User-friendly DNS tunnel client for Iran — scan resolvers, save profiles, launch MasterDnsVPN or VayDNS with one click. No config editing required.
See the code🇮🇷 فارسی | 🇬🇧 English
A user-friendly GUI client for DNS tunneling supports MasterDnsVPN and VayDNS
KevinNet automatically scans Iranian IP ranges to find working DNS resolvers, then generates ready-to-use config files and launch scripts with a single click to connect. No config files to edit. No terminal commands to remember.
Created by Kevin Haji · kevinhaji.com · kevin.fullstack.dev@gmail.com
A DNS tunnel disguises your internet traffic as ordinary DNS queries. Iran's DPI filtering cannot easily identify or block it. KevinNet handles all the technical parts scanning for working resolvers, writing config files, copying binaries, launching the VPN so you only need to fill in a few fields and click buttons.
Two VPN engines are supported:
KevinNet ships two public releases. Pick the one that fits your situation:
The current release. This is what you should download unless you have a specific reason not to. It does everything 3.2.2 does plus:
launched 5m ago, etc.)See CHANGELOG.md for the full list of changes.
The previous stable release. Still works, still available on the Releases page. Use this only if:
For everyone else, use v4.1.6. Profile files are compatible between the two versions, so you can switch back and forth without losing your data.
Go to the Releases page and pick one of the two versions:
| Platform | File |
|---|---|
| 🪟 Windows x64 | KevinNet_Windows_x64.exe |
| 🪟 Windows ARM64 | KevinNet_Windows_ARM64.exe |
| 🍎 macOS (Intel + Apple Silicon) | KevinNet_macOS_Universal |
| 🐧 Linux x64 | KevinNet_Linux_x64 |
| 🐧 Linux ARM64 | KevinNet_Linux_ARM64 |
Same platform binaries are available on the v3.2.2 release page. Only download these if 4.1.6 doesn't work for you — see CHANGELOG.md for the comparison.
macOS: After downloading, run in Terminal:
chmod +x KevinNet_macOS_Universal xattr -d com.apple.quarantine KevinNet_macOS_Universal
Linux: Run
chmod +x KevinNet_Linux_x64before launching.
Every release ships with a SHA256SUMS.txt file alongside the binaries. To verify the file you downloaded hasn't been tampered with:
shasum -a 256 -c SHA256SUMS.txt # macOS / Linux
Get-FileHash -Algorithm SHA256 KevinNet_Windows_x64.exe # Windows
Compare the output against the line for your platform in SHA256SUMS.txt. If they don't match, do not run the file - re-download from the official Releases page.
KevinNet is the client app. It connects to a VPN server that you (or someone you know) must set up on a VPS outside Iran.
Any Linux VPS with a public IP address. Popular providers: Hetzner, DigitalOcean, Vultr, Linode.
MasterDNS acts as an authoritative DNS server, so DNS queries for your tunnel subdomain must be forwarded to your VPS. Create two DNS records in your domain provider's control panel:
| Type | Name | Value | Purpose |
|---|---|---|---|
A | ns | Your server's IP | Glue record where your nameserver lives |
NS | v | ns.yourdomain.com | Delegates v.yourdomain.com queries to your server |
Example with domain example.com and server IP 1.2.3.4:
ns.example.com → 1.2.3.4 (A record)v.example.com → ns.example.com (NS record)Your tunnel domain is v.example.com.
Cloudflare users: The
Arecord fornsmust be DNS only (grey cloud), not proxied. Tip: Short names (1–2 chars) leave more room for data per DNS packet → better speed.
Follow the official guide: 👉 https://github.com/masterking32/MasterDnsVPN
After setup you will have:
v.example.com → enter this in KevinNetencrypt_key.txt on the server → enter this in KevinNetThe key must match between client and server. If you lose it, run
cat encrypt_key.txton your server.
Bundled inside KevinNet copied to your output folder automatically when you save. If missing, see ⚠️ Binary missing? below.
Same as MasterDNS any Linux VPS with a public IP.
VayDNS also acts as an authoritative DNS server. The DNS setup concept is identical to MasterDNS: one A glue record + one NS delegation record.
Example with domain example.com and server IP 1.2.3.4:
tns.example.com → 1.2.3.4 (A record glue)t.example.com → tns.example.com (NS record delegation)Your tunnel domain is t.example.com.
