EonaCat.Blocky 4.6.2

Prefix Reserved
There is a newer version of this package available.
See the version list below for details.
dotnet add package EonaCat.Blocky --version 4.6.2
                    
NuGet\Install-Package EonaCat.Blocky -Version 4.6.2
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="EonaCat.Blocky" Version="4.6.2" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="EonaCat.Blocky" Version="4.6.2" />
                    
Directory.Packages.props
<PackageReference Include="EonaCat.Blocky" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add EonaCat.Blocky --version 4.6.2
                    
#r "nuget: EonaCat.Blocky, 4.6.2"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package EonaCat.Blocky@4.6.2
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=EonaCat.Blocky&version=4.6.2
                    
Install as a Cake Addin
#tool nuget:?package=EonaCat.Blocky&version=4.6.2
                    
Install as a Cake Tool

Blocky

Blocking domains the way you want it Blocky is the web administration interface and host application for EonaCat DNS. It provides domain blocking, allowlisting, DNS configuration, live statistics, logs, and server management from a browser.

Copyright EonaCat (Jeroen Saey) 2017-2026 https://blocky.eonacat.com

Features

  • DNS blocklists and allowlists with category support
  • Recursive resolution through configured IPv4, IPv6, or DNS-over-HTTPS forwarders
  • Authoritative zone data from the bundled masterFile.txt
  • DNSSEC signing for local authoritative answers
  • IPv4 and IPv6 DNS listeners with UDP and TCP fallback
  • Optional multicast DNS support
  • Cache, negative-cache, and stale-answer settings
  • Client network allow/deny rules and per-client query limits
  • Live dashboard metrics through SignalR
  • Statistics, client, domain, blocklist, category, and log management
  • Windows Service hosting

Requirements

  • .NET 6 or .NET 8 runtime
  • Port 53 available for the DNS listener
  • Port 80 available for the default local administration interface

The administration interface binds to http://127.0.0.1:80/ by default. Configure the web and DNS endpoints before exposing the application to another network.

Running on Windows

When port 80 is already reserved by HTTP.sys, stop the conflicting reservation from an elevated Command Prompt:

net stop http

The DNS executable also supports Windows Service installation:

EonaCat.Dns.exe /install
EonaCat.Dns.exe /uninstall

Run these commands from an elevated Administrator console. The service is created with Automatic startup.

Running on Linux

Make sure port 53 is free:

sudo lsof -i :53

On systems using systemd-resolved, disable its stub listener and point the host resolver at Blocky:

# /etc/systemd/resolved.conf
[Resolve]
DNS=127.0.0.1
DNSStubListener=no

Then restart systemd-resolved and ensure /etc/resolv.conf points to /run/systemd/resolve/resolv.conf:

sudo systemctl restart systemd-resolved
sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf

Do not start Blocky until the existing DNS service has released port 53.

Configuration

The web interface exposes the main DNS settings. The underlying EonaCatDnsConfig model also supports:

  • IPv4/IPv6 listen and resolver addresses
  • Standard DNS and DoH forwarders
  • DNSSEC algorithm selection (ECDSAP256, ECDSAP384, or ED25519)
  • Cache size, TTL, negative-cache, and serve-stale limits
  • Client network allow/deny lists and query-rate/burst limits
  • Optional DNS-over-TLS on port 853
  • TSIG keys and authenticated updates or zone transfers
  • Plugin loading and secondary-zone configuration

Treat the administration interface and any DNS-over-TLS certificate material as production secrets. Put externally exposed administration endpoints behind HTTPS, authentication, firewall rules, or a reverse proxy.

Log files

Blocky uses EonaCat.LogStack and writes daily files under the runtime logs directory:

  • blocky-startup_* - startup, setup, and host lifecycle
  • dns-server_* - DNS listener, catalog, DNSSEC, and server lifecycle
  • dns-query_* - DNS query and response events
  • multicast_* - multicast DNS lifecycle and errors
  • blocky-web_* and dns-web_* - web request and framework diagnostics
  • dns-general_* - DNS background services and uncategorized errors

Verbose per-query text logging is disabled by default. Enable it from Network > DNS resolution > Verbose query text logs when detailed query text is required. Structured query records and metrics remain available while it is disabled.

License

Licensed under the Apache License, Version 2.0. See LICENSE.

DNS performance and secure upstream optimizations

The resolver now uses a security-first upstream pipeline with adaptive health tracking. Built-in DNS-over-HTTPS endpoints are bootstrapped without depending on the operating system resolver, while TLS/SNI continues to use the original hostname. DoH connections use pooled HTTP/2, short connection timeouts, and parallel upstream racing. DoT and plain DNS upstreams are health-ranked and automatically backed off after repeated failures.

Additional correctness/performance changes include: adaptive latency scoring, cancellation of losing parallel upstream requests, proper NXDOMAIN/NODATA handling, IPv6-safe DoT endpoint parsing, Happy-Eyeballs-style secure bootstrap, removal of the unreliable preflight Internet/DNS check, and isolated DNS-over-TCP fallback connections so concurrent DNS frames cannot interleave.

These changes are designed so an allowed domain is still resolved even when the machine's normal DNS resolver is broken.

Product Compatible and additional computed target framework versions.
.NET net6.0 is compatible.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
4.6.6 64 9/30/2026
4.6.5 67 9/30/2026
4.6.4 72 9/29/2026
4.6.3 63 9/29/2026
4.6.2 96 9/27/2026
4.6.1 95 9/27/2026
4.6.0 88 9/27/2026
4.5.7 98 9/23/2026
4.5.6 102 9/23/2026
4.4.7 99 9/21/2026
Loading failed

Blocky
Blocking domains the way you want it.
Copyright EonaCat (Jeroen Saey)
https://blocky.eonacat.com/

This library uses EonaCatDns.

Source available on:  https://github.com/EonaCat/Blocky