How to Configure SOCKS5 DNS Resolution for Proxy Connections in InternetIncome
Enable USE_SOCKS5_DNS=true in properties.conf and add socks5:// proxies to proxies.txt to route all DNS queries through the SOCKS5 tunnel instead of the host’s resolver.
InternetIncome is an open-source automation framework for managing multiple income-generating containers behind proxies. When you enable SOCKS5 DNS resolution, the system launches a lightweight tun-to-SOCKS container (ghcr.io/heiher/hev-socks5-tunnel) that intercepts DNS requests and forwards them through your SOCKS5 proxy, ensuring that hostname lookups follow the same encrypted path as your application traffic.
How SOCKS5 DNS Resolution Works in InternetIncome
The implementation relies on Linux network namespaces and a dedicated DNS resolver file. When start_containers() in internetIncome.sh detects a SOCKS5 proxy and the USE_SOCKS5_DNS flag is enabled, it performs the following sequence:
- Image Pull – Downloads
ghcr.io/heiher/hev-socks5-tunnel:latest(lines 206‑208). - Resolver Preparation – Generates a temporary
resolv.confcontaining public DNS servers (8.8.8.8, 1.1.1.1) and mounts it into the tunnel container (lines 44‑48). - Proxy Parsing – Strips the
socks5://scheme and extractsSOCKS5_ADDR,SOCKS5_PORT,SOCKS5_USERNAME, andSOCKS5_PASSWORDfrom the proxy line (lines 226‑238). - Tunnel Launch – Starts the tun container with the parsed credentials and the custom resolver (lines 243‑251).
- Network Attachment – All subsequent application containers join the tunnel’s network namespace via
--network=container:tun$UNIQUE_ID$i(defined at lines 165‑166), forcing DNS through the SOCKS5 link.
Prerequisites for SOCKS5 DNS Configuration
Before enabling this feature, verify that your environment meets the following requirements:
- Docker is installed and the daemon is running.
- The proxy listed in
proxies.txtsupports remote DNS resolution (the proxy itself must handle DNS queries). - You have write permissions in the repository root to create the temporary
resolv.conffile. - The
ghcr.io/heiher/hev-socks5-tunnelimage is accessible from your host (requires internet connectivity on first run).
Step-by-Step Configuration Guide
Enable SOCKS5 DNS in properties.conf
Open properties.conf in the repository root and set the flag:
# properties.conf
USE_SOCKS5_DNS=true
USE_PROXIES=true
The USE_SOCKS5_DNS variable is defined at lines 14‑17 of the file. When set to true, the script evaluates every proxy line to determine if it begins with socks5:// before launching the tunnel.
Add SOCKS5 Proxies to proxies.txt
Create or edit proxies.txt in the repository root. Each line must use the socks5:// scheme. Authentication is optional but supported:
# proxies.txt
socks5://username:password@192.168.1.100:1080
socks5://203.0.113.45:1080
The script parses these entries in start_containers() (lines 226‑238 of internetIncome.sh), splitting the string to extract host, port, and credentials.
Launch the Tunnel Container
Execute the main script:
./internetIncome.sh
Upon encountering the first SOCKS5 proxy with USE_SOCKS5_DNS=true, the script automatically:
- Pulls
ghcr.io/heiher/hev-socks5-tunnel:latest(lines 206‑208). - Generates a temporary
resolv.confwith Google and Cloudflare DNS (lines 44‑48). - Starts the tunnel container named
tun$UNIQUE_ID$iwith environment variablesSOCKS5_ADDR,SOCKS5_PORT,SOCKS5_USERNAME, andSOCKS5_PASSWORD(lines 243‑251).
All subsequent containers will attach to this tunnel’s network namespace, ensuring their DNS queries traverse the SOCKS5 connection.
Technical Implementation Details
The SOCKS5 DNS feature is implemented entirely within internetIncome.sh. Key implementation points include:
- Conditional Logic: The flag check at lines 223‑251 ensures the tunnel is only created when
USE_SOCKS5_DNSistrueand the proxy scheme issocks5://. - Credential Parsing: Lines 226‑238 handle both authenticated and unauthenticated SOCKS5 URLs by checking for the
@delimiter and splitting on:and@characters. - Resolver File: Lines 44‑48 create a temporary
resolv.confcontainingnameserver 8.8.8.8,nameserver 1.1.1.1, andnameserver 8.8.4.4, which is mounted into the tunnel container to provide upstream DNS. - Network Sharing: The
NETWORK_TUNvariable defined at lines 165‑166 sets--network=container:tun$UNIQUE_ID$i, forcing all application containers to share the tunnel’s network stack and therefore its DNS resolver.
Summary
- Enable the feature by setting
USE_SOCKS5_DNS=trueinproperties.conf(lines 14‑17). - Provide SOCKS5 proxies using the
socks5://scheme inproxies.txt, with optional authentication. - Automatic tunnel creation occurs when
internetIncome.shdetects a SOCKS5 proxy and the flag is enabled, pullingghcr.io/heiher/hev-socks5-tunneland launching it with parsed credentials. - Network namespace sharing ensures all containers use the tunnel’s resolver, routing DNS over the SOCKS5 connection instead of the host’s DNS.
Frequently Asked Questions
Does InternetIncome support SOCKS4 or HTTP proxies for DNS resolution?
No. The SOCKS5 DNS feature specifically requires the socks5:// scheme because it relies on the SOCKS5 protocol’s remote DNS resolution capability. SOCKS4 and HTTP proxies do not support the BIND or UDP ASSOCIATE commands necessary for tunneling DNS queries. If you use http:// or socks4:// entries in proxies.txt, the script skips the tunnel creation and containers will use the host’s default DNS resolver.
What DNS servers are used when SOCKS5 DNS is enabled?
InternetIncome generates a temporary resolv.conf file containing Google DNS (8.8.8.8, 8.8.4.4) and Cloudflare DNS (1.1.1.1). This file is mounted into the hev-socks5-tunnel container at /etc/resolv.conf. The tunnel then forwards all DNS queries received on the virtual interface to these upstream servers through the SOCKS5 proxy. You can verify the exact servers in the script at lines 44‑48 of internetIncome.sh.
How can I verify that DNS queries are routing through the SOCKS5 proxy?
To confirm DNS is tunneling correctly, execute an interactive shell inside one of the running application containers and perform a lookup:
sudo docker exec -it earnapp$UNIQUE_ID$i sh
nslookup example.com
If the SOCKS5 DNS tunnel is active, the query will resolve successfully, and you can further verify by checking that the container’s /etc/resolv.conf points to the tunnel’s virtual interface (typically 127.0.0.1 or the tunnel’s IP). Additionally, the hev-socks5-tunnel container logs will show connection activity when DNS queries are forwarded.
Can I use authenticated SOCKS5 proxies with DNS resolution?
Yes. InternetIncome fully supports SOCKS5 authentication. Include the credentials directly in the proxies.txt URL using the format socks5://username:password@host:port. The parsing logic in internetIncome.sh (lines 226‑238) extracts the SOCKS5_USERNAME and SOCKS5_PASSWORD variables and passes them as environment variables to the hev-socks5-tunnel container. If your proxy requires authentication but you omit the credentials, the tunnel will fail to establish the SOCKS5 connection and DNS resolution will not function.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →