# Rethink DNS + Firewall + VPN for Android: a WireGuard proxifier, per-app firewall and DoH client in one app

> Rethink is an Android app that combines a multi-hop WireGuard client, a per-app firewall and a DNS-over-HTTPS/DNSCrypt resolver. It is for Android users who want to see and control what each app connects to, and it ships through F-Droid, Google Play or Obtainium.

**celzero/rethink-app** — DNS over HTTPS / DNS over Tor / DNSCrypt client, WireGuard proxifier, firewall, and connection tracker for Android.

- Repository: https://github.com/celzero/rethink-app
- Website: https://rethinkfirewall.com/
- Stars: 5,481 · Forks: 338
- Language: Kotlin
- License: Apache-2.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/celzero-rethink-app

## What Rethink DNS + Firewall + VPN actually does on Android

Rethink is a single Android app that bundles three things a stock phone does not give you: a VPN client that can run several WireGuard, SOCKS5 or HTTP CONNECT tunnels at once in a split-tunnel layout, a firewall that decides per app whether traffic is allowed, and a DNS client that sends every app's DNS lookups to a resolver you pick. The README frames it as three primary modes, VPN, DNS and Firewall, and the modes are meant to be combined rather than chosen one at a time.

The target user is someone who wants to know which app opened which connection and to a where. The README positions the firewall against Little Snitch, LuLu and Glasswire rather than against packet filters: it says the firewall does not care about connections per se, but about what is making those connections. That is a meaningful distinction. A normal firewall rule on a phone would block a port or a host; Rethink blocks or allows an application, optionally conditioned on events like screen-on, screen-off, app-foreground, app-background, and unmetered versus metered connection, or on Play Store categories such as Social, Games, Utility and Productivity.

It is not a generic VPN subscription. There is no bundled exit node for ordinary browsing in the open source app. The proxifier forwards traffic into tunnels you configure, and the DNS mode redirects lookups to resolvers you choose. If you want a one-tap commercial VPN, this is the wrong shape of tool.

## How firestack, ConnectivityService and procfs produce per-app attribution

The mechanism is split between a Go library and the Android framework. Per-app connection mapping is implemented by capturing udp and tcp flows managed by firestack, a Go library, and then asking ConnectivityService for the owner of a socket. The README notes that this API is available only on Android 10 and newer. On Android 9 and below the app reads procfs, specifically /proc/net/tcp and /proc/net/udp, on demand, the same approach the README attributes to NetGuard and OpenSnitch.

That fallback is the source of the app's main accuracy caveat. Socket ownership read from procfs is a snapshot of a shared kernel table, so attribution can lag or miss short-lived connections. The README does not claim parity between the two paths, and the two paths are not the same mechanism at all: one asks the framework who owns a flow, the other infers it from a table.

DNS tracking has a similar split. The README states that tracking UDP and TCP is straightforward, and DNS on Android 12 and above as well, but that DNS requests are trickier to track on Android 11 and below, where a rough heuristic is used which may not hold in all cases. If you plan to audit DNS logs rather than just block apps, that sentence is the one that matters.

The network monitor is the reporting layer on top: a per-app record of when connections were made, how many, and to where. It is a report card, not a live packet capture.

The DNS path itself is a hard fork of Jigsaw-Code/outline-go-tun2socks, per the README, with a UI that borrows minimally from Jigsaw-Code/Intra. A split tunnel traps requests sent to the VPN's DNS endpoint and relays them to a DoH, DoT, DNSCrypt or Oblivious DoH endpoint of your choosing, logging end-to-end latency, request time, the query and the answer. That logging is local to the app; the README does not describe any telemetry upload.

## Installing Rethink from F-Droid, Google Play or Obtainium

The README offers three distribution channels: F-Droid, Google Play and Obtainium. There is no build-from-source tutorial in the README, so the practical install path is one of those three. Pick the channel that matches how you want updates delivered, because the release certificate digests differ per flavour and the README lists them separately.

If you use Obtainium, the README gives the redirect URL that adds the repository directly to the app:

```text
obtainium://add/https://github.com/celzero/rethink-app
```

After installing, the first real task is choosing a DNS resolver, because the default is the project's own endpoint. The README states that https://sky.rethinkdns.com/rs is the default DNS-over-HTTPS endpoint, deployed via Cloudflare Workers, and that you are free to change it. To run your own blocklists against the hosted resolver instead of the app's defaults, the README points at a configuration page:

```text
https://rethinkdns.com/configure
```

Expect the app to ask for VPN permission when you enable any of the three modes, since the split tunnel and the firewall both run through Android's VPN service. The README does not document a rollback path or an export of firewall rules, so before you build up a long denylist, decide whether you are comfortable recreating it by hand.

## Where Rethink is the wrong tool

The clearest limitation is Android version. Per-app attribution through ConnectivityService requires Android 10 or newer. On Android 9 and below the app falls back to procfs, and the README does not present that as equivalent. If your fleet is older than Android 10, treat the per-app firewall as best-effort rather than authoritative.

The second limitation is DNS tracking on Android 11 and below. Because the app uses a heuristic there, a DNS log cannot be read as a complete record of what an app resolved. Blocking may still work; auditing may not.

The third is scope. Rethink is not a content filter for a household and not a central policy console. Rules live on the device, and the README describes no management server, no MDM integration and no rule sync. For an organisation that needs one policy pushed to many phones, this is the wrong layer.

The fourth is the paid surface. The Rethink Proxy Network, a multi-party relay whose packets exit over a serverless proxy hosted on Cloudflare Workers and hop over Windscribe, is priced at $1.75/month for unlimited bandwidth with 5 of 80+ locations active per device. That is a separate product from the open source app, and the README does not claim the app requires it. If you want only the firewall and DNS features, the paid relay is irrelevant; if you wanted a bundled VPN service, note that the relay is the paid piece and it is not the same thing as the WireGuard client.

## How Rethink differs from NetGuard and from Intra

The closest functional alternative named in the README is NetGuard, which the project itself cites as prior art for the procfs approach. The difference is in what each app does with the data. NetGuard is a firewall with a VPN-based traffic path; Rethink adds a proxifier that can carry TCP and UDP over SOCKS5, HTTP CONNECT and WireGuard tunnels at the same time, with different apps routed over different tunnels. The README's own example is routing Firefox over SOCKS5 to Tor, Netflix over WireGuard through a commercial provider, and Telegram or WhatsApp over HTTP CONNECT endpoints simultaneously. NetGuard does not offer that multi-tunnel split.

Against Intra, the difference is narrower and mostly about scope. Rethink's DNS path is a hard fork of outline-go-tun2socks and the UI borrows minimally from Intra, so the DNS plumbing is related. Intra is a DNS-over-HTTPS client; Rethink wraps the same idea in a firewall and a connection tracker. If all you want is to stop DNS tampering, Intra is a smaller surface. If you also want to see and block per-app connections, Rethink is the one that carries both.

Against a resolver-side blocker such as a Pi-hole style setup, the difference is where the decision is made. Rethink decides on the device, per app, including when the device is on a mobile network away from your home resolver. A network-level blocker decides for every device behind it, with no per-app granularity and no visibility into which app asked.

## Maintenance, licence and what upgrading costs you

The repository is not archived, and the last push was on 2026-09-22. Recent releases are v0.5.7 on 2026-09-21, v0.5.6 on 2026-08-09 and v0.5.5z on 2026-08-02. That is a release cadence of roughly a month, with a nightly alpha workflow referenced in the README for the alpha flavour.

Licensed under Apache-2.0. That permits use, modification and redistribution with the usual conditions around notices and patent grants; it is not a copyleft licence, so a fork does not have to publish its source. Nothing here is legal advice, and the licence file in the repository is the authority.

The upgrade cost is mostly in the certificate digests. The README lists three separate release certificate SHA-256 digests: one for the prod flavour on the Play Store and the website, one for the alpha flavour built by the GitHub nightly workflow, and one for the Izzy flavour. If you switch channels, the signing identity changes. Android will refuse to update an installed app across a different signing key, so a channel switch means uninstall and reinstall, which also means losing local firewall rules and DNS settings. The README does not document an export or import for those settings, so plan the migration as a manual rebuild.

A second upgrade consideration: the README states that a configurable DNS resolver with denylist and allowlist management, rewrites and DNS request analysis is launching late 2026, separate from the app. If your workflow depends on that, it is not available yet, and the current path is the hosted configuration page.

## Conclusion

Adopt Rethink if you run Android 10 or newer and want per-app connection visibility plus a DNS resolver you choose yourself, installed from F-Droid, Google Play or Obtainium. Skip it if you need per-app attribution on Android 9 or below, where the app falls back to reading /proc/net/tcp and /proc/net/udp, or if you want to leave firewall rules unattended. Before trusting a build, verify the release certificate SHA-256 digest for the flavour you installed against the digests listed in the README.

## FAQ

### What is the Rethink app?

Rethink DNS + Firewall + VPN is an Android app that combines a multi-hop WireGuard, SOCKS5 and HTTP CONNECT proxifier, a per-app firewall and network monitor, and a DNS-over-HTTPS, DNS-over-TLS, DNSCrypt and Oblivious DoH client with blocklists.

### How do you use the Rethink app?

Install it from F-Droid, Google Play or Obtainium, grant VPN permission when you enable a mode, then choose the DNS resolver you want instead of the default sky.rethinkdns.com endpoint. From there you can set per-app firewall rules based on events like screen-on or metered connection, or on Play Store categories.

### Is the Rethink app safe?

The app is Apache-2.0 licensed open source with a public repository, and the README publishes release certificate SHA-256 digests per flavour so you can check the build you installed. It requires Android's VPN service to function, which is how the split tunnel and firewall operate.

## Sources

- [celzero/rethink-app on GitHub](https://github.com/celzero/rethink-app)
- [License: Apache-2.0](https://github.com/celzero/rethink-app/blob/main/LICENSE)
- [Project website](https://rethinkfirewall.com/)
- [README](https://github.com/celzero/rethink-app/blob/main/README.md)
- [Releases](https://github.com/celzero/rethink-app/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/celzero-rethink-app