Important: The glue record name (
tns) must NOT be a subdomain of the tunnel name (t). They must be separate e.g.tnsandt, notns.t.
Follow the official guide: 👉 https://github.com/net2share/vaydns
After setup you will have:
t.example.com → enter this in KevinNetserver.pub file on the server contains your public keyThe public key authenticates your server it proves to the client that it is talking to the right server and not an interceptor. To get it, run on your server:
cat server.pub
You will see a 64-character hex string like:
0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b
Copy this entire string and paste it into the VayDNS Public Key field in KevinNet.
The public key is safe to share it only verifies your server's identity. The private key (
server.key) must stay on the server and never be shared.
Bundled inside KevinNet copied to your output folder automatically when you save. If missing, see ⚠️ Binary missing? below.
At the top of the Scanner panel, click MasterDNS or VayDNS. Only the fields and save button for your chosen type will show.
| Field | MasterDNS | VayDNS |
|---|---|---|
| Country / Folder | Any name e.g. Iran | Any name e.g. Iran |
| Tunnel Domain | e.g. v.example.com | e.g. t.example.com |
| Key | 32-char key from encrypt_key.txt | 64-char hex key from server.pub |
| Option | Recommended for Iran | Notes |
|---|---|---|
| Target | 100 | How many resolvers to find |
| Concurrency | 80 | Do not go above 100 inside Iran |
| Timeout | 3s | Iranian networks are slow |
| Pool ×1000 | 200 | 200k IPs scanned. Increase to 300–500 if few found |
Run the scan 2–3 times each run tests a different random set of IPs.
Click ▶ Start Scan. Three automatic phases:
🟢 6/6 excellent · 🟡 4–5 good · 🟠 2–3 weak · ⚫ ·0–1 very weak
A profile is saved with sensible defaults. The VPN binary is copied into the output folder automatically.
After any scan, the 📤 Export DNS List button becomes active regardless of which VPN mode you used. Click it to save the found resolver IPs as a plain .txt file - one IP per line. Useful if you want to use the resolver list in another application or script.
The 🔒 Scan DoH/DoT button (new in 3.3.0) probes a curated list of well-known DNS-over-HTTPS (port 443) and DNS-over-TLS (port 853) endpoints. The traffic looks like normal HTTPS, so it's much harder for Iranian DPI to fingerprint as tunnel traffic than plain UDP/53. Working endpoints stream into the results list with a 🔒 icon - paste any of them into a VayDNS profile as a custom resolver when UDP isn't surviving DPI.
The lists live in data/doh_endpoints.txt and data/dot_endpoints.txt next to the app. You can edit them to add private endpoints or remove dead ones without rebuilding.
In the results list, right-click (or two-finger click / Ctrl-click on Mac) to Copy IP, Copy all IPs, or Open output folder in your file manager.
Click 📋 MasterDNS Profiles or 📋 VayDNS Profiles at the top.
Set your browser proxy to SOCKS5 127.0.0.1:18000 (MasterDNS) or SOCKS5 127.0.0.1:7000 (VayDNS).
Every save creates a profile in masterdns_profiles/ or vaydns_profiles/ next to the app.
| Button | What it does |
|---|---|
| 💾 Save Changes | Rewrites config files with your current settings |
| 🚀 Launch VPN | Regenerates files and launches the VPN |
| 📋 Duplicate | Copies the profile great for A/B testing different settings |
| 🗑 Delete | Removes the profile and optionally the output folder |
| Option | Iran optimal | Why |
|---|---|---|
| Encryption Method | 1 XOR | Lowest overhead in small DNS packets. Must match server. |
| Balancing Strategy | 3 Least Loss | Iran has high uneven packet loss favours the most reliable resolver |
| Packet Duplication | 2–3 | Sends each packet via multiple resolvers redundancy on lossy paths |
| Max Upload MTU | 80–100 | Smaller DNS queries look less suspicious to DPI |
| Max Download MTU | 700 | Prevents ISP from fragmenting large DNS responses |
| Min Upload MTU | 38 | Very conservative keeps the maximum number of resolvers usable |
| Min Download MTU | 400 | Keeps resolvers that return slightly smaller responses |
| Log Level | INFO | Shows connection events without flooding the terminal |
| Option | Iran optimal | Why |
|---|---|---|
| Transport | UDP | Plaintext UDP on port 53 most direct path from Iran |
| Resolver | (empty) | Uses all scanned resolvers in order see note below |
| Listen Port | 7000 | The local port your browser proxy connects to |
| Max QNAME Length | 101 | ~50 byte upstream MTU, safe for most Iranian resolvers |
| Idle Timeout | 10s | How long before declaring a session dead. Must match server. Increase to 30s if reconnects are frequent. |
| Keepalive | 2s | How often to ping the server to keep the session alive. Must be less than idle timeout. Must match server. |
| Record Type | txt | TXT records carry the most data and are most compatible under DPI |
| Queue Size | 512 | Internal packet buffer increase to 1024 on fast connections |
| UDP Workers | 100 | Concurrent outgoing queries lower to 50 if you see socket errors |
| Resolver Timeout | 60s | If a resolver doesn't connect within this many seconds, the script moves to the next one |
| Log Level | info | Normal operation |
The Resolver field:
Resolver Timeout seconds.8.8.8.8:53 for UDP · https://dns.google/dns-query for DoH · dns.google:853 for DoT.Testing from outside Iran: Scanned resolvers are Iranian public DNS servers. They only work correctly when connecting from inside Iran. Testing from Australia, Europe, or anywhere else will show NXDOMAIN errors those resolvers cannot reach your tunnel server from a foreign network.
KevinNet v3.0.9+ bundles the correct binary automatically for every platform - upgrade first before trying manual steps below.
Download the client binary from the MasterDnsVPN releases:
| Platform | Download |
|---|---|
| 🐧 Linux x64 | MasterDnsVPN_Client_Linux_AMD64.zip |
| 🐧 Linux ARM64 | MasterDnsVPN_Client_Linux_ARM64.zip |
| 🐧 Linux x64 (legacy glibc) | MasterDnsVPN_Client_Linux-Legacy_AMD64.zip |
| 🪟 Windows x64 | MasterDnsVPN_Client_Windows_AMD64.zip |
| 🪟 Windows ARM64 | MasterDnsVPN_Client_Windows_ARM64.zip |
| 🍎 macOS (all) | MasterDnsVPN releases page |
MasterDnsVPN (macOS/Linux) or MasterDnsVPN.exe (Windows)Download from the VayDNS releases page. Use these exact filenames when placing next to KevinNet:
| Platform | Filename |
|---|---|
| macOS Apple Silicon (M1/M2/M3/M4) | vaydns-client-darwin-arm64 |
| macOS Intel | vaydns-client-darwin-amd64 |
| Linux x64 | vaydns-client-linux-amd64 |
| Linux ARM64 | vaydns-client-linux-arm64 |
| Windows x64 | vaydns-client_windows_amd64.exe |
macOS: "KevinNet is damaged and can't be opened" or "cannot be verified"
chmod +x KevinNet_macOS_Universal
xattr -d com.apple.quarantine KevinNet_macOS_Universal
Or right-click the app → Open → Open.
Linux: "Permission denied" when launching
chmod +x KevinNet_Linux_x64
./KevinNet_Linux_x64
Windows: antivirus blocks the app This is a false positive PyInstaller-compiled apps trigger some antivirus scanners. Add an exception for the file, or build from source yourself (see BUILD_INSTRUCTIONS.txt).
Windows: Persian text appears as separate unjoined characters v3.1.2+ bundles Vazirmatn and loads it automatically on startup. If you are on an older version, upgrade to the latest release from the releases page.
After clicking Save, the country folder has no MasterDnsVPN or vaydns-client
The binary must be placed next to the KevinNet app before saving KevinNet copies it into the output folder. See ⚠️ Binary missing? for download links and exact filenames.
