Skip to content
vmcsoftPublic

About

Android DNS changer with DNS-over-HTTPS, custom resolvers, and Quick Settings controls.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

AeroDNS app icon

AeroDNS

A lightweight, open-source DNS changer for Android.

Android CI Apache-2.0 license Android 7.0+

AeroDNS changes the device DNS resolver through Android's VpnService API. It is designed to route only DNS traffic, keeping ordinary application traffic on the device's underlying network.

Install

Get the maintained app from Google Play. The source on main may be ahead of the version available to your device; see the changelog for version history. GitHub CI retains validation reports; it does not distribute signed app updates.

Features

  • One-tap DNS connect and disconnect
  • Standard DNS and DNS-over-HTTPS (DoH)
  • Built-in Cloudflare, Google, AdGuard, OpenDNS, and Quad9 profiles
  • Custom IPv4, IPv6, and DoH resolvers
  • Parallel DNS latency testing for the selected protocol
  • Quick Settings tile
  • Automatic recovery after network changes
  • OLED-friendly Jetpack Compose interface
  • No ads, analytics, accounts, or VMCSoft-operated DNS servers

How it works

For standard DNS, AeroDNS establishes a VPN interface with the selected DNS servers and no default route for normal application traffic.

For DoH, the app exposes a virtual DNS address at 10.0.0.1, routes only that address into the VPN interface, and forwards DNS packets to the selected HTTPS resolver through protected sockets on the underlying network.

Important

AeroDNS is a DNS changer, not an anonymity service or a full-tunnel VPN. Your selected DNS provider can observe your DNS queries, and non-DNS traffic does not pass through AeroDNS.

See Architecture for the technical model and current protocol limitations.

Connection status and limits

  • Checking DNS… means Android has established the interface and a DNS check is running.
  • Connected means the latest check succeeded through the selected DNS path.
  • DNS check failed keeps the VPN in place so a later check can recover. You can choose another resolver or disconnect when Always-on is off.

Checks query example.com on connection and again 30 seconds after each result. They show sampled resolver health, not a guarantee that every domain or app works. Filtering that domain can make a working resolver fail the check.

The DoH packet loop supports IPv4 UDP DNS; TCP DNS and IPv6 DNS packets inside the loop are not implemented. Apps using their own DNS may bypass Android's selected resolver. Android Private DNS, manufacturer firmware and network conditions can affect behavior. See Testing for the validation scope.

Always-on VPN

When Android Always-on VPN is selected, turn it off in Android VPN settings before disconnecting or running a speed test. You can still choose another DNS resolver. Leave Block connections without VPN off: AeroDNS routes DNS only, so this Android option blocks ordinary app traffic. If AeroDNS cannot read the Android VPN settings, it directs you there to manage the connection. Android 7–9 compatibility uses system settings that may differ on manufacturer builds; broader device validation remains open.

Build from source

Requirements:

  • JDK 17
  • Android SDK Platform 36.1 and Build Tools 36.0.0
  • Android Studio or the included Gradle wrapper
git clone https://github.com/vmcsoft/aerodns.git
cd aerodns
./gradlew assembleDebug

Install a connected-device build:

./gradlew installDebug

This uses the production application ID with a debug key and cannot update the Play-signed installation. Use the isolated validation package to keep a development build alongside the Play app without removing its data.

Run the local test suite:

./gradlew testDebugUnitTest

More validation scenarios are documented in Testing.

Security and privacy

AeroDNS does not operate a backend or upload telemetry. Connected DNS traffic and health checks use the selected resolver; speed tests contact the providers being measured. Custom DoH endpoint discovery can use the underlying network's DNS. Read PRIVACY.md for the complete data-flow summary.

Custom DoH profiles include an advanced, opt-in certificate-verification override for resolvers that cannot use Android's normal trust store. It is disabled by default, isolated from built-in providers, and exposes DNS traffic to interception when enabled. See SECURITY.md before using or modifying this feature.

Please report vulnerabilities privately through GitHub Security Advisories.

Contributing

Bug reports, documentation improvements, tests, and focused code contributions are welcome. Read CONTRIBUTING.md before opening a pull request.

By participating, you agree to follow the Code of Conduct.

License

Copyright 2026 VMCSoft and AeroDNS contributors.

Licensed under the Apache License 2.0.

About

Android DNS changer with DNS-over-HTTPS, custom resolvers, and Quick Settings controls.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages