{"id":15688,"date":"2025-04-18T22:13:05","date_gmt":"2025-04-18T14:13:05","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/15688.html"},"modified":"2025-04-18T22:13:05","modified_gmt":"2025-04-18T14:13:05","slug":"linux-%e6%9c%8d%e5%8a%a1%e5%99%a8%e5%90%af%e7%94%a8-dns-%e5%8a%a0%e5%af%86","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/15688.html","title":{"rendered":"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6"},"content":{"rendered":"<p>DNS \u52a0\u5bc6\u7684\u5e38\u7528\u534f\u8bae\u5305\u62ec DNS over HTTPS (DoH)\u3001DNS over TLS (DoT) \u548c DNSCrypt\u3002\u4ee5\u4e0b\u662f\u5b9e\u73b0\u8fd9\u4e9b\u52a0\u5bc6\u7684\u6b65\u9aa4\u548c\u5de5\u5177\u5efa\u8bae&#xff1a;<\/p>\n<hr \/>\n<h4>1. \u4f7f\u7528 DoH (DNS over HTTPS)<\/h4>\n<h5>\u5de5\u5177\u63a8\u8350&#xff1a;<\/h5>\n<ul>\n<li>cloudflared&#xff08;Cloudflare \u63d0\u4f9b\u7684\u5ba2\u6237\u7aef&#xff09;<\/li>\n<li>doh-client&#xff08;\u8f7b\u91cf\u7ea7 DoH \u5ba2\u6237\u7aef&#xff09;<\/li>\n<li>coredns&#xff08;\u53ef\u914d\u7f6e DoH \u670d\u52a1&#xff09;<\/li>\n<\/ul>\n<h5>\u914d\u7f6e\u6b65\u9aa4&#xff1a;<\/h5>\n<li>\n<p>\u5b89\u88c5\u5de5\u5177&#xff1a; \u4f8b\u5982&#xff0c;\u4f7f\u7528 cloudflared&#xff1a;<\/p>\n<p> <span class=\"token function\">sudo<\/span> <span class=\"token function\">apt<\/span> update<br \/>\n<span class=\"token function\">sudo<\/span> <span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> cloudflared\n <\/li>\n<li>\n<p>\u914d\u7f6e DNS \u670d\u52a1&#xff1a; \u4fee\u6539 \/etc\/cloudflared\/config.yml&#xff1a;<\/p>\n<p> <span class=\"token key atrule\">proxy-dns<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token boolean important\">true<\/span><br \/>\n<span class=\"token key atrule\">proxy-dns-port<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">5053<\/span><br \/>\n<span class=\"token key atrule\">proxy-dns-upstream<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> https<span class=\"token punctuation\">:<\/span>\/\/1.1.1.1\/dns<span class=\"token punctuation\">&#8211;<\/span>query<br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> https<span class=\"token punctuation\">:<\/span>\/\/8.8.8.8\/dns<span class=\"token punctuation\">&#8211;<\/span>query\n <\/li>\n<li>\n<p>\u542f\u52a8\u670d\u52a1&#xff1a;<\/p>\n<p> <span class=\"token function\">sudo<\/span> systemctl <span class=\"token builtin class-name\">enable<\/span> cloudflared<br \/>\n<span class=\"token function\">sudo<\/span> systemctl start cloudflared\n <\/li>\n<li>\n<p>\u66f4\u6539\u7cfb\u7edf DNS&#xff1a; \u7f16\u8f91 \/etc\/resolv.conf&#xff0c;\u5c06\u672c\u5730\u89e3\u6790\u5668\u6307\u5411 127.0.0.1:5053\u3002<\/p>\n<\/li>\n<hr \/>\n<h4>2. \u4f7f\u7528 DoT (DNS over TLS)<\/h4>\n<h5>\u5de5\u5177\u63a8\u8350&#xff1a;<\/h5>\n<ul>\n<li>Stubby<\/li>\n<li>Unbound<\/li>\n<\/ul>\n<h5>\u914d\u7f6e\u6b65\u9aa4&#xff08;\u4ee5 Stubby \u4e3a\u4f8b&#xff09;&#xff1a;<\/h5>\n<li>\n<p>\u5b89\u88c5 Stubby&#xff1a;<\/p>\n<p> <span class=\"token function\">sudo<\/span> <span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> stubby\n <\/li>\n<li>\n<p>\u914d\u7f6e Stubby&#xff1a; \u7f16\u8f91 \/etc\/stubby\/stubby.yml&#xff1a;<\/p>\n<p> <span class=\"token key atrule\">resolution_type<\/span><span class=\"token punctuation\">:<\/span> GETDNS_RESOLUTION_STUB<br \/>\n<span class=\"token key atrule\">dns_transport_list<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> GETDNS_TRANSPORT_TLS<br \/>\n<span class=\"token key atrule\">tls_authentication<\/span><span class=\"token punctuation\">:<\/span> GETDNS_AUTHENTICATION_REQUIRED<br \/>\n<span class=\"token key atrule\">upstream_recursive_servers<\/span><span class=\"token punctuation\">:<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">address_data<\/span><span class=\"token punctuation\">:<\/span> 1.1.1.1<br \/>\n    <span class=\"token key atrule\">tls_port<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">853<\/span><br \/>\n    <span class=\"token key atrule\">tls_auth_name<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;cloudflare-dns.com&#034;<\/span><br \/>\n  <span class=\"token punctuation\">&#8211;<\/span> <span class=\"token key atrule\">address_data<\/span><span class=\"token punctuation\">:<\/span> 8.8.8.8<br \/>\n    <span class=\"token key atrule\">tls_port<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token number\">853<\/span><br \/>\n    <span class=\"token key atrule\">tls_auth_name<\/span><span class=\"token punctuation\">:<\/span> <span class=\"token string\">&#034;dns.google&#034;<\/span>\n <\/li>\n<li>\n<p>\u542f\u52a8\u670d\u52a1&#xff1a;<\/p>\n<p> <span class=\"token function\">sudo<\/span> systemctl <span class=\"token builtin class-name\">enable<\/span> stubby<br \/>\n<span class=\"token function\">sudo<\/span> systemctl start stubby\n <\/li>\n<li>\n<p>\u66f4\u6539\u7cfb\u7edf DNS&#xff1a; \u5c06 \/etc\/resolv.conf \u914d\u7f6e\u4e3a&#xff1a;<\/p>\n<p> nameserver 127.0.0.1\n <\/li>\n<hr \/>\n<h4>3. \u4f7f\u7528 DNSCrypt<\/h4>\n<h5>\u5de5\u5177\u63a8\u8350&#xff1a;<\/h5>\n<ul>\n<li>dnscrypt-proxy<\/li>\n<\/ul>\n<h5>\u914d\u7f6e\u6b65\u9aa4&#xff1a;<\/h5>\n<li>\n<p>\u5b89\u88c5 dnscrypt-proxy&#xff1a; \u4ece\u5b98\u65b9 GitHub \u9875\u9762\u4e0b\u8f7d\u5e76\u5b89\u88c5&#xff1a;<\/p>\n<p> <span class=\"token function\">sudo<\/span> <span class=\"token function\">apt<\/span> <span class=\"token function\">install<\/span> dnscrypt-proxy\n <\/li>\n<li>\n<p>\u914d\u7f6e dnscrypt-proxy&#xff1a; \u7f16\u8f91 \/etc\/dnscrypt-proxy\/dnscrypt-proxy.toml&#xff1a;<\/p>\n<p> server_names &#061; [&#039;cloudflare&#039;, &#039;google&#039;]<br \/>\nlisten_addresses &#061; [&#039;127.0.0.1:5353&#039;]\n <\/li>\n<li>\n<p>\u542f\u52a8\u670d\u52a1&#xff1a;<\/p>\n<p> <span class=\"token function\">sudo<\/span> systemctl <span class=\"token builtin class-name\">enable<\/span> dnscrypt-proxy<br \/>\n<span class=\"token function\">sudo<\/span> systemctl start dnscrypt-proxy\n <\/li>\n<li>\n<p>\u66f4\u6539\u7cfb\u7edf DNS&#xff1a; \u4fee\u6539 \/etc\/resolv.conf&#xff0c;\u6307\u5411 127.0.0.1:5353\u3002<\/p>\n<\/li>\n<hr \/>\n<h4>4. \u9a8c\u8bc1 DNS \u52a0\u5bc6\u662f\u5426\u542f\u7528<\/h4>\n<p>\u4f7f\u7528\u4ee5\u4e0b\u5de5\u5177\u68c0\u67e5 DNS \u8bf7\u6c42\u662f\u5426\u52a0\u5bc6&#xff1a;<\/p>\n<ul>\n<li>dig&#xff08;\u68c0\u67e5\u89e3\u6790\u662f\u5426\u901a\u8fc7\u52a0\u5bc6\u670d\u52a1&#xff09;<\/li>\n<li>tcpdump&#xff08;\u6355\u83b7\u7f51\u7edc\u6d41\u91cf&#xff0c;\u9a8c\u8bc1\u662f\u5426\u8d70\u52a0\u5bc6\u7aef\u53e3&#xff09;<\/li>\n<\/ul>\n<p>\u4f8b\u5982&#xff1a;<\/p>\n<p><span