Ross ROSS = Recommend OSS · open-source software intelligence for agents

getdnsapi/stubby

Stubby is the name given to a mode of using getdns which enables it to act as a local DNS Privacy stub resolver (using DNS-over-TLS). observed · 2026-08-28

github.com/getdnsapi/stubby · homepage · C · BSD-3-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

37/100

  • Activity 31
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3355
  • days_rel: n/a
  • days_push: 414
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1314 stars · 104 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Stubby is a local DNS Privacy stub resolver daemon that encrypts DNS queries using DNS-over-TLS (RFC 7858), built on the getdns library. It listens on loopback and forwards outgoing DNS queries over authenticated TLS connections to privacy-respecting resolvers.

Use cases

  • encrypt DNS queries with DNS-over-TLS on my laptop
  • hide DNS traffic from network observers
  • run a local stub resolver daemon on Linux
  • use DNS privacy resolvers like Cloudflare or Quad9 with strict authentication
  • set up encrypted DNS on macOS