DNS-over-TLS resolver through Tor using haproxy with built-in health checks and automatic failover.
Routes your DNS queries through the Tor network to encrypted upstream DNS resolvers. haproxy provides industrial-grade TCP proxying with native SOCKS4 support for Tor routing and active health monitoring of all upstreams.
Legacy listener, port 853 (Cloudflare only, in failover order):
Identity-bound routes (one provider each, never another): 18531 Cloudflare .onion, 18532 Cloudflare 1.1.1.1/1.0.0.1 via a Tor exit, 18533 Quad9 9.9.9.9/149.112.112.112 via a Tor exit. Your client verifies the provider's TLS name for the route it uses.
Clients connect via DNS-over-TLS — haproxy does transparent TLS passthrough, so the TLS session is end-to-end between your client and the upstream resolver.
docker run -d --name=tor-haproxy -p 853:853 --restart=always sureserver/tor-haproxy:latest
Then point your DNS client to 127.0.0.1:853 as a DNS-over-TLS upstream.
docker run -d --name=tor-haproxy --restart=always sureserver/tor-haproxy:latest
Use the container IP and port 853 as a DNS-over-TLS upstream in your resolver (Unbound, Pi-hole, etc.).
podman run -d --name=tor-haproxy -p 853:853 --restart=always sureserver/tor-haproxy:latest
| Variable | Default | Description |
|---|---|---|
BRIDGE1..BRIDGE16 | (none; required) | obfs4 bridge lines; at least one, three for Conflux |
BRIDGE_EVAL | off | In-container bridge evaluation: off, auto, moat or force |
docker run -d --name=tor-haproxy \
-e BRIDGE1="obfs4 IP:PORT FINGERPRINT cert=... iat-mode=0" \
-e BRIDGE2="obfs4 IP:PORT FINGERPRINT cert=... iat-mode=0" \
--restart=always sureserver/tor-haproxy:latest
Client --[DNS-over-TLS]--> haproxy --[SOCKS4]--> Tor ---> upstream DoT resolver
fall 3 rise 3 on the legacy 853 listener — automatic failover to the Cloudflare backuplinux/amd64 | linux/arm/v7 | linux/arm64 | linux/riscv64
MIT
Content type
Image
Digest
sha256:973e5082e…
Size
32.7 MB
Last updated
2 days ago
docker pull sureserver/tor-haproxy