DNS Ad-Blocking Engine
Trigger: Use when building DNS-level ad blocking with blocklist parsing and filtering.
Key Libraries
- Rust:
hickory-dns,hickory-client,hickory-proto,adblock(Brave's engine) - Python:
dnspython,asyncio - Clojure:
clara-rulesfor rule-based blocklist decisions
Implementation
- Primary engine in Rust using
hickory-dnsfor DNS protocol handling - Blocklist parser supporting EasyList (
||domain.com^), hosts (0.0.0.0 domain.com), plain domains - Multi-strategy matcher: Hash set exact (O(1)) → wildcard suffix trie → subdomain walk → regex
- LRU DNS cache using Rust's
lrucrate with configurable TTL per record type - Bloom filter pre-check against massive blocklists (millions of entries)
Connected Skills
encrypted-dns-resolver, dns-cache-layer, blocklist-manager, packet-capture-engine
Pitfalls
- Hickory DNS async runtime conflicts — use separate Tokio runtime for DNS vs packet capture
- Aho-Corasick automaton rebuild is expensive — batch domain updates
- Bloom filter false positives require exact-match fallback chain