【一键脚本】DNS解锁:让你的小鸡解锁AI,解锁流媒体

Many people buy US/Japan/Singapore-made machines to run AI, buy Hong Kong machines to post, browse the web. You can also see many merchants offering DNS unlock services.

Our pain point is that, due to regional reasons or IP quality, we can’t access certain streaming sites or AI sites, but the machines in unlocked regions may be unaffordable or have high latency.

Common solutions include:

  1. Client-side traffic splitting: clients like Clash or V2rayN support routing by domain or IP, using different nodes to access different sites to meet the unlocking needs.
  2. Server-side splitting: mainstream node setup tools like Xray, singbox support server-side splitting, based on domain or IP, a “chain proxy” (use an ss-like proxy and forward the traffic again to the landing node).
  3. DNS unlocking: distribute traffic via DNS. Use SmartDNS tools to set routing rules, forwarding designated traffic to the unlocking machine, which forwards to the real site.

Let the client’s actual TCP/HTTP traffic to streaming platforms bypass your “unlock machine,” with the unlock machine then forwarding to the real streaming server, so the other end sees the exit IP of the unlock machine.

Of course, DNS unlocking and server unlocking aren’t completely distinct, and node setup tools also support specifying in the config the DNS server for a domain; you can use server-side routing and DNS unlocking together.

DNS unlocking

Essentially, it’s using DNS routing tools like SmartDNS to provide a “specific answer” for a “specific set of domains (streaming platform domains),” thereby guiding the client connections to your desired target.
In our setup, these domains are resolved to the unlocker machine’s IP, so all connections hit the unlocker first.

Implementation:
Nginx

  • HTTPS: stream + ssl_preread pass-through (layer-4 proxy based on SNI), preserve the original SNI, do not decrypt.
  • HTTP: port 80 reverse proxy, Host header passed through.

DNS unlocking is responsible for “bending the traffic,” Nginx for “pushing the traffic out.” Neither can be missing.

Recommended installation methods:

  • Direct DNS modification: have the “unlocked machine” system DNS point directly to the unlocker’s SmartDNS
    • Unlocker: SmartDNS + Nginx, configure streaming domains → its own public IPv4, other domains fall back to 1.1.1.1 and other public DNS.
    • Unlocked machine: set system DNS to the unlocker IP. This makes the streaming domain resolution result in the unlocker’s IPv4, and the actual TCP/HTTPS will also hit the unlocker and be forwarded by Nginx.
  • More complex but with the best resolution: install SmartDNS locally on the unlocked machine as well, routing streaming domain resolution to the “unlocker IP” while other normal domains go to 1.1.1.1, etc.

Why is the second method better?
Because some Geo-DNS will return better results depending on the DNS query source IP. If all queries use the DNS unlocking machine’s IP for DNS queries, the worst case is:
a Hong Kong machine queries the IP of google.com, the unlocker in the US returns the US Google IP. The latency from Hong Kong to Google, which was ~2 ms, jumps to around 200 ms.

From scratch: configure the unlocker (in the target region’s VPS)

I’m using two machines for the demo:

  • Unlocker SG 159.223.86.13
  • Unlocked AU 170.64.197.111

One-click script download command (open-source address: oneclick_smartdns):

curl -fsSL https://raw.githubusercontent.com/kilvil/oneclick_smartdns/main/oneclick.sh | bash

Start with the smartdnsctl command

  1. Install components (press z → Nginx/SmartDNS)

  2. Configure the default upstream DNS

  3. Create the “unlock machine group”

    • On the group page press n: group name like UnlockHost, DNS address can be left blank (this group doesn’t use upstream).
    • Enter the group, press m to switch to address, press e to fill ident=the machine’s public IPv4 (if not auto-filled).
  4. Check the platforms to unlock

    • Left side Region, right side platforms. If occupied by another group, it shows “! GroupName” and cannot be selected.
    • Press Space to select, press again to deselect.
  5. Press s to save

  6. Open ports and service status (if you’re using a cloud provider’s security group)

    • Open inbound 53/UDP, 80/TCP, 443/TCP; confirm SmartDNS/Nginx are active (the UI top shows status).
    • SmartDNS “start” won’t override system DNS; don’t use the unlocker to “Override system DNS” (that would cause traffic to loop on itself and not exit)
  7. Validate (on the unlocker)

    • After exiting the UI with q, run nginx -t to check the nginx configuration
    • systemctl status smartdns nginx shows both services as active.

Accessing the unlocked machine, two options to choose

  • Plan A (Direct DNS, easier): point the system DNS to the unlocker
    • Linux (systemd-resolved):
      • sudo resolvectl dns eth0 .
    • Validation:
      • dig +short www.netflix.com @ should return the unlocker’s public IPv4 (or the specific platform domain, depending on the unlock service you selected).
      • After the unlocked machine’s node connects, visiting the corresponding platform should display the target region.
  • Plan B: local SmartDNS nameserver to the unlocker
    • The machine itself also runs this tool; configure default upstream DNS. 1.1.1.1/8.8.8.8
    • Create a new SG group, select the same platforms as the previous unlocker and save.
    • The local system DNS points to 127.0.0.1 (via the z menu, choose to override system DNS → 127.0.0.1).

The Ultimate Freeloading Trick

People can use powerful search engines to find SNI Proxy instances in various regions: FOFA. Based on a world map, choose your preferred region and find one or two accessible IPs.

The principle is that some people set up SNI Proxy without a firewall, allowing only their own machines to use these SNI Proxy services. That is, you’ve set up unlocking services but exposed them to everyone, which invites others to freeload. It’s recommended to use ufw to block non-owned IPs.

实测可用的IP

JP: 140.238.50.134

With these IPs, you can unlock directly on a single machine!

Configure on a “single machine”

  1. Open the tool, go to the DNS group list
    • First-time use can install SmartDNS via the z menu. No need to install a local Nginx.
  2. Create a group for each region
    • In the group page press n, enter the group name (recommended to use region names like US, JP, UK).
    • Enter the group then:
      • Press m to switch parsing method to address.
      • Press e to set ident to “the region’s sniproxy public IPv4” (e.g., 203.0.113.10).
    • Note: This means “resolve traffic by domain directly to the remote sniproxy”; this machine does not act as a proxy.
  3. Check the groups to unlock platforms
    • Left: Region; right: platforms.
  4. Press s to save
    • If SmartDNS is running, you may be prompted to restart to apply; a restart is recommended.
  5. Let the client use this “single machine” DNS
    • For personal use: use the tool’s “Override system DNS” to set the system DNS to 127.0.0.1.
  6. Validation:
    - dig +short www.netflix.com @127.0.0.1 should return a regional sniproxy public IPv4 (the IP you entered in address)
    - Access the corresponding platform; the platform should exit via that region.

Guard against freeloaders, firewall

First install ufw

  1. Ensure you don’t lock yourself out: open SSH
    • sudo ufw allow OpenSSH
  2. Allow your own unlocked machine IP to access 80/443
    • sudo ufw allow proto tcp from <IP, e.g., 203.0.113.10> to any port 80
    • sudo ufw allow proto tcp from <IP, e.g., 203.0.113.10> to any port 443
  3. Deny other sources from accessing 80/443 (if you opened earlier, remove old rules)
    • View numbers: sudo ufw status numbered
    • Delete any “80/tcp ALLOW Anywhere” or “443/tcp ALLOW Anywhere” rules: sudo ufw delete
  4. Global default policy (recommended to deny by default)
    • sudo ufw default deny incoming
    • sudo ufw default allow outgoing
  5. Enable or reload UFW
    • First time: sudo ufw enable
    • If already enabled: sudo ufw reload
  6. Validation
    • Local check: sudo ufw status verbose
    • Allowed port test (your unlocked machine): openssl s_client -connect <SERVER_IP>:443 -servername www.example.com -brief

Underlying principle

This small script is essentially to help everyone operate SmartDNS routing rules, so you don’t need to consider which domain the streaming service uses; just configure by platform. You can also verify the whole process with simple commands after configuration to see what the config file looks like.

Configuration files:

  • SmartDNS
    • Main config: /etc/smartdns/smartdns.conf
    • DNS cache: /etc/smartdns/cache
    • Processes and service: systemctl status smartdns
  • Nginx
    • Main config: /etc/nginx/nginx.conf
    • HTTP sites: /etc/nginx/conf.d/*.conf
    • Stream (layer-4) sites: /etc/nginx/stream.d/*.conf (included from the main config)
    • Dynamic module directory: /usr/lib/nginx/modules
    • Module load include: /etc/nginx/modules-enabled/*.conf
    • Logs: /var/log/nginx/access.log, /var/log/nginx/error.log

SmartDNS configuration highlights and examples

  • Recommended basic options (already added by default):
dualstack-ip-selection no
speed-check-mode none
serve-expired yes
serve-expired-reply-ttl 3
serve-expired-prefetch-time 21600
prefetch-domain yes
cache-size 32768
cache-persist yes
cache-file /etc/smartdns/cache
cache-checkpoint-time 86400
  • Define upstream DNS groups
    • Example: put 1.1.1.1, 8.8.8.8 into a separate group named US
      • server 1.1.1.1 -group US -exclude-default-group
      • server 8.8.8.8 -group US -exclude-default-group
    • Default (non-group) fallback DNS (applies in order):
      • server 9.9.9.9
      • server 114.114.114.114
  • Domain rules (choose one of two)
    • Specify upstream group parsing (nameserver)
      • Syntax: nameserver /<domain or regex>/ -group <GroupName>
      • Example: nameserver /.netflix.com/ -group US
    • Specify fixed-address parsing (address)
      • Syntax: address /<domain or regex>/ <IPv4>
      • Example: address /.netflix.com/ 203.0.113.10
  • The “unlocker” group (make all selected domains resolve directly to this machine’s public IPv4)
#> unlock special address 203.0.113.5
address /.netflix.com/ 203.0.113.5
address /.hulu.com/ 203.0.113.5
#< unlock

