How Zapret Handles Wildcard Domain Matching in Lists
Zapret delegates wildcard domain matching to WinDivert, where any domain entry automatically matches its subdomains without requiring explicit wildcard syntax.
The Flowseal/zapret-discord-youtube repository provides a Windows-based circumvention tool that relies on the WinDivert packet-filter driver to process traffic. Understanding how wildcard domain matching works in Zapret is essential for customizing blocklists and ensuring comprehensive coverage of target services like Discord and YouTube.
How WinDivert Implements Wildcard Domain Matching
Zapret does not implement its own domain matching logic. Instead, it relies entirely on WinDivert's host-list feature, which provides built-in wildcard behavior for every domain entry.
When winws.exe receives a list file via the --hostlist or --hostlist-domains parameters, WinDivert parses each line and applies the following matching rules:
-
Automatic subdomain coverage – A plain entry like
example.commatchesexample.comand all subdomains such aswww.example.com,api.example.com, ordeep.sub.example.com. This behavior is hardcoded into WinDivert's host-list matcher. -
Explicit wildcard syntax – You may optionally prefix entries with an asterisk (e.g.,
*.example.com), which produces identical results to a plain entry but clarifies intent for list maintainers. -
Line-separated format – Each non-empty line in the list files represents one domain pattern. Comments and blank lines are ignored during parsing.
Configuring Domain Lists in Zapret
The --hostlist Parameter
The primary mechanism for loading domains occurs in general.bat, where winws.exe receives list files through the --hostlist argument. This instructs WinDivert to filter traffic destined for any host matching the supplied patterns.
set "BIN=%~dp0bin"
set "LISTS=%~dp0lists"
start "" /min "%BIN%winws.exe" ^
--hostlist="%LISTS%list-general.txt" ^
--hostlist="%LISTS%list-general-user.txt"
In this configuration, entries in list-general.txt trigger filtering for the exact domain and all its subdomains automatically.
Domain-Only Filtering with --hostlist-domains
For services operating across multiple ports (such as Discord's media servers), Zapret uses the --hostlist-domains flag to restrict matching to the DNS name portion only, ignoring port numbers.
In general.bat (line 19), you will find:
--hostlist-domains="%LISTS%list-general.txt"
This ensures that example.com:443 and example.com:80 match equally when example.com appears in the list.
Practical Examples and List Files
Default Lists vs User Lists
Zapret maintains domain lists in the lists/ directory with specific purposes:
-
lists/list-general.txt– The default blocklist containing domains for Discord and YouTube services. Each entry automatically covers subdomains. -
lists/list-general-user.txt– A user-editable copy created automatically on first run. This file follows identical wildcard matching rules and persists across updates.
To add custom coverage, edit list-general-user.txt and insert your domain:
mydomain.com
*.example.org
Both entries match sub.mydomain.com and sub.example.org respectively, requiring no additional configuration.
Example Entries
Valid patterns in any Zapret list file include:
googlevideo.com
*.discord.gg
cdn.discordapp.com
According to the repository README, "поддомены автоматически учитываются" (subdomains are automatically accounted for), confirming that googlevideo.com matches r5---sn-8xgp1vo-xfge7.googlevideo.com without explicit wildcard notation.
Summary
- Zapret relies on WinDivert's native host-list matcher for all domain matching operations.
- Plain domain entries automatically match subdomains without requiring
*.prefixes. - The
--hostlistparameter loads list files, while--hostlist-domainsrestricts matching to DNS names only. - User customizations belong in
list-general-user.txt, which persists across tool updates. - All list files are simple line-separated text files processed by
winws.exe.
Frequently Asked Questions
Does Zapret support regex patterns in domain lists?
No, Zapret does not support regular expressions in its list files. The tool passes list files directly to WinDivert, which implements only suffix-based matching (automatic subdomain matching) and optional leading wildcards. For complex filtering, you must rely on the specific domain entries or use separate firewall rules.
Why does example.com block sub.example.com automatically?
This occurs because WinDivert's host-list matcher treats every domain entry as a suffix pattern. When example.com is present in the list, WinDivert checks if the packet's destination hostname ends with that string, effectively covering all subdomains. This design choice simplifies list maintenance by eliminating the need to enumerate every subdomain manually.
Where do I add custom domains in Zapret?
Add custom domains to lists/list-general-user.txt in the Zapret installation directory. This file is created automatically when you first run the application. Entries follow the same wildcard domain matching rules as the default list-general.txt, but modifications to the user list persist through software updates without being overwritten.
What is the difference between --hostlist and --hostlist-domains?
The --hostlist parameter filters based on the full host string including potential port information, while --hostlist-domains applies the filter exclusively to the domain name portion of packets. According to the WinDivert documentation referenced in the Zapret implementation, --hostlist-domains is specifically designed for services using the same domain across multiple ports, ensuring consistent blocking regardless of the destination port number.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →