is RAM-only like the query log.
- Fake SNI works only for browsers on this PC going through the proxy, only for domains with an
sni=rule, and breaks apps that pin certificates. Firefox may needsecurity.enterprise_roots.enabled. - Devices using this PC's DNS lose the internet when it is off or disconnected. iOS has no fallback: with the DoH profile, the iPhone has no internet on your home Wi-Fi until you choose Automatic in Settings › General › VPN & Device Management › DNS (mobile data is not affected). Disconnect asks first while LAN devices use the DNS server; if this PC is often off, set the iPhone's DNS manually instead of using the profile. Android's Private DNS cannot use Ghostline; set a static DNS for your Wi-Fi instead.
- If you approve UAC with a different administrator account,
%APPDATA%and the system proxy belong to that account, so "use for this PC" does not affect the signed-in user. - Web fragmentation only helps apps that go through the proxy. Apps that ignore the Windows proxy (some games, Firefox with its own proxy settings) need the DPI engine instead.
- LAN sharing works only on networks marked Private in Windows; Ghostline never changes the network profile itself.
- GNOME has no tray by default: with close to tray on, a closed window has no icon to click; open Ghostline again from the app menu to bring it back, or turn the setting off so ✕ quits. Protection keeps running in the background service either way.
- The system proxy is set automatically only on GNOME and KDE; on other desktops set
127.0.0.1:<port>by hand. - Fake SNI in Chrome and Chromium on Ubuntu and Debian needs
libnss3-tools(certutil). - A kernel without NFQUEUE (
nfnetlink_queue,nft_queue) has no DPI bypass; the proxy's fragmentation still works. - No GoodbyeDPI (it is Windows-only); zapret2 is the engine.
- Packages are not GPG-signed yet: check
SHA256SUMS. - The AppImage needs glibc 2.39 or newer (Ubuntu 24.04, Debian 13, Fedora 40 and later).
- SteamOS (Steam Deck) is not verified yet.
Prerequisites: Go 1.27+, Node.js 24, Wails v3 v3.0.0-beta.27, and NSIS for the Windows installer.
go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-beta.27
wails3 dev # live-reload dev build (connecting for real needs admin)
wails3 build # bin/ghostline.exe
wails3 package # NSIS installer
wails3 task windows:portable # portable zipOn Linux (GTK 4 and WebKitGTK 6.0 development packages, plus squashfs-tools for the AppImage):
wails3 task linux:build # bin/linux/ghostline and bin/linux/ghostlined
wails3 task linux:package VERSION=0.6.1 # deb, rpm, AppImage and tar.gz in bin/Tests:
go test ./...
cd frontend && npm testIntegration tests change real system settings, so run them in an admin terminal on Windows:
go test -tags integration ./internal/sysdns/... ./internal/startup/...and as root on Linux (system DNS, the nftables queue with nfqws2, recovery after kill -9):
sudo -E env "PATH=$PATH" go test -tags integration_root ./internal/sysdns/ ./internal/dpi/ ./cmd/ghostlined/Before a release, go through docs/release-checklist.md. Pushing a v* tag builds and publishes the release through GitHub Actions.
| Path | Purpose |
|---|---|
internal/app |
Orchestrator: connect, disconnect, health checks, DPI, recovery |
internal/core |
Everything below the window, shared by the Windows app and the Linux service |
internal/platform |
The one place that picks each OS's implementations |
internal/engine |
Local DNS server built on dnsproxy |
internal/sysdns |
System DNS: Windows adapters (Win32 + netsh fallback); NetworkManager, systemd-resolved and resolv.conf on Linux |
internal/watchdog, internal/startup |
Recovery, watchdog process and scheduled tasks (Windows) |
internal/dpi |
DPI engines (zapret2, GoodbyeDPI), signed strategy list, packet capture (WinDivert, nftables) |
internal/sysproxy, internal/certstore, internal/firewall |
System proxy, certificate stores and firewall per OS |
cmd/ghostlined, internal/rpc, internal/session |
Linux service, its socket protocol, and tasks run in the user's desktop session |
internal/sysinstall, build/linux |
Linux systemd unit, service install, and the deb/rpm/AppImage/tar.gz/PKGBUILD packaging |
internal/scanner, internal/probe |
Server latency scan and blocked-site probes |
internal/servers, internal/upstreams |
Signed server list and DNSCrypt list |
internal/shell |
Window, tray and OS events (Wails) |
frontend/ |
React + TypeScript UI |
lists/servers.json |
Signed server list, regenerated weekly by CI |
Bug reports, translations and pull requests are welcome. Please read CONTRIBUTING.md first.
Please do not open a public issue for vulnerabilities. See SECURITY.md.
Ghostline is provided for research and educational purposes, to study encrypted DNS, network filtering and DPI. Its main goals are privacy (keeping DNS queries from being read or logged), protection against DNS spoofing and hijacking, and network diagnostics. You are solely responsible for how you use it and for complying with the laws and regulations of your country and the terms of your network provider. Do not use Ghostline for any unlawful purpose, including:
- reaching websites, services or content that a competent authority has ordered to be blocked under the law of your country;
- online gambling, copyright infringement, fraud, or spreading content that is prohibited by law;
- attacking, disrupting or getting unauthorized access to any network or system.
Ghostline does not ship, recommend or maintain lists of sites blocked by authorities. Lists and rules you add yourself are your own responsibility.
The software is provided "as is", without warranty of any kind. The authors are not liable for any damage, data loss, service disruption or legal consequences arising from its use. See LICENSE for the full terms.
Ghostline is free software, released under the GNU General Public License v3.0 only. You may use, study, share and modify it; if you distribute a modified version, you must release its source code under the same license. Releases v0.1.0 and v0.1.1 were published under the MIT License.
It stands on the shoulders of dnsproxy, zapret2, GoodbyeDPI, WinDivert and Wails, and was inspired by DNSveil / SecureDNSClient. Third-party licenses are listed in NOTICE.
Ghostline is free and always will be. If you can, please support the projects it is built on first; they do the heavy lifting:
- zapret2 by bol-van: the DPI bypass engine
- GoodbyeDPI by ValdikSS
- WinDivert by basil00
- dnsproxy by AdGuard
- Wails
If you would also like to support Ghostline itself, you can send a tip through PayPal, stablecoins, or MoMo / VietQR. Thank you!
Stablecoins (USDT or USDC):
0x3C0E297cC77416DA2Ac108F09360d7Bf7C4E2c8e
Warning
Send only through BNB Smart Chain (BEP20) or Arc. Coins sent through any other network, such as Ethereum (ERC20) or Tron (TRC20), will be lost.













