Route Traffic by DomainSet traffic policies with domains instead of maintaining IP lists and policy-routing rules by hand; DNS answers update the eBPF maps automatically.
Per-Flow DNS IsolationEach Flow has independent DNS upstreams, rules and cache, preventing cross-Flow leaks.
eBPF Kernel Data PlaneXDP and TC steer packets in the kernel, with no userspace datapath or iptables.
Standard Linux, No Lock-InRun on Debian, Arch or openSUSE; keep configuration in one directory and upgrade by replacing the binary.
Egress-Aware DNSEach Flow queries DNS through its selected egress, so CDN answers match the path traffic actually uses.
Container Egress, Isolated FailuresSend selected traffic through any TProxy-compatible Docker container; direct traffic remains independent if it fails.