Encrypted Transport Active

Recursive Resolution. Zero Upstream Tracking.

A private, DNSSEC-validating recursive resolver backed by NGINX, AdGuard Home, and Knot. Block ads, trackers, and adult content at the network level without forwarding queries to third-party resolvers.

Resolver Statistics

Live
Fetching stats…

Top Queried Domains · AGH window

Top Blocked Domains · AGH window

DoH / DoH3

Port 443 PQC Active

Proxied via NGINX with Post-Quantum hybrid key exchange (ML-KEM) and HTTP/3.

URI Template
https://dns.salmanshafi.net/dns-query/

DNS-over-TLS (DoT)

Port 853

Native Android and router integration. PQC awaiting upstream support.

Hostname
dns.salmanshafi.net

DNS-over-QUIC (DoQ)

UDP 853

Rapid handshakes and zero head-of-line blocking for mobile networks.

URI Template
quic://dns.salmanshafi.net

Plain DNS (Unencrypted) — Not Recommended

Port 53 Unencrypted

Plain DNS does not encrypt your queries. Your ISP can see every domain you resolve. Additionally, the server IP may change in the future without notice. Use only if you fully understand the risks.

103.174.50.32
2001:df7:b880:4::53

Architecture Stack

Hosted on AlmaLinux 10 in Bangladesh, the multi-stage stack operates as a fully self-contained recursive resolver.

NGINX fronts the edge with TLS termination and PQC. AdGuard Home applies network filters, immediately forwarding unblocked queries locally to Knot Resolver for root resolution.

Location MetroVPS (Bangladesh)
Edge Proxy NGINX (PQC Terminated)
Policy Engine AdGuard Home (:5380)
Backend Knot Resolver (127.0.0.53)

Resolution Pipeline

Left-to-right transport branches, then top-to-bottom recursive resolver pipeline.

Client Device

Initiates DNS query

Port 53

Plain DNS

Unencrypted, ISP visible

Port 853

DoT / DoQ

Encrypted, Direct

Port 443

DoH / DoH3

NGINX & PQC Terminated

Policy Engine

AdGuard Home

Blocklists Allowlists SafeSearch

Knot Resolver

Recursive Backend — DNSSEC Validation, QNAME Minimisation, 1GB Cache

Root, TLD, Authoritative DNS

Direct recursive walk — no third-party forwarding

Configuration Guide

Select your platform to configure encrypted DNS resolution.

Android Private DNS

01
Navigate to Settings > Network & internet.
02
Tap on Private DNS.
03
Select Private DNS provider hostname and enter:
dns.salmanshafi.net

Active Filter Policies

Synchronised blocklists operating at the AdGuard Home layer.