Tor and socat in one container, joined as DNS proxy to CloudFlare's hidden DNS resolver
10K+
DNS-over-TLS resolver through Tor using socat with multi-tier failover.
Routes your DNS queries through the Tor network to encrypted upstream DNS resolvers. socat relays raw TCP streams through Tor's SOCKS4A proxy, providing transparent TLS passthrough — the TLS session is end-to-end between your client and the upstream resolver.
Legacy listener, port 853 (Cloudflare only, in failover order):
Identity-bound routes (one provider each, never another): 18531 Cloudflare .onion, 18532 Cloudflare 1.1.1.1 via a Tor exit, 18533 Quad9 9.9.9.9 via a Tor exit. Your client verifies the provider's TLS name for the route it uses.
Clients connect via DNS-over-TLS — socat passes TLS through transparently.
docker run -d --name=tor-socat -p 853:853 --restart=always sureserver/tor-socat:latest
Then point your DNS client to 127.0.0.1:853 as a DNS-over-TLS upstream.
docker run -d --name=tor-socat --restart=always sureserver/tor-socat:latest
Use the container IP and port 853 as a DNS-over-TLS upstream in your resolver (Unbound, Pi-hole, etc.).
podman run -d --name=tor-socat -p 853:853 --restart=always sureserver/tor-socat:latest
| Variable | Default | Description |
|---|---|---|
BRIDGE1..BRIDGE16 | (none; required) | obfs4 bridge lines; at least one, three for Conflux |
BRIDGE_EVAL | off | In-container bridge evaluation: off, auto, moat or force |
SOCAT_MAX_CHILDREN | 256 | Connection cap of the legacy 853 listener |
ROUTE_MAX_CHILDREN | 128 | Connection cap of each route listener |
docker run -d --name=tor-socat \
-e BRIDGE1="obfs4 IP:PORT FINGERPRINT cert=... iat-mode=0" \
-e BRIDGE2="obfs4 IP:PORT FINGERPRINT cert=... iat-mode=0" \
--restart=always sureserver/tor-socat:latest
Client --[DNS-over-TLS]--> socat --[SOCKS4A]--> Tor ---> upstream DoT resolver
linux/amd64 | linux/arm/v7 | linux/arm64 | linux/riscv64
MIT
Content type
Image
Digest
sha256:852167818…
Size
29.8 MB
Last updated
2 days ago
docker pull sureserver/tor-socat