Brief Introduction
dnstt is a censorship circumvention method that creates a DNS tunnel and uses DNS over HTTPS (DoH) and DNS over TLS (DoT) resolvers, making it difficult for a network observer to tell that a tunnel is being used.
You can read more about dnstt and how it works and browse the source code on the project’s website.
dnstt can be used with Tor as a pluggable transport.
Using dnstt with Orbot
Latest versions of Orbot have built-in support for dnstt.
Step 1. Please make sure you are using the latest version of Orbot.
On Android:
- At least Orbot version 17.9.3-RC-1.
- To check the version of Orbot you have installed, tap on ‘More’ after launching the app. The version number should be listed on this page.
On iOS:
- At least Orbot version 1.10.0.
- To check the version of Orbot you have installed, after launching the app, tap on the dotted menu button on top right. Tap on ‘Settings’, The version number should be listed at the end of this page.
Step 2. Copy the following Tor dnstt bridge lines.
dnstt 192.0.2.4:1 A998F319ADB60EE344540EC4B21524CC484F96BE doh=https://dns.google/dns-query pubkey=241169008830694749fe96bb070c4855c5bb5b9c47b3833ed7d88521ba30a43f domain=t.ruhnama.net
dnstt 192.0.2.4:2 80EEFA4F4875ED2B7B5A86DF2D7588AD32E29F15 doh=https://dns.google/dns-query pubkey=a2fb71077eeaa54a02cda7a90be306af5d299ab21822a8b277d4eacbc9168631 domain=t2.bypasscensorship.org
dnstt 192.0.2.4:3 74D409BED3E2F881F365543A72C8F079CB84FFEB doh=https://dns.google/dns-query pubkey=c596c458fc3453dc40903ab235f5854a2609831075640c4c5584f76de05b8271 domain=t.arkadag.org
Step 3. Launch the Orbot app.
- On Android, tap on ‘Set Transport’.
- On iOS, tap on ‘Choose How to Connect’
Step 4. Select ‘Custom Bridges’ and then tap on ‘Next’ and finally paste the bridge lines.
Step 5. Tap on “Connect”.
Important: If dns.google is blocked, please use other DNS resolver (DoH or DoT).