# DNSCrypt/dnscrypt-proxy

dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols.

Repository: https://github.com/DNSCrypt/dnscrypt-proxy
Canonical: https://ross.abutalabs.com/products/dnscrypt-proxy
Homepage: https://dnscrypt.info
Language: Go
License: ISC
License Family: permissive
Topics: dnscrypt, dnscrypt-proxy2, doh, dnscrypt-proxy, dns-over-https, dns, proxy, odoh, oblivious-doh, anonymized, anonymized-dns, oblivious-dns-over-https
Last push: 2026-08-25T03:52:52+00:00

## Health v2 (maintenance only)
Score: 93/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 81, longevity 100
- inputs: {"age_days": 3159, "days_push": 8, "days_rel": 46, "gap_med": 50, "n_releases_24m": 12}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 13600, forks 1128 (observed 2026-08-28T04:11:03.618019+00:00)

## What it is
dnscrypt-proxy is a flexible local DNS proxy that encrypts and authenticates DNS traffic using DNSCrypt v2, DNS-over-HTTPS, Anonymized DNS, and Oblivious DoH. It also provides DNS caching, load balancing across resolvers, ad/malware filtering, and client IP anonymization via relays, Tor, or SOCKS proxies.

## Use cases
- encrypt my DNS traffic to prevent ISP snooping
- block ads and malware at the DNS level
- hide my IP address from DNS resolvers
- set up DNS-over-HTTPS locally on my router
- bypass DNS spoofing and censorship
- load balance across multiple fast DNS resolvers
- force safe search on Google and Bing for my family

## When to choose
- you want encrypted, authenticated DNS with no plaintext bootstrap and no CA dependency
- you need anonymized DNS relays or ODoH to hide client IPs from resolvers
- you want a single local proxy combining encryption, caching, filtering, and load balancing
- you need censorship-resistant DNS with no SNI or fixed port signatures

## When to avoid
- you just need a simple recursive DNS server rather than a forwarding proxy
- you want a GUI-managed DNS solution with a web dashboard
- you need full DNSSEC validation as your primary requirement

## Facets
- artifact type: service
- maturity: stable
- function: proxy, caching, security, privacy, networking
- domain: security, privacy, networking, self-hosted, censorship-circumvention
- platform: windows, bsd, cross-platform, go, cli, self-hosted
- tags: dns, dnscrypt, dns-over-https, doh, odoh, anonymized-dns, dns-encryption, ad-blocking, dns-filtering, censorship-resistance, linux, macos, android, ios

## Member repositories
- DNSCrypt/dnscrypt-proxy (main) score 93

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:03.618019+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:13:10.308534+00:00, confidence not recorded.
  - readme: https://github.com/DNSCrypt/dnscrypt-proxy (fetched 2026-08-28T04:11:03.618019+00:00, sha 048ec20076f5)
  - homepage: https://dnscrypt.info (fetched 2026-08-29T08:09:12.367169+00:00, sha d800408a81e3)
  - site_page: https://dnscrypt.info/faq (fetched 2026-08-29T08:09:12.376050+00:00, sha 7d12db0bfc1d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
