
DNSnitch is a local, privacy-first DNS server that puts you in complete control of your network traffic. Unlike passive blocklists, DNSnitch operates on a "Default Deny" philosophy: every unknown domain is blocked by default until you authorize it via a real-time terminal dashboard.
Disclaimer I use that for myself, it's here if someone needs it though. Feel free to open an issue if you find bugs!
The Interactive Terminal DNS Firewall
DNSnitch is a local, privacy-first DNS server that puts you in complete control of your network traffic. Unlike passive blocklists, DNSnitch operates on a "Default Deny" philosophy: every unknown domain is blocked by default until you authorize it via a real-time terminal dashboard.
NXDOMAIN instantly and appear in a "Pending Queue".Apply.Navigate the dashboard using F-Keys:
PgUp/PgDn.Left/Right arrows to highlight a column (Temp, Once, Perm, Blocked), and Up/Down to scroll that specific column.> indicates selection, * indicates staged changes.DNSnitch is keyboard-driven. Below is the complete list of commands available in the Console [F1].
Before applying an action, you must select targets. You can select pending requests by ID or manual domains by name.
| Command | Usage Example | Description |
|---|---|---|
s | s | Clear the current selection. |
s <id> | s 1 3 5 | Select pending domains by their Queue ID (visible in F3). |
s <domain> | s google.com | Select a specific domain by name (even if not in queue). Useful for editing existing rules. Multi-selection is supported |
q, ls | q | Switch to the Queue Tab [F3]. |
clear | clear | Flush the pending queue (removes all pending requests from view). |
Once domains are selected, use these shortcuts to set their status.
| Command | Usage | Description |
|---|---|---|
p | p | Mark selected as Permanent Allow. |
t | t | Mark selected as Temporary (5 Minutes). |
o | o | Mark selected as Allow Once (Next request only). |
b | b | Mark selected as Blocked (Blacklist). |
rm, del | rm | Remove the rule for the selected domain (Forget it, start fresh). |
Changes are not live until applied.
| Command | Usage | Description |
|---|---|---|
cc | cc | Check Config: Print a text summary of staged changes. |
d, ditch | d | Discard: Reset the workspace and undo all staged changes. |
a | a | Apply: Commit the workspace to the live firewall database. |
Change how the firewall behaves globally.
| Command | Usage | Description |
|---|---|---|
m dft | m dft | Default Mode: Block everything unknown (Standard security). |
m rec | m rec | Record Mode: Allow everything + Log unique domains to [F6]. |
m rbl | m rbl | Record + Blocklist: Allow everything except known blocks + Log unique domains. |
crec | crec | Clear Records: Wipe the list of recorded domains in [F6]. |
Map domains to custom targets (Local DNS spoofing).
| Command | Usage Example | Description |
|---|---|---|
r | r dev.loc 127.0.0.1 | Redirect dev.loc to local IP (A Record). |
r | r my.net google.com | Redirect my.net to google.com (CNAME). |
ur | ur dev.loc | Unredirect: Remove the custom rule for dev.loc. |
| Command | Usage | Description |
|---|---|---|
logs | logs | Switch to Logs Tab [F4]. |
help | help | List all available commands. |
exit | exit | Shut down the DNS server. |
example.com. It fails.1. example.com.s 1. (Row highlights).p. (Row shows [PERM]).a. (Apply).google.com.s google.com.rm (Remove) or p (Perm) to overwrite the block.a.mysite.local.r mysite.local 127.0.0.1.m rec (Mode: Record).m dft to go back to secure mode.