Dnscrypt-proxy 2 – A flexible DNS proxy with support for encrypted DNS protocols
github.com
github.com
It was actually the post "Big ISPs aren’t happy about Google’s plans for encrypted DNS" [1] which made me think that I will tackle this issue now, even though I was already thinking about this for months.
Fortunately, openbsd added DoH support to their recursive resolver, allowing me to get rid of dnscrypt-proxy.
My only complaint is that it doesn't stay running in the background waiting for connection if you boot up without wifi. There is a 1 hour timeout, but it doesn't seem to reliably keep the service hanging around till you connect to a wifi. Not a big deal - it starts up pretty much immediately from the Task Manager Services tab.
I imagine if you have a dedicated router with limited RAM or are running a UNIX desktop there may be better options, but for a Windows laptop connecting direct to untrusted connections (e.g. 4G phone tether) it does the job just fine.
Both. It'll easily use several hundred mb of ram and, if you use its cache feature (enabled by default) and hit the cache while measuring the latency, you'll see it takes about 10x the time to respond compared to pdnsd's cache.
Therefore, when I used it, I put pdnsd in front.
I see people here are using some DNS switchers in macos, but you can also configure an extra 'location' in your networking configuration. My default location uses the dnscrypt-proxy server I run locally and another uses CloudFlare, for the rare occasions where things break. I haven't had anything break really, but sometimes you want to test certain things and it is useful to be able to switch quickly.
https://wiki.alpinelinux.org/wiki/Linux_Router_with_VPN_on_a...
My DHCP server hands out the router's IP as a DNS server, then that DNS server forwards through the VPN to my VPN provider's DNS server, or to my DNSCrypt servers.
The good thing about it is it works on every host no matter what platform, configuration, application without any installed software.
When I am out and about I just use a VPN on my phone and use the accepted DNS server pushed to me (which is an internal one to my VPN provider).
If you’re interested in something lightweight for OpenWrt give this a try:
https://openwrt.org/docs/guide-user/services/dns/doh_dnsmasq...
Why? Go compiles to distributable binaries, Go binaries do not depend on Go to run. You wouldn’t need to actually install Go on the router
> The dnscrypt-proxy file is quite large, but can be compressed for a massive reduction of its size, from ~12 Mb down to ~2 Mb.
Routers typically have 8-16 Mb of storage. Even 2 Mb is a bit much but even if the size doesn’t bother you the memory usage is still relatively extreme when compared to the link I shared.
[1] https://github.com/dnscrypt/dnscrypt-proxy/wiki/Installation...
Last month or so, the main GitHub repo for DNSCrypt randomly got deleted. It wasn't until several days later, the author posted a tweet saying he/she are not supporting it anymore.
Now it has seemingly been resurrected...after I have already configured my server to use a new project called getdns (and stubby).
The GitHub repository for dnscrypt-proxy was simply moved from my personal GitHub account to the DNSCrypt organization. GitHub automatically adds redirections when a project is moved, so this should be transparent.
dnscrypt-proxy 2 is actively supported since it was released in January 2018. What has been EOL'd is the legacy dnscrypt-proxy 1.x client, after having been supported for 7 years.
The protocol itself is also still evolving, with the recent introduction of a lightweight alternative to Tor in order to hide IP addresses: https://raw.githubusercontent.com/DNSCrypt/dnscrypt-protocol...
Besides the main website https://dnscrypt.info, there is a subreddit for announcements: https://www.reddit.com/r/dnscrypt/
I normally use WireGuard and use a DNS server supplied by that. If WireGuard is offline, I automatically use DNSCrypt.
Been using it for years, but did not know of the recent episode. Leaves you wondering..