DNScrypt-proxy 2

dnscrypt.info
DNScrypt-proxy 2

A flexible DNS proxy, with support for modern encrypted DNS protocols including DNSCrypt V2, DNS-over-HTTPS and Anonymized DNSCrypt. Also allows for advanced monitoring, filtering, caching and client IP protection through Tor, SOCKS proxies or Anonymized DNS relays.

Open Source

DNScrypt-proxy 2 Source Code

Author

DNSCrypt

Description

dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols.

#anonymized#anonymized-dns#dns#dns-over-https#dnscrypt#dnscrypt-proxy#dnscrypt-proxy2#doh#oblivious-dns-over-https#oblivious-doh#odoh#proxy

Homepage

https://dnscrypt.info

License

ISC

Created

08 Jan 18

Last Updated

29 Jul 26

Latest version

2.1.18

Primary Language

Go

Size

32,478 KB

Stars

13,516

Forks

1,120

Watchers

13,516

Language Usage

Language Usage

Star History

Star History

Recent Commits

  • Frank Denis (22 Jul 26)

    PQ: pad resumed UDP queries to the regular question size target Also discard oversized tickets and fall back to TCP when a query cannot fit a datagram.

  • Frank Denis (22 Jul 26)

    Forwarding: only use TCP with bootstrap resolvers Everything else is just sent to local devices, so UDP is fine. Fixes #3295

  • Frank Denis (19 Jul 26)

    Add the version number to the UI web pages

  • Frank Denis (18 Jul 26)

    Bump

  • Frank Denis (18 Jul 26)

    Improve examples

  • Frank Denis (18 Jul 26)

    Real TCP queries dial a fresh connection every time

  • Frank Denis (18 Jul 26)

    Start benchmarking before Write(), not the setup time

  • Frank Denis (18 Jul 26)

    Stop counting PQ certs transfer time in the startup benchmark

  • Frank Denis (18 Jul 26)

    Support $PROXY in forwarding rules Fixes #2441

  • Frank Denis (18 Jul 26)

    Update github actions

  • Frank Denis (18 Jul 26)

    Update miekg/dns

  • Frank Denis (18 Jul 26)

    Fix PQ certificate fallback on fragmented UDP paths Try the rollover-sized certificate query over UDP first and return as soon as the small query succeeds so that a truncated response can trigger TCP fallback instead of waiting for large UDP probes to time out. We keep relayed UDP packets at the intended size after accounting for the Anonymized DNSCrypt header. When retrying through a relay over TCP, retain a rollover-sized inner query because the relay still forwards it to the resolver over UDP and applies the anti-amplification thing. Preserve the UDP RTT when TCP is used only to complete certificate retrieval, so resolver latency does not incorrectly appear to be the TCP fallback latency.

  • Frank Denis (13 Jul 26)

    UI: limit the size of top domains map

  • Frank Denis (13 Jul 26)

    Improve ODoH diagnostics

  • Frank Denis (13 Jul 26)

    Update CodeQL action

  • Frank Denis (13 Jul 26)

    Sync deps

  • Frank Denis (13 Jul 26)

    Update deps

  • Frank Denis (13 Jul 26)

    Bump

  • Frank Denis (13 Jul 26)

    Mention that dnscrypt_servers also affects PQDNSCrypt

  • Frank Denis (13 Jul 26)

    Reuse PQ key pairs

  • Frank Denis (13 Jul 26)

    ephemeral key pairs are for X25519

  • Frank Denis (13 Jul 26)

    Update README.md to include PQ stuff

  • Frank Denis (13 Jul 26)

    Make pqdnscrypt a setting

  • Frank Denis (13 Jul 26)

    Validate ODoH padding length Not really necessary, since responses are authenticated, but useful to spot broken server implementations.

  • Frank Denis (11 Jul 26)

    local DoH: pad responses, not the incoming query

  • Frank Denis (11 Jul 26)

    resolveUsingResolver: don't return an error if we got some IPs Even if this is not the full set of IPs.

  • Frank Denis (11 Jul 26)

    pattern matcher: test membership, not nil

  • Frank Denis (11 Jul 26)

    When using SOCKS + relay + a simple DNS exchange, send to the relay Not to the server

  • Frank Denis (11 Jul 26)

    lock source.refresh

  • Frank Denis (11 Jul 26)

    cache: include CD bit in the cache key

DNScrypt-proxy 2 Security

6.6/10

Repo Security Summary

Updated 13 Jul 26

  • Maintained 10/10
  • Dangerous-Workflow 10/10
  • Packaging N/A
  • Code-Review 0/10
  • Token-Permissions 0/10
  • CII-Best-Practices 0/10
  • SAST 10/10
  • Binary-Artifacts 10/10
  • Security-Policy 0/10
  • Fuzzing 10/10
  • License 10/10
  • Pinned-Dependencies 8/10
  • Branch-Protection N/A
  • Signed-Releases 8/10

DNScrypt-proxy 2 Website

Website

DNSCrypt version 2 - Official Project Home Page | DNSCrypt

New home of the DNSCrypt project, now implementing multiple protocols to improve DNS security. Download official DNSCrypt & DoH servers and clients here.

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address 37.59.238.213
  • Hostname recital.c9x.org
  • Location Roubaix, Hauts-de-France, France, EU
  • ISP OVH SAS
  • ASN AS16276

Associated Countries

  • FR FR

Safety Score

Website marked as safe

100%

Blacklist Check

dnscrypt.info was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

DNScrypt-proxy 2 Reviews

More DNS Clients

About the Data: DNScrypt-proxy 2

API

You can access DNScrypt-proxy 2's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/dnscrypt-proxy-2

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share DNScrypt-proxy 2

Help your friends compare DNS Clients, and pick privacy-respecting software and services.
Share DNScrypt-proxy 2 and Awesome Privacy with your network!

View DNS Clients (5)