class=\"token function\">dig<\/span> &#064;127.0.0.1 <span class=\"token parameter variable\">-p<\/span> <span class=\"token number\">5053<\/span> google.com<\/p>\n<hr \/>\n<p>\u5982\u679c\u9700\u8981\u8fdb\u4e00\u6b65\u4f18\u5316\u6216\u89e3\u51b3\u95ee\u9898&#xff0c;\u53ef\u4ee5\u544a\u8bc9\u6211\u5177\u4f53\u7684\u573a\u666f\u6216\u9700\u6c42\u3002 &#x1f60a;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb1.3k\u6b21\uff0c\u70b9\u8d5e5\u6b21\uff0c\u6536\u85cf15\u6b21\u3002DNS \u52a0\u5bc6\u7684\u5e38\u7528\u534f\u8bae\u5305\u62ec\u548c\u3002_\u652f\u6301\u52a0\u5bc6\u7684dns<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[58,43,1045,44],"topic":[],"class_list":["post-15688","post","type-post","status-publish","format-standard","hentry","category-server","tag-linux","tag-43","tag-1045","tag-44"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/15688.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb1.3k\u6b21\uff0c\u70b9\u8d5e5\u6b21\uff0c\u6536\u85cf15\u6b21\u3002DNS \u52a0\u5bc6\u7684\u5e38\u7528\u534f\u8bae\u5305\u62ec\u548c\u3002_\u652f\u6301\u52a0\u5bc6\u7684dns\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/15688.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-18T14:13:05+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/15688.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/15688.html\",\"name\":\"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2025-04-18T14:13:05+00:00\",\"dateModified\":\"2025-04-18T14:13:05+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/15688.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/15688.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/15688.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/15688.html","og_locale":"zh_CN","og_type":"article","og_title":"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u6587\u7ae0\u6d4f\u89c8\u9605\u8bfb1.3k\u6b21\uff0c\u70b9\u8d5e5\u6b21\uff0c\u6536\u85cf15\u6b21\u3002DNS \u52a0\u5bc6\u7684\u5e38\u7528\u534f\u8bae\u5305\u62ec\u548c\u3002_\u652f\u6301\u52a0\u5bc6\u7684dns","og_url":"https:\/\/www.wsisp.com\/helps\/15688.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2025-04-18T14:13:05+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"1 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/15688.html","url":"https:\/\/www.wsisp.com\/helps\/15688.html","name":"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2025-04-18T14:13:05+00:00","dateModified":"2025-04-18T14:13:05+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/15688.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/15688.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/15688.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"Linux \u670d\u52a1\u5668\u542f\u7528 DNS \u52a0\u5bc6"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/15688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=15688"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/15688\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=15688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=15688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=15688"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=15688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}