๐ฟ dns-guard v1.0.2 ยท MIT
A pragmatic SQLite-backed task manager built for AI/human shared work queues โ priority, a verification-first lifecycle, waiting-for tracking, triage, and a soft archive that never hard-deletes.
What it does
- Detects poisoning resolvers: flags configured DNS servers that intentionally return wrong answers for parts of the Internet (censorship, geo-blocking) โ default blocklist includes
114.114.114.114/114.114.115.115. - Full resolver inventory: macOS per-service settings + runtime view (DHCP- and VPN-injected, via
scutil --dns); Linux/etc/resolv.conf+resolvectl. - Optional repair:
--fix(macOS) replaces blocked resolvers on every network service with universal ones (1.1.1.1, 8.8.8.8). - Extensible blocklist:
--blocklistadds your own entries;--filechecks any resolv.conf-style file instead of the live system. - Machine-readable:
--jsonoutput; clear exit codes (0 clean, 1 blocked found, 2 error). - Zero dependencies โ bash only, macOS & Linux.
Install (pip)
pip install "dns-guard @ git+https://mandrilly.com/git/dns-guard.git"
Installs a dns-guard command (thin wrapper around the bundled bash script; the script also works standalone).
Quick start
dns-guard # read-only check of the live system dns-guard --json # machine-readable output dns-guard --fix # macOS: replace blocked resolvers with 1.1.1.1 / 8.8.8.8
Source
git clone https://mandrilly.com/git/dns-guard.git
Requires Python 3.9+. MIT license.