Magic DNS
Every peer gets a stable .blinex hostname derived from its device name, resolved by a resolver the agent runs locally.
It configures itself
The agent points the operating system at its own resolver on startup and puts the original settings back on a clean shutdown. There is nothing to configure — no /etc/hosts, no port forwarding, no manual resolver change.
- Linux with a kernel TUN device — a per-link override on the mesh interface via
resolvectl. Crash-safe for free: the kernel destroys a non-persistent TUN device when its process dies, and systemd-resolved drops the override with it. - Windows, and netstack peers — the adapters are pointed at the agent’s resolver and the previous settings are backed up first, then restored on exit.
Renaming a device
Renaming from the dashboard updates the DNS label and removes the old one, so a device never answers to two names at once. The name is operator-managed: re-enrolling does not overwrite it.
Malicious-domain filtering
On by default, with no per-device configuration. The management server periodically compiles a public threat-intel feed and serves it to every agent, whose resolver checks each query — and its parent domains, so subdomains are covered — before forwarding. A match is answered with NXDOMAIN, the same failure shape as a domain that genuinely does not exist.
Set MGMT_BLOCKLIST_URL="" on the management server to disable it.
Checking it
# through the system resolver, the way an application would
getent hosts server-2.blinex
# or query the agent's resolver directly
dig @127.0.0.1 -p 53535 server-2.blinexTest through the system resolver, not only with dig against the resolver directly — the two answer over different paths, and only the first is what your applications actually use.
Everything else
Queries that are not for .blinex and not on the blocklist are forwarded upstream (8.8.8.8:53 by default, set BLINEX_DNS_UPSTREAM to change it). If the upstream cannot be reached the resolver answers SERVFAIL rather than going silent, so clients fail over immediately instead of waiting out a timeout.