DNS tunnelling is how SlipNet and StormDNS get through networks that block normal VPNs. This article explains, in plain terms, how it works, why it's hard to block, and why it's slower than a regular VPN.
The simple version
Imagine passing notes in class by tucking them inside homework the teacher collects anyway. The teacher (the censor) sees homework, not secret notes. DNS tunnelling does the same with your internet traffic: it tucks it inside DNS lookups, which networks pass along all the time.
What is DNS?
DNS (the Domain Name System) is the internet's address book. When you visit example.com, your device asks a DNS resolver "what's the IP address for example.com?" and gets an answer back. Every device does this constantly, for every website and app.
How the tunnel works
- Encode: the app on your device encrypts a small piece of your traffic and writes it into a DNS query for a hostname that belongs to our tunnel server. With StormDNS, that hostname is unique to you.
- Relay: the query goes to a DNS resolver, just like any other lookup. Because the hostname is delegated to our server, the resolver forwards the query to us.
- Decode: our server unpacks and decrypts your traffic, fetches what you asked for from the internet, and sends the reply back hidden inside the DNS response.
To someone watching your connection, it looks like DNS lookups and answers.
This is also why resolvers matter. If the resolver your app uses is blocked or filtered on your network, your queries never reach us. That's why we recommend scanning for working resolvers: see How to Find Working DNS Resolvers.
Why it's hard to block
Almost everything online depends on DNS, so a country can't simply switch it off without breaking its own internet. That makes DNS tunnels one of the last things still working when filtering is at its heaviest.
It isn't impossible to interfere with, though. Censors can block particular resolvers, slow DNS down, or look for unusual query patterns. That's why SlipNet offers several DNS protocols (VayDNS, NoizDNS, DNSTT and Slipstream), each shaping its traffic differently, so you can switch when one is detected.
The trade-off: speed
DNS tunnels are slower than a normal VPN because:
- Each DNS query can only carry a small amount of data.
- Many queries are needed to move even a small web page.
- Every query takes a trip through a resolver as well as our server, which adds delay.
Messaging, browsing and social media usually work fine. For video or large downloads, try Slipstream (the fastest DNS tunnel) or NaiveProxy (which uses HTTPS instead of DNS), or a faster option such as the PremierVPN app if it works on your network.
Is my traffic encrypted?
Yes. Your traffic is encrypted on your device before it's put into DNS queries, so anyone who reads the queries sees only scrambled data, not your browsing. DNSTT, for example, uses Curve25519 keys, and Slipstream uses the encryption built into QUIC.
Learn more about each protocol in Understanding the 6 SlipNet Protocols.