🛡️ DoH Proxy Pro

🚀 DoH Proxy Pro

A personal DNS over HTTPS proxy on your own domain that forwards only to Cloudflare's resolver — for bypassing filtering at the DNS layer.

runtimeCloudflare Workers protocolDNS-over-HTTPS providersCloudflare only licenseMIT
Active and ready — forwarding to Cloudflare's resolver with automatic failover and caching
This is an advanced DNS over HTTPS (DoH) service with anti-censorship features.
Queries are forwarded only to Cloudflare's own resolver (the same company already hosting this proxy), so no additional third party ever sees your DNS traffic. Includes DNS Padding, ECS Stripping, Negative Caching, Adaptive Timeouts, and automatic failover between Cloudflare endpoints.
📊 View Live Server Statistics

📍 Your Service Address

https://cloudflare-e8a.pages.dev/dns-query

✨ Advanced Features

☁️
Cloudflare-only upstream — queries are forwarded only to Cloudflare's own public resolver, never to third parties
🎯
Single-upstream forwarding — each query goes to one resolver; the next one is tried only if it fails
🛡️
Circuit Breaker Pattern — temporarily takes a failing endpoint out of rotation and brings it back automatically
⏱️
Adaptive Timeouts — automatically adjusts wait time based on each endpoint's history
🔒
DNS Padding per RFC 8467 — prevents packet-size analysis
🚫
ECS Stripping — genuinely removes EDNS Client Subnet from the OPT record
💾
Smart Caching with automatic management of cache size and expiry
🔁
Negative Caching — intelligent caching of NXDOMAIN responses
🔗
Request Coalescing — merges concurrent requests for the same query to reduce latency
🌏
Full CORS support for browser requests
📡
JSON DoH API support with the application/dns-json format

🌐 DNS Providers Used

cloudflare-dns.com — primary
1.1.1.1 / 1.0.0.1
mozilla.cloudflare-dns.com
brave.cloudflare-dns.com
All endpoints are Cloudflare's unfiltered public resolver; the others serve only as fallbacks
✅ What this DoH proxy does

• Fully encrypts DNS requests over HTTPS
• Bypasses DNS poisoning and prevents tampering with DNS responses
• Opens websites filtered at the DNS layer
• Improves privacy — your ISP cannot see which domains you query
• Prevents man-in-the-middle attacks at the DNS layer
• Higher speed with Smart Caching, Request Coalescing, and automatic failover
💡 Understanding filtering types

Network filtering usually happens at several independent layers, each with its own solution:
Filtering LayerDescriptionIs this DoH enough?
DNS Filtering The site is blocked or spoofed at the DNS response level ✓ Yes
SNI Filtering The connection is identified and blocked by the domain name in the TLS ClientHello ✗ No — needs ECH or Fragment
IP Blocking The destination IP address is blocked directly ✗ No — needs a VPN/Proxy
Deep Packet Inspection Packet patterns are inspected regardless of DNS or SNI ✗ No — needs an advanced VPN/Proxy

Bottom line: if the site you want is filtered only via DNS, this DoH is enough. For more advanced filtering (SNI/IP/DPI), use this DoH together with a Fragment config or a VPN — the two operate at different network layers and complement each other rather than replacing each other.

📱 How to Use

🌐 Browsers (Firefox, Chrome, Edge, Brave)

Go to browser settings → Privacy or Security → DNS over HTTPS → choose Custom Provider and enter the address above.

Enable ECH in Firefox:

1. Type this in the address bar: about:config
2. Search for: network.dns.echconfig.enabled
3. Set the value to true

With these settings, many DNS-filtered sites become accessible.

📱 Intra App (Android)

1. Install Intra from Google Play
2. Open the app
3. Tap "Configure custom server URL"
4. Enter the address below in the Custom DNS over HTTPS server URL field:

https://cloudflare-e8a.pages.dev/dns-query

5. Turn the ON switch on

This encrypts your DNS and opens sites that are blocked only by DNS filtering.

🍎 iOS, iPadOS, and macOS

For Apple devices, download and install your personal profile:

🍎 Download iOS/macOS Profile

Installation:

• iOS/iPadOS: download the file with Safari → Settings → General → VPN, DNS & Device Management → Downloaded Profile → Install
• macOS: download the file → System Settings → Privacy & Security → Profiles → install the profile

After installation, DNS for all your apps is encrypted.

💻 Windows 10/11

Settings → Network & Internet → Properties → DNS server assignment → Edit → Preferred DNS encryption: Encrypted only (DNS over HTTPS), then enter the address above.

