TheGreatWall VS dohservers

Compare TheGreatWall vs dohservers and see what are their differences.

TheGreatWall

Prevent program and malware to bypass DNS filter by using DoH (by Sekhan)

dohservers

A list of publicly available DNS over HTTPS (DoH) servers (by oneoffdallas)
Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
TheGreatWall dohservers
11 12
103 227
- -
0.0 3.8
almost 2 years ago about 2 months ago
MIT License MIT License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

TheGreatWall

Posts with mentions or reviews of TheGreatWall. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-02-24.
  • Restrict DNS resolution to pihole only
    3 projects | /r/pihole | 24 Feb 2023
    Here's lists: https://github.com/Sekhan/TheGreatWall
  • AdGuard Home and dealing with DoH
    4 projects | /r/Adguard | 17 Mar 2022
    I run Pfsense and am able to block most common DoH services. I’m sure you will be able to configure similar options on opnsense. The best way to do this is a DNS block through AGH and an IP block with opnsense. Firefox provides what domains to block to disable their DoH, https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https. You can also add these two lists to block most other common DoH services, https://github.com/oneoffdallas/dohservers, https://github.com/Sekhan/TheGreatWall. These lists will work with AGH for DNS blocking and for IP blocking aliases. If you have any Apple devices on your network you can use these domains to block private relay, https://raw.githubusercontent.com/Rogacz/private-relay/main/pr2.txt. I recommend you add these private relay domains as a custom entry in AGH to return NXDOMAIN so that the device shows that private relay is unavailable versus using a NULL response where it will say it’s available when it really isn’t. With these lists added to DNS blocklists as well as IP blocklists I have seen almost no DoH services getting through. The only service that I’ve experienced getting through the rules so far is Next DNS since it uses different IPs depending on what is fastest for your location, making it harder to block. I found a way to discover the IPs for their servers near you and will edit the post if I find the instructions again. Also make sure to completely block port 853 to block DoT. Lastly using these instructions from Pfsense, you can redirect or block all DNS queries that aren’t destined for your AGH instance. The instructions should be transferable to opnsense.
  • Device has not a single query?
    1 project | /r/pihole | 3 Jan 2022
    You can also have the pihole block these DoH servers, using this: https://github.com/Sekhan/TheGreatWall/blob/master/TheGreatWall.txt but for applications that have a list DoH IP's hardwired into them, then pihole blocking won't catch those because they connect without DNS lookups. You have to block them at your firewall.
  • PSA - Netflix on iOS seems to be contacting 8.8.8.8 (Google DNS) a lot, possibly to circumvent blocking
    1 project | /r/pihole | 15 Dec 2021
  • Blocklist for DNS over HTTPS?
    4 projects | /r/pihole | 22 Oct 2021
  • How long until Google [and others] use https://8.8.8.8 internally, and hence bypass Pi-Hole?
    2 projects | /r/pihole | 28 Jun 2021
  • Any guide to catching and redirecting DoH traffic?
    1 project | /r/opnsense | 13 Jun 2021
  • Adguar home question
    2 projects | /r/Adguard | 23 Mar 2021
    Original: https://github.com/Sekhan/TheGreatWall
  • Android defaults to 8.8.8.8 as secondary DNS with Pi-hole as DHCP server
    2 projects | /r/pihole | 19 Mar 2021
    Another test is android also offers Private DNS under advanced settings if set to automatic it will send requests to google DoH, turn this off and see if that changes anything. You could also add the The Great Wall DoH pihole blocklist to see if that helps too: https://github.com/Sekhan/TheGreatWall/blob/master/TheGreatWall.txt
  • Blocking DNS over HTTPS Suggestions
    1 project | /r/homelab | 15 Jan 2021
    Hopefully this helps: https://github.com/Sekhan/TheGreatWall

