finds.dev← search

// the find

svenshi/oxidns

★ 533 · Rust · GPL-3.0 · updated Sep 2026

A high-performance, programmable DNS engine in Rust with flexible pipeline-based routing.

OxiDNS is a Rust-based DNS resolver/policy engine aimed at OpenWrt routers, homelabs, and advanced self-hosted networks, built as a more general successor to mosdns. Instead of simple domain-to-upstream rule splitting, it lets you compose matchers, executors, and providers into a 'sequence' pipeline that can route, cache, rewrite, and trigger network side effects (firewall sets, RouterOS routes) based on query and response data. It's for people running their own DNS infra who want fine-grained control and observability, not for someone who wants a one-click ad blocker.

The sequence/matcher/executor/provider model is a real generalization over mosdns's plugin chain — it treats DNS decisions as a composable pipeline rather than a fixed rule-then-forward flow, which is genuinely useful for multi-upstream, multi-protocol setups. It has an actual benchmark suite in-repo (benchmarks/configs comparing against mosdns, smartdns, AdGuardHome with matching scenario configs) rather than just asserting performance. Protocol coverage is broad and symmetric — UDP/TCP/DoT/DoQ/DoH on both the listening and upstream side, with shared connection reuse and concurrent-response arbitration. The DNS-to-network-effect integration (ipset/nftset, RouterOS address lists, webhooks) is a feature most DNS forwarders don't attempt and it's built as first-class output, not a bolt-on script hook.

The README (and presumably most of the useful design detail) is Chinese-first with an English version as a secondary artifact — a lot of the architecture reasoning lives behind an external docs site rather than in the repo, so you can't fully judge implementation quality without leaving GitHub. It's maintained by one person who explicitly states in the README they're job-hunting, which is a real continuity risk for something you'd run as core network infra. DNSSEC shows up in the wire codec (rdata/dnssec.rs) but isn't listed anywhere in the feature table, so it's unclear whether it's parse-only or actually validated — worth checking before relying on it. And by the project's own admission this isn't authoritative DNS and isn't a turnkey ad-blocking panel; the policy-pipeline model is powerful but means real config investment before it does anything useful, unlike drop-in alternatives.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →