DoH VS TheGreatWall

Compare DoH vs TheGreatWall and see what are their differences.

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
DoH TheGreatWall
18 11
52 103
- -
1.2 0.0
about 1 year ago almost 2 years ago
PHP
MIT License MIT License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

DoH

Posts with mentions or reviews of DoH. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-03-06.
  • Encrypted DNS, what's the point?
    3 projects | /r/privacy | 6 Mar 2023
    Even those who weren't interested in self-hosting might spend a couple of minutes hosting their own DNS proxy since it's much more flexible and don't require root or dedicated port (at least with DoH).
  • I have a feeling 1.1.1.1 + WARP isn't gonna last long
    2 projects | /r/indonesia | 30 Jul 2022
  • AdGuard Home and dealing with DoH
    4 projects | /r/Adguard | 17 Mar 2022
    To inject a little paranoia, DoH spec and implementation don't actually require the providers to only use /dns-query, it's possible (and very simple) to create an innocuous-looking website with /supersecretdns serving DoH, or directly on the homepage itself (the request for DoH vs regular webpage has different header), but if your kids are already that proficient, no way to stop them aside from plugging off the router.
  • Preparing for when NextDNS gets blocked
    3 projects | /r/nextdns | 15 Feb 2022
    Get a PHP hosting (dime a dozen these days), and proxying on PHP is also seamless, pretty much any website can have a secret URL that serves DoH.
  • Tiny script for DoH proxy
    1 project | /r/dns | 28 Dec 2021
    https://github.com/NotMikeDEV/DoH/blob/master/dns.php handles both POST & GET. Yours only work with the POST, used by Chrome & Firefox, but not AdGuard.
  • Is there any issue with playing DoH DNS roulette?
    1 project | /r/dns | 23 Nov 2021
    If you are paranoid about a particular DNS server knowing your requests (but not paranoid enough to just use Tor entirely), the alternative will be just running a recursive resolver where you're running that PHP file. This exposes your server IP to the nameserver, but that's it, no extra third parties are involved. Or take it to the next level by running Tor there and forwarding plain DNS requests through it.
  • Anyone know of a free service I can host a custom dns on
    2 projects | /r/dns | 17 Nov 2021
    DoH can be somewhat protected with a secret path, you can even create one for free on Cloudflare Worker or any PHP hosting, but only Windows 11, iOS, macOS, and browsers support it natively. DoT is supported by Android natively but hiding the custom domain is more complex (you'll need wildcard cert, which requires manual record update with LetsEncrypt every 90 days), and if someone snoops on your traffic since they can see the domain for the DoT.
  • Dirt simple PHP script to run DNS over HTTPS (DoH) on almost any hosting
    1 project | /r/programming | 6 Nov 2021
  • Is there any DoH add-on for WordPress?
    1 project | /r/Wordpress | 20 Sep 2021
  • My ISP starts hijacking dns servers so unbound stopped working
    6 projects | /r/pihole | 18 Jun 2021
    That relies on a list of known DoH providers. Private DoH server won't be in the list, which can be very easily made on any PHP hosting or even just a Cloudflare Worker.

TheGreatWall

Posts with mentions or reviews of TheGreatWall. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-02-24.
  • Restrict DNS resolution to pihole only
    3 projects | /r/pihole | 24 Feb 2023
    Here's lists: https://github.com/Sekhan/TheGreatWall
  • AdGuard Home and dealing with DoH
    4 projects | /r/Adguard | 17 Mar 2022
    I run Pfsense and am able to block most common DoH services. I’m sure you will be able to configure similar options on opnsense. The best way to do this is a DNS block through AGH and an IP block with opnsense. Firefox provides what domains to block to disable their DoH, https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https. You can also add these two lists to block most other common DoH services, https://github.com/oneoffdallas/dohservers, https://github.com/Sekhan/TheGreatWall. These lists will work with AGH for DNS blocking and for IP blocking aliases. If you have any Apple devices on your network you can use these domains to block private relay, https://raw.githubusercontent.com/Rogacz/private-relay/main/pr2.txt. I recommend you add these private relay domains as a custom entry in AGH to return NXDOMAIN so that the device shows that private relay is unavailable versus using a NULL response where it will say it’s available when it really isn’t. With these lists added to DNS blocklists as well as IP blocklists I have seen almost no DoH services getting through. The only service that I’ve experienced getting through the rules so far is Next DNS since it uses different IPs depending on what is fastest for your location, making it harder to block. I found a way to discover the IPs for their servers near you and will edit the post if I find the instructions again. Also make sure to completely block port 853 to block DoT. Lastly using these instructions from Pfsense, you can redirect or block all DNS queries that aren’t destined for your AGH instance. The instructions should be transferable to opnsense.
  • Device has not a single query?
    1 project | /r/pihole | 3 Jan 2022
    You can also have the pihole block these DoH servers, using this: https://github.com/Sekhan/TheGreatWall/blob/master/TheGreatWall.txt but for applications that have a list DoH IP's hardwired into them, then pihole blocking won't catch those because they connect without DNS lookups. You have to block them at your firewall.
  • PSA - Netflix on iOS seems to be contacting 8.8.8.8 (Google DNS) a lot, possibly to circumvent blocking
    1 project | /r/pihole | 15 Dec 2021
  • Blocklist for DNS over HTTPS?
    4 projects | /r/pihole | 22 Oct 2021
  • How long until Google [and others] use https://8.8.8.8 internally, and hence bypass Pi-Hole?
    2 projects | /r/pihole | 28 Jun 2021
  • Any guide to catching and redirecting DoH traffic?
    1 project | /r/opnsense | 13 Jun 2021
  • Adguar home question
    2 projects | /r/Adguard | 23 Mar 2021
    Original: https://github.com/Sekhan/TheGreatWall
  • Android defaults to 8.8.8.8 as secondary DNS with Pi-hole as DHCP server
    2 projects | /r/pihole | 19 Mar 2021
    Another test is android also offers Private DNS under advanced settings if set to automatic it will send requests to google DoH, turn this off and see if that changes anything. You could also add the The Great Wall DoH pihole blocklist to see if that helps too: https://github.com/Sekhan/TheGreatWall/blob/master/TheGreatWall.txt
  • Blocking DNS over HTTPS Suggestions
    1 project | /r/homelab | 15 Jan 2021
    Hopefully this helps: https://github.com/Sekhan/TheGreatWall

What are some alternatives?

When comparing DoH and TheGreatWall you can also consider the following projects:

Unbound - Unbound is a validating, recursive, and caching DNS resolver.

blocklists - Domain-ONLY Filter Lists (for use with DNS / Domain blocking tools)

docker-cloudflared - Cloudflared proxy-dns Docker image

Inversion-DNSBL-Blocklists - Malicious URLs identified by scanning various public URL sources using the Google Safe Browsing API (over 6 billion URLs scanned daily)

encrypted-dns - DNS over HTTPS config profiles for iOS & macOS

pihole-phishtank-list - A blocklist for Pihole from PhishTank

bebasdns - Membantumu berselancar dengan aman dan tidak terbatas!.

Pi-hole - A black hole for Internet advertisements

dnsproxy - Simple DNS proxy with DoH, DoT, DoQ and DNSCrypt support

1Hosts - World's most advanced DNS filter-/blocklists!

doh-cf-workers - DNS-over-HTTPS proxy on Cloudflare Workers