dohservers

Posts with mentions or reviews of dohservers. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-02-24.
  • Restrict DNS resolution to pihole only
    3 projects | /r/pihole | 24 Feb 2023
    shouldn't be that hard, just load one of these... https://github.com/Sekhan/TheGreatWall https://github.com/oneoffdallas/dohservers
  • Private IPs in Public DNS: Android Private DNS by default, LetsEncrypt
    1 project | /r/homelab | 29 Jan 2023
    No reason to put private IPs in public DNS. Use split DNS and block port 853 and use this list for DoH.
  • nextDNS being blocked; solutions
    2 projects | /r/nextdns | 3 Sep 2022
  • Blocklist for other DNS/DoH/DoT services
    2 projects | /r/nextdns | 30 Aug 2022
    There is some meager effort like this, but it's seriously trivial for one to create their own DoH proxy, or heck, just create their own NextDNS config. So even if you block port 853 (used by DoT & DoQ) and port 53 (unencrypted DNS), DoH traffic is simply unstoppable, yes there is traffic analysis, but with DoH3 it would be impossible to detect an innocuous-looking website serving regular traffic has a hidden DoH endpoint.
  • AdGuard Home and dealing with DoH
    4 projects | /r/Adguard | 17 Mar 2022
    I run Pfsense and am able to block most common DoH services. I’m sure you will be able to configure similar options on opnsense. The best way to do this is a DNS block through AGH and an IP block with opnsense. Firefox provides what domains to block to disable their DoH, https://support.mozilla.org/en-US/kb/configuring-networks-disable-dns-over-https. You can also add these two lists to block most other common DoH services, https://github.com/oneoffdallas/dohservers, https://github.com/Sekhan/TheGreatWall. These lists will work with AGH for DNS blocking and for IP blocking aliases. If you have any Apple devices on your network you can use these domains to block private relay, https://raw.githubusercontent.com/Rogacz/private-relay/main/pr2.txt. I recommend you add these private relay domains as a custom entry in AGH to return NXDOMAIN so that the device shows that private relay is unavailable versus using a NULL response where it will say it’s available when it really isn’t. With these lists added to DNS blocklists as well as IP blocklists I have seen almost no DoH services getting through. The only service that I’ve experienced getting through the rules so far is Next DNS since it uses different IPs depending on what is fastest for your location, making it harder to block. I found a way to discover the IPs for their servers near you and will edit the post if I find the instructions again. Also make sure to completely block port 853 to block DoT. Lastly using these instructions from Pfsense, you can redirect or block all DNS queries that aren’t destined for your AGH instance. The instructions should be transferable to opnsense.
  • AdGuard Home - Docker
    2 projects | /r/selfhosted | 22 Feb 2022
    I’ve also been using this to block doh domains: https://github.com/travisboss/TheGreatWall - and in conjunction, at router level, I block their IP endpoints: https://github.com/oneoffdallas/dohservers
  • How to properly block DNS ? (not only port 53)
    2 projects | /r/Ubiquiti | 27 Oct 2021
    DoH serves is another story of course. You can at least check https://github.com/oneoffdallas/dohservers/ It can be imported directly into Pi-Hole
  • Blocking DoH for family filter
    2 projects | /r/PFSENSE | 21 Oct 2021
    After reading through this and looking at some other sources I think I am going to create a URL Table of IPs that updates every X days using the list from https://github.com/oneoffdallas/dohservers/blob/master/iplist.txt . And I'll add in the few Cloudflares that it has commented out. And I'll use that alias to block outgoing 443 to those IPs. It seems pretty low maintenance and I don't have to have another package installed, which I was hoping to avoid. And I'll block all outgoing 853 as well. We'll see how it goes
  • (Update) Ubiquiti refuses to disclose why they are tracking us.
    1 project | /r/Ubiquiti | 4 Mar 2021
    Step 5: Add the DNS over HTTPS lists to your pihole (https://github.com/oneoffdallas/dohservers)
  • Breach of privacy in Home Assistant's implementation of CoreDNS discovered.
    3 projects | /r/homeassistant | 28 Jan 2021
    This isn't a complete approach, but you can block outgoing traffic from hitting DoH servers. https://raw.githubusercontent.com/Sekhan/TheGreatWall/master/TheGreatWall_ipv4 https://github.com/oneoffdallas/dohservers

What are some alternatives?

When comparing TheGreatWall and dohservers you can also consider the following projects:

blocklists - Domain-ONLY Filter Lists (for use with DNS / Domain blocking tools)

ProxyDNS - Tool written in C which bypasses DNS-based internet censorship even when port 53 is intercepted. No longer supported.

Inversion-DNSBL-Blocklists - Malicious URLs identified by scanning various public URL sources using the Google Safe Browsing API (over 6 billion URLs scanned daily)

doh-cf-workers - DNS-over-HTTPS proxy on Cloudflare Workers

pihole-phishtank-list - A blocklist for Pihole from PhishTank

DoH

Pi-hole - A black hole for Internet advertisements

TheGreatWall - Prevent program and malware to bypass DNS filter by using DoH

plugin-dns - CoreDNS implementation for Home Assistant

1Hosts - World's most advanced DNS filter-/blocklists!