Threat feed
Hagezi DNS-over-HTTPS/VPN Bypass
Last fetched
Proxies · refreshed daily · last verified
Hagezi DNS-over-HTTPS/VPN Bypass is a Proxies threat-intelligence feed, refreshed daily, indexed by WhisperGraph. WhisperGraph currently records 1,363 indicators listed by it.
What is Hagezi DNS-over-HTTPS/VPN Bypass
Hagezi DNS-over-HTTPS/VPN Bypass is a specialised list from the Hagezi DNS-blocklist project cataloguing known public DNS-over-HTTPS resolvers and VPN endpoints that a client could use to bypass local DNS-based filtering. Network operators who deploy DNS-level ad- or content-blocking add this list specifically to prevent a device from silently routing around the filter via an alternate encrypted resolver. It is a defensive meta-list rather than a threat-indicator feed in the traditional sense — the entries are legitimate services being tracked for policy-enforcement purposes, not malicious infrastructure. It is indexed here because it is a commonly deployed companion to the project's other DNS blocklist tiers.
- Refresh cadence
- daily
Category drift. The curated category for this feed is Proxies, while WhisperGraph currently files it under proxies.
Indicators currently listed
1,363 indicators across 2 node types.
IPV4 · 1,352
Related pages
Pivot from Hagezi DNS-over-HTTPS/VPN Bypass into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.