macOS: MasterDnsVPN is there but won't run "cannot be opened"
chmod +x /path/to/Iran/MasterDnsVPN
xattr -d com.apple.quarantine /path/to/Iran/MasterDnsVPN
macOS: vaydns-client-darwin-arm64 won't run
chmod +x /path/to/Iran/vaydns-client-darwin-arm64
xattr -d com.apple.quarantine /path/to/Iran/vaydns-client-darwin-arm64
Finding 0–5 resolvers even after scanning
200 to 500 more IPs scanned = more found2s if the scan takes too long (sacrifices some accuracy)100 inside IranPhase 3 (E2E) passes zero resolvers
Phase 3 tests the actual tunnel through your server. Zero means either:
encrypt_key.txtConnected but browser shows no internet / pages don't load
SOCKS5 127.0.0.1:18000 (MasterDNS) or SOCKS5 127.0.0.1:7000 (VayDNS)Connected but very slow
For MasterDNS try lowering MTU values:
60–80 (smaller packets, less likely to be throttled)600For VayDNS:
80 instead of 101null instead of txt (higher throughput on some resolvers)"parse TOML failed" error when launching MasterDnsVPN
The config file has an unfilled placeholder. This happens if you launch from the output folder without saving through KevinNet. Always save from the Profiles tab before launching. If the error persists:
Frequent disconnections / reconnects
3 more redundancy on lossy paths3 Least LossOnly a handful of resolvers work (most are 1–2)
This is normal most public DNS servers don't forward DNS queries for custom NS delegations. A score of 10–30 good resolvers from a scan of 200k IPs is a good result.
"noise handshake: timeout" repeated in the terminal
The resolver is returning NXDOMAIN it can't reach your tunnel server. The script will automatically move to the next resolver after Resolver Timeout seconds. If all resolvers fail:
dig v.yourdomain.com NS90s to give each resolver more timeVPN process keeps running after Ctrl+C
This was a known issue fixed in the latest version. The launch script now uses trap to clean up background processes on exit. Re-save your profile to get the updated script.
"all resolvers exhausted" message
All scanned resolvers failed within the timeout. Solutions:
8.8.8.8:53Testing from outside Iran NXDOMAIN on all resolvers
This is expected behaviour, not a bug. The scanned resolvers are Iranian public DNS servers. They only forward queries for your tunnel domain when accessed from inside Iran. Testing from Europe, Australia, or anywhere outside Iran will always fail.
"dig v.yourdomain.com NS" shows no results
DNS propagation can take up to 48 hours. Wait and try again. Also check:
ns.yourdomain.com)Server is running but no resolvers pass Phase 3
Try verifying the domain manually from your server:
dig @127.0.0.1 test.v.yourdomain.com A
If this returns NXDOMAIN, the server is not receiving DNS queries correctly. Check the firewall (port 53 UDP must be open) and systemd-resolved is disabled.
KevinNet is a client-side app only. Server installation is covered in the official repos:
See BUILD_INSTRUCTIONS.txt (English) or BUILD_INSTRUCTIONS_FA.txt (فارسی) for the full PyInstaller build steps.
KevinNet ships with a unit test suite (87 tests) covering input validation, scanner helpers, profile config building, and settings handling. Tests run in CI before every release.
pip install pytest dnspython pillow
python -m pytest tests/ -v
All tests must pass before a release is built - the CI workflow gates the platform-specific builds behind a successful pytest run.
The Iranian CIDR ranges, public DNS resolvers, WhiteDNS Iran list, and DoH/DoT endpoint lists live as plain text files in data/:
| File | Contents |
|---|---|
data/iran_cidrs.txt | Iranian IPv4 CIDR ranges sampled during scanning |
data/public_resolvers.txt | Well-known public DNS resolvers (warm-up set) |
data/white_dns_iran.txt | Pre-verified Iranian DNS resolvers (high-hit-rate seed list) |
data/doh_endpoints.txt | DNS-over-HTTPS endpoints scanned by the 🔒 button |
data/dot_endpoints.txt | DNS-over-TLS endpoints scanned by the 🔒 button |
You can edit these files to add private endpoints or remove dead entries - no rebuild needed. When PyInstaller bundles the binary it copies them inside, and the app also looks for a data/ folder next to the executable so user edits take priority over the bundled copy.
MasterDnsVPN by MasterkinG32 (Amin Mahmoudi) GitHub MIT License
VayDNS by net2share GitHub fork of dnstt by David Fifield (public domain)
See THIRD_PARTY_LICENSES.md for full license texts.
Every star and share helps this tool reach one more family that needs it.
See CHANGELOG.md for what's new in each release.