🐧 Linux (systemd-resolved)

1. Edit the config file:

sudo nano /etc/systemd/resolved.conf

2. Add these lines:

[Resolve]
DNS=https://cloudflare-e8a.pages.dev/dns-query
DNSOverTLS=yes

3. Restart the service:

sudo systemctl restart systemd-resolved

🔧 Router

Depending on the model, your router may support DoH. Check your router's DNS settings. Configuring DoH on the router makes every device on the network use encrypted DNS.

🔧 Xray Configs

Simple Config (v2rayNG and similar)

For Xray-based clients, you can use the config below:

doh-proxy-simple.json
{ "remarks": "🛡️ DoH Proxy Pro", "dns": { "servers": [ { "address": "https://cloudflare-e8a.pages.dev/dns-query", "skipFallback": true } ], "queryStrategy": "UseIP" }, "inbounds": [ { "port": 10808, "listen": "127.0.0.1", "protocol": "socks", "settings": { "auth": "noauth", "udp": true }, "sniffing": { "enabled": true, "destOverride": ["http", "tls"] } } ], "outbounds": [ { "protocol": "freedom", "settings": { "domainStrategy": "UseIP" }, "tag": "direct" } ], "routing": { "domainStrategy": "AsIs", "rules": [ { "type": "field", "outboundTag": "direct", "network": "udp,tcp" } ] } }

Note: this config secures your DNS and opens sites that are blocked only by DNS filtering.

Advanced Config with Fragment (Recommended)

On top of DoH, this config adds Fragment support, which helps bypass SNI-based filtering at the TCP/TLS layer. The config is always fetched live from the project's GitHub repository; if the box below fails to load or the config looks outdated, click "Fetch Latest Config":

doh-proxy-fragment.json
1Fetching config from GitHub...

Fragment config benefits:

• Splits the TLS ClientHello packet to bypass DPI
• Complements DoH; it operates at a different network layer
• Improves the ability to bypass more advanced filtering

🛡️ Security Recommendations

For maximum security and access:

Scenario 1 — DNS filtering only:
✓ Use this DoH proxy
✓ Many sites become accessible

Scenario 2 — more advanced filtering:
✓ Use this DoH proxy
✓ Enable ECH in your browser
✓ Use the Fragment config in Xray
✓ Use a VPN for the other layers

General tips:
• Use up-to-date browsers
• Keep HTTPS enabled at all times
• Use reputable security software
• Use strong passwords

❓ Frequently Asked Questions

Can I access filtered sites with this DoH?
Yes, if the site is filtered only by DNS. If it is filtered by other methods (IP blocking, DPI, SNI), you will also need Fragment or a VPN.
What is Fragment and how does it help?
Fragment is an anti-filtering technique that splits the TLS ClientHello packet at the TCP level so that DPI cannot see the domain name (SNI) in a single complete packet. It applies to the connection to the destination itself, not to DNS, which is why it complements DoH rather than replacing it.
What is ECH and how does it help?
Encrypted Client Hello encrypts the domain name (SNI) during the TLS handshake and prevents SNI-based filtering. To use it, both your browser or client and the destination server must support it.
How is this DoH different from 1.1.1.1?
This is your own personal DoH proxy running on a Cloudflare Worker. It forwards your queries to Cloudflare's own 1.1.1.1 resolver, but through your own domain — useful where cloudflare-dns.com itself is blocked. It also adds caching, padding, ECS stripping, and automatic failover between Cloudflare endpoints.
Is this service free?
Yes — it is completely free within the Cloudflare Workers free tier (100,000 requests per day).
Does using this DoH reduce speed?
No — the proxy runs at the Cloudflare edge right next to Cloudflare's resolver, and smart caching answers repeated queries instantly.
What is the difference between the simple config and the Fragment config?
The simple config only enables DoH and is enough to bypass filtering at the DNS layer. On top of DoH, the Fragment config also splits TLS ClientHello packets, which helps bypass more advanced filtering (SNI/DPI). For maximum access, the Fragment config is recommended.
Can anyone see that I use this service?
Your DNS requests are encrypted and your ISP cannot see their contents; it can only see that you are connected to a Cloudflare server.
Why only Cloudflare resolvers?
Cloudflare already terminates TLS for this proxy, so it can see your queries anyway. Forwarding only to Cloudflare's own resolver means no additional party sees your DNS traffic. Racing many third-party resolvers would expose every query to all of them, and the fastest — not the most trustworthy — answer would win.
What is Request Coalescing?
When several users or apps query the same domain at the same time, instead of sending several separate requests to the upstream provider, the Worker sends only one and shares the response among all of them. This reduces server load and latency.