This script tool uses the content between lines like #> <region> <id> and #< as the management markers (used to identify deletions/rewrites).

Nginx configuration principle

Because Nginx does not include the stream module by default, we use dynamic module loading to enable this function.

  • Stream module

    • Module file location: /usr/lib/nginx/modules/ngx_stream_module.so
    • The main config uses include /etc/nginx/modules-enabled/*.conf to dynamically import the module;
    • In /etc/nginx/modules-enabled/50-mod-stream.conf add:
      • load_module /usr/lib/nginx/modules/ngx_stream_module.so
  • In the main config, include the stream directory

    • At the end of /etc/nginx/nginx.conf, add:
      • stream { include /etc/nginx/stream.d/*.conf; }
  • HTTPS SNI passthrough

    • Example: /etc/nginx/stream.d/smartdns_stream.conf:
map $ssl_preread_server_name $proxy_host {
    default $ssl_preread_server_name;
}
server {
    listen 443 reuseport;
    proxy_pass $proxy_host:443;
    resolver 1.1.1.1 8.8.8.8 valid=10s;
    resolver_timeout 5s;
    ssl_preread on;
    proxy_ssl_server_name on;
}

Here using 1.1.1.1, 8.8.8.8 means the unlocker uses this DNS to reach the final target site. If you have a vendor-provided DNS unlock machine, you can nest DNS unlocking here! (Other unlocked machines can also use this DNS unlock)

  • HTTP 80 reverse proxy is simpler, part of basic Nginx features (Host pass-through)
    • Example: /etc/nginx/conf.d/smartdns_http.conf:
map $host $http_upstream {
    default $host;
}
server {
    listen 80;
    resolver 1.1.1.1 8.8.8.8 valid=10s;
    resolver_timeout 5s;
    location / {
        proxy_set_header Host $host;
        proxy_pass http://$http_upstream:80;
    }
}

Is it necessary to enable DNS unlocking?

Personally, I think with vendors providing DNS unlocking, using it to nest unlocking for other machines or for simple DNS-based routing is a very good option.

Some streaming services impose not only regional restrictions but also IP-quality constraints. When you have few machines, nesting unlocks maximizes what vendors provide for DNS unlocking!

Other times, if you DIY DNS unlocking, it may not be as meaningful if you don’t have many regions, and you also worry about IP quality causing the unlock on the unlock machine to fail.

You’ve probably also experimented with client-side routing rules:

  • Previously you had to manually toggle proxies between LAN and WAN; now you can learn direct connection/proxy rule configurations, avoiding manual toggling
  • Previously you manually switched nodes to balance latency and unlocking; now you can route by site, using different nodes for different sites

I believe once you complete your own DNS unlocking, you’ll feel enlightened and hooked just like when you first learned routing rules.

Originally you’d configure routing on phones, computers, and smart routers to split traffic by node → now a single server-side configuration takes effect across the board (Clash subscriptions can also achieve this). Previously you disliked that Hong Kong-based nodes couldn’t run AI → now you rely on Hong Kong’s low latency, and DNS unlocking for various AIs works smoothly.

102 Likes

感谢佬友分享

2 Likes

感谢佬友分享

2 Likes

收藏学习

2 Likes

感谢佬友分享

1 Like

没有用nginx,caddy感觉应该也可以,不过估计caddy也要插件

2 Likes

感谢佬分享

1 Like

Thank you for sharing!

3 Likes

Thank you for sharing!!!

1 Like

能用得上

1 Like

感谢分享! 学习学习! :smiling_face_with_three_hearts:

感谢佬友分享

1 Like

Thank you for sharing :folded_hands:

1 Like

Thank you for sharing the tutorial!

3 Likes

有意思

curl https://cdn.spiritlhl.net/https://raw.githubusercontent.com/oneclickvirt/UnlockTests/main/ut_install.sh -sSf | bash
./ut

测测真dns解锁了么

2 Likes

感谢大佬!

1 Like

感谢佬分享

1 Like

This is useful. Thanks for sharing.

2 Likes

Support! It’s written in great detail; you must provide a recommendation.

2 Likes

感谢佬友分享