Skip to content

Threat feed

Hagezi DNS-over-HTTPS/VPN Bypass

Last fetched

Proxies · refreshed daily · last verified

Hagezi DNS-over-HTTPS/VPN Bypass is a Proxies threat-intelligence feed, refreshed daily, indexed by WhisperGraph. WhisperGraph currently records 1,363 indicators listed by it.

What is Hagezi DNS-over-HTTPS/VPN Bypass

Hagezi DNS-over-HTTPS/VPN Bypass is a specialised list from the Hagezi DNS-blocklist project cataloguing known public DNS-over-HTTPS resolvers and VPN endpoints that a client could use to bypass local DNS-based filtering. Network operators who deploy DNS-level ad- or content-blocking add this list specifically to prevent a device from silently routing around the filter via an alternate encrypted resolver. It is a defensive meta-list rather than a threat-indicator feed in the traditional sense — the entries are legitimate services being tracked for policy-enforcement purposes, not malicious infrastructure. It is indexed here because it is a commonly deployed companion to the project's other DNS blocklist tiers.

Refresh cadence
daily

Category drift. The curated category for this feed is Proxies, while WhisperGraph currently files it under proxies.

Indicators currently listed

1,363 indicators across 2 node types.

Related pages

Pivot from Hagezi DNS-over-HTTPS/VPN Bypass into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.