Copyright © 2026 Kevin Haji MIT License See DISCLAIMER.md
Python
97.9%
Shell
1.7%
User-friendly DNS tunnel client for Iran — scan resolvers, save profiles, launch MasterDnsVPN or VayDNS with one click. No config editing required.
See the code🇮🇷 فارسی | 🇬🇧 English
A user-friendly GUI client for DNS tunneling supports MasterDnsVPN and VayDNS
KevinNet automatically scans Iranian IP ranges to find working DNS resolvers, then generates ready-to-use config files and launch scripts with a single click to connect. No config files to edit. No terminal commands to remember.
Created by Kevin Haji · kevinhaji.com · kevin.fullstack.dev@gmail.com
A DNS tunnel disguises your internet traffic as ordinary DNS queries. Iran's DPI filtering cannot easily identify or block it. KevinNet handles all the technical parts scanning for working resolvers, writing config files, copying binaries, launching the VPN so you only need to fill in a few fields and click buttons.
Two VPN engines are supported:
KevinNet ships two public releases. Pick the one that fits your situation:
The current release. This is what you should download unless you have a specific reason not to. It does everything 3.2.2 does plus:
launched 5m ago, etc.)See CHANGELOG.md for the full list of changes.
The previous stable release. Still works, still available on the Releases page. Use this only if:
For everyone else, use v4.1.6. Profile files are compatible between the two versions, so you can switch back and forth without losing your data.
Go to the Releases page and pick one of the two versions:
| Platform | File |
|---|---|
| 🪟 Windows x64 | KevinNet_Windows_x64.exe |
| 🪟 Windows ARM64 | KevinNet_Windows_ARM64.exe |
| 🍎 macOS (Intel + Apple Silicon) | KevinNet_macOS_Universal |
| 🐧 Linux x64 | KevinNet_Linux_x64 |
| 🐧 Linux ARM64 | KevinNet_Linux_ARM64 |
Same platform binaries are available on the v3.2.2 release page. Only download these if 4.1.6 doesn't work for you — see CHANGELOG.md for the comparison.
macOS: After downloading, run in Terminal:
chmod +x KevinNet_macOS_Universal xattr -d com.apple.quarantine KevinNet_macOS_Universal
Linux: Run
chmod +x KevinNet_Linux_x64before launching.
Every release ships with a SHA256SUMS.txt file alongside the binaries. To verify the file you downloaded hasn't been tampered with:
shasum -a 256 -c SHA256SUMS.txt # macOS / Linux
Get-FileHash -Algorithm SHA256 KevinNet_Windows_x64.exe # Windows
Compare the output against the line for your platform in SHA256SUMS.txt. If they don't match, do not run the file - re-download from the official Releases page.
KevinNet is the client app. It connects to a VPN server that you (or someone you know) must set up on a VPS outside Iran.
Any Linux VPS with a public IP address. Popular providers: Hetzner, DigitalOcean, Vultr, Linode.
MasterDNS acts as an authoritative DNS server, so DNS queries for your tunnel subdomain must be forwarded to your VPS. Create two DNS records in your domain provider's control panel:
| Type | Name | Value | Purpose |
|---|---|---|---|
A | ns | Your server's IP | Glue record where your nameserver lives |
NS | v | ns.yourdomain.com | Delegates v.yourdomain.com queries to your server |
Example with domain example.com and server IP 1.2.3.4:
ns.example.com → 1.2.3.4 (A record)v.example.com → ns.example.com (NS record)Your tunnel domain is v.example.com.
Cloudflare users: The
Arecord fornsmust be DNS only (grey cloud), not proxied. Tip: Short names (1–2 chars) leave more room for data per DNS packet → better speed.
Follow the official guide: 👉 https://github.com/masterking32/MasterDnsVPN
After setup you will have:
v.example.com → enter this in KevinNetencrypt_key.txt on the server → enter this in KevinNetThe key must match between client and server. If you lose it, run
cat encrypt_key.txton your server.
Bundled inside KevinNet copied to your output folder automatically when you save. If missing, see ⚠️ Binary missing? below.
Same as MasterDNS any Linux VPS with a public IP.
VayDNS also acts as an authoritative DNS server. The DNS setup concept is identical to MasterDNS: one A glue record + one NS delegation record.
Example with domain example.com and server IP 1.2.3.4:
tns.example.com → 1.2.3.4 (A record glue)t.example.com → tns.example.com (NS record delegation)Your tunnel domain is t.example.com.
Important: The glue record name (
tns) must NOT be a subdomain of the tunnel name (t). They must be separate e.g.tnsandt, notns.t.
Follow the official guide: 👉 https://github.com/net2share/vaydns
After setup you will have:
t.example.com → enter this in KevinNetserver.pub file on the server contains your public keyThe public key authenticates your server it proves to the client that it is talking to the right server and not an interceptor. To get it, run on your server:
cat server.pub
You will see a 64-character hex string like:
0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b
Copy this entire string and paste it into the VayDNS Public Key field in KevinNet.
The public key is safe to share it only verifies your server's identity. The private key (
server.key) must stay on the server and never be shared.
Bundled inside KevinNet copied to your output folder automatically when you save. If missing, see ⚠️ Binary missing? below.
At the top of the Scanner panel, click MasterDNS or VayDNS. Only the fields and save button for your chosen type will show.
| Field | MasterDNS | VayDNS |
|---|---|---|
| Country / Folder | Any name e.g. Iran | Any name e.g. Iran |
| Tunnel Domain | e.g. v.example.com | e.g. t.example.com |
| Key | 32-char key from encrypt_key.txt | 64-char hex key from server.pub |
| Option | Recommended for Iran | Notes |
|---|---|---|
| Target | 100 | How many resolvers to find |
| Concurrency | 80 | Do not go above 100 inside Iran |
| Timeout | 3s | Iranian networks are slow |
| Pool ×1000 | 200 | 200k IPs scanned. Increase to 300–500 if few found |
Run the scan 2–3 times each run tests a different random set of IPs.
Click ▶ Start Scan. Three automatic phases:
🟢 6/6 excellent · 🟡 4–5 good · 🟠 2–3 weak · ⚫ ·0–1 very weak
A profile is saved with sensible defaults. The VPN binary is copied into the output folder automatically.
After any scan, the 📤 Export DNS List button becomes active regardless of which VPN mode you used. Click it to save the found resolver IPs as a plain .txt file - one IP per line. Useful if you want to use the resolver list in another application or script.
The 🔒 Scan DoH/DoT button (new in 3.3.0) probes a curated list of well-known DNS-over-HTTPS (port 443) and DNS-over-TLS (port 853) endpoints. The traffic looks like normal HTTPS, so it's much harder for Iranian DPI to fingerprint as tunnel traffic than plain UDP/53. Working endpoints stream into the results list with a 🔒 icon - paste any of them into a VayDNS profile as a custom resolver when UDP isn't surviving DPI.
The lists live in data/doh_endpoints.txt and data/dot_endpoints.txt next to the app. You can edit them to add private endpoints or remove dead ones without rebuilding.
In the results list, right-click (or two-finger click / Ctrl-click on Mac) to Copy IP, Copy all IPs, or Open output folder in your file manager.
Click 📋 MasterDNS Profiles or 📋 VayDNS Profiles at the top.
Set your browser proxy to SOCKS5 127.0.0.1:18000 (MasterDNS) or SOCKS5 127.0.0.1:7000 (VayDNS).
Every save creates a profile in masterdns_profiles/ or vaydns_profiles/ next to the app.
| Button | What it does |
|---|---|
| 💾 Save Changes | Rewrites config files with your current settings |
| 🚀 Launch VPN | Regenerates files and launches the VPN |
| 📋 Duplicate | Copies the profile great for A/B testing different settings |
| 🗑 Delete | Removes the profile and optionally the output folder |
| Option | Iran optimal | Why |
|---|---|---|
| Encryption Method | 1 XOR | Lowest overhead in small DNS packets. Must match server. |
| Balancing Strategy | 3 Least Loss | Iran has high uneven packet loss favours the most reliable resolver |
| Packet Duplication | 2–3 | Sends each packet via multiple resolvers redundancy on lossy paths |
| Max Upload MTU | 80–100 | Smaller DNS queries look less suspicious to DPI |
| Max Download MTU | 700 | Prevents ISP from fragmenting large DNS responses |
| Min Upload MTU | 38 | Very conservative keeps the maximum number of resolvers usable |
| Min Download MTU | 400 | Keeps resolvers that return slightly smaller responses |
| Log Level | INFO | Shows connection events without flooding the terminal |
| Option | Iran optimal | Why |
|---|---|---|
| Transport | UDP | Plaintext UDP on port 53 most direct path from Iran |
| Resolver | (empty) | Uses all scanned resolvers in order see note below |
| Listen Port | 7000 | The local port your browser proxy connects to |
| Max QNAME Length | 101 | ~50 byte upstream MTU, safe for most Iranian resolvers |
| Idle Timeout | 10s | How long before declaring a session dead. Must match server. Increase to 30s if reconnects are frequent. |
| Keepalive | 2s | How often to ping the server to keep the session alive. Must be less than idle timeout. Must match server. |
| Record Type | txt | TXT records carry the most data and are most compatible under DPI |
| Queue Size | 512 | Internal packet buffer increase to 1024 on fast connections |
| UDP Workers | 100 | Concurrent outgoing queries lower to 50 if you see socket errors |
| Resolver Timeout | 60s | If a resolver doesn't connect within this many seconds, the script moves to the next one |
| Log Level | info | Normal operation |
The Resolver field:
Resolver Timeout seconds.8.8.8.8:53 for UDP · https://dns.google/dns-query for DoH · dns.google:853 for DoT.Testing from outside Iran: Scanned resolvers are Iranian public DNS servers. They only work correctly when connecting from inside Iran. Testing from Australia, Europe, or anywhere else will show NXDOMAIN errors those resolvers cannot reach your tunnel server from a foreign network.
KevinNet v3.0.9+ bundles the correct binary automatically for every platform - upgrade first before trying manual steps below.
Download the client binary from the MasterDnsVPN releases:
| Platform | Download |
|---|---|
| 🐧 Linux x64 | MasterDnsVPN_Client_Linux_AMD64.zip |
| 🐧 Linux ARM64 | MasterDnsVPN_Client_Linux_ARM64.zip |
| 🐧 Linux x64 (legacy glibc) | MasterDnsVPN_Client_Linux-Legacy_AMD64.zip |
| 🪟 Windows x64 | MasterDnsVPN_Client_Windows_AMD64.zip |
| 🪟 Windows ARM64 | MasterDnsVPN_Client_Windows_ARM64.zip |
| 🍎 macOS (all) | MasterDnsVPN releases page |
MasterDnsVPN (macOS/Linux) or MasterDnsVPN.exe (Windows)Download from the VayDNS releases page. Use these exact filenames when placing next to KevinNet:
| Platform | Filename |
|---|---|
| macOS Apple Silicon (M1/M2/M3/M4) | vaydns-client-darwin-arm64 |
| macOS Intel | vaydns-client-darwin-amd64 |
| Linux x64 | vaydns-client-linux-amd64 |
| Linux ARM64 | vaydns-client-linux-arm64 |
| Windows x64 | vaydns-client_windows_amd64.exe |
macOS: "KevinNet is damaged and can't be opened" or "cannot be verified"
chmod +x KevinNet_macOS_Universal
xattr -d com.apple.quarantine KevinNet_macOS_Universal
Or right-click the app → Open → Open.
Linux: "Permission denied" when launching
chmod +x KevinNet_Linux_x64
./KevinNet_Linux_x64
Windows: antivirus blocks the app This is a false positive PyInstaller-compiled apps trigger some antivirus scanners. Add an exception for the file, or build from source yourself (see BUILD_INSTRUCTIONS.txt).
Windows: Persian text appears as separate unjoined characters v3.1.2+ bundles Vazirmatn and loads it automatically on startup. If you are on an older version, upgrade to the latest release from the releases page.
After clicking Save, the country folder has no MasterDnsVPN or vaydns-client
The binary must be placed next to the KevinNet app before saving KevinNet copies it into the output folder. See ⚠️ Binary missing? for download links and exact filenames.
macOS: MasterDnsVPN is there but won't run "cannot be opened"
chmod +x /path/to/Iran/MasterDnsVPN
xattr -d com.apple.quarantine /path/to/Iran/MasterDnsVPN
macOS: vaydns-client-darwin-arm64 won't run
chmod +x /path/to/Iran/vaydns-client-darwin-arm64
xattr -d com.apple.quarantine /path/to/Iran/vaydns-client-darwin-arm64
Finding 0–5 resolvers even after scanning
200 to 500 more IPs scanned = more found2s if the scan takes too long (sacrifices some accuracy)100 inside IranPhase 3 (E2E) passes zero resolvers
Phase 3 tests the actual tunnel through your server. Zero means either:
encrypt_key.txtConnected but browser shows no internet / pages don't load
SOCKS5 127.0.0.1:18000 (MasterDNS) or SOCKS5 127.0.0.1:7000 (VayDNS)Connected but very slow
For MasterDNS try lowering MTU values:
60–80 (smaller packets, less likely to be throttled)600For VayDNS:
80 instead of 101null instead of txt (higher throughput on some resolvers)"parse TOML failed" error when launching MasterDnsVPN
The config file has an unfilled placeholder. This happens if you launch from the output folder without saving through KevinNet. Always save from the Profiles tab before launching. If the error persists:
Frequent disconnections / reconnects
3 more redundancy on lossy paths3 Least LossOnly a handful of resolvers work (most are 1–2)
This is normal most public DNS servers don't forward DNS queries for custom NS delegations. A score of 10–30 good resolvers from a scan of 200k IPs is a good result.
"noise handshake: timeout" repeated in the terminal
The resolver is returning NXDOMAIN it can't reach your tunnel server. The script will automatically move to the next resolver after Resolver Timeout seconds. If all resolvers fail:
dig v.yourdomain.com NS90s to give each resolver more timeVPN process keeps running after Ctrl+C
This was a known issue fixed in the latest version. The launch script now uses trap to clean up background processes on exit. Re-save your profile to get the updated script.
"all resolvers exhausted" message
All scanned resolvers failed within the timeout. Solutions:
8.8.8.8:53Testing from outside Iran NXDOMAIN on all resolvers
This is expected behaviour, not a bug. The scanned resolvers are Iranian public DNS servers. They only forward queries for your tunnel domain when accessed from inside Iran. Testing from Europe, Australia, or anywhere outside Iran will always fail.
"dig v.yourdomain.com NS" shows no results
DNS propagation can take up to 48 hours. Wait and try again. Also check:
ns.yourdomain.com)Server is running but no resolvers pass Phase 3
Try verifying the domain manually from your server:
dig @127.0.0.1 test.v.yourdomain.com A
If this returns NXDOMAIN, the server is not receiving DNS queries correctly. Check the firewall (port 53 UDP must be open) and systemd-resolved is disabled.
KevinNet is a client-side app only. Server installation is covered in the official repos:
See BUILD_INSTRUCTIONS.txt (English) or BUILD_INSTRUCTIONS_FA.txt (فارسی) for the full PyInstaller build steps.
KevinNet ships with a unit test suite (87 tests) covering input validation, scanner helpers, profile config building, and settings handling. Tests run in CI before every release.
pip install pytest dnspython pillow
python -m pytest tests/ -v
All tests must pass before a release is built - the CI workflow gates the platform-specific builds behind a successful pytest run.
The Iranian CIDR ranges, public DNS resolvers, WhiteDNS Iran list, and DoH/DoT endpoint lists live as plain text files in data/:
| File | Contents |
|---|---|
data/iran_cidrs.txt | Iranian IPv4 CIDR ranges sampled during scanning |
data/public_resolvers.txt | Well-known public DNS resolvers (warm-up set) |
data/white_dns_iran.txt | Pre-verified Iranian DNS resolvers (high-hit-rate seed list) |
data/doh_endpoints.txt | DNS-over-HTTPS endpoints scanned by the 🔒 button |
data/dot_endpoints.txt | DNS-over-TLS endpoints scanned by the 🔒 button |
You can edit these files to add private endpoints or remove dead entries - no rebuild needed. When PyInstaller bundles the binary it copies them inside, and the app also looks for a data/ folder next to the executable so user edits take priority over the bundled copy.
MasterDnsVPN by MasterkinG32 (Amin Mahmoudi) GitHub MIT License
VayDNS by net2share GitHub fork of dnstt by David Fifield (public domain)
See THIRD_PARTY_LICENSES.md for full license texts.
Every star and share helps this tool reach one more family that needs it.
See CHANGELOG.md for what's new in each release.
Copyright © 2026 Kevin Haji MIT License See DISCLAIMER.md
Python
97.9%
Shell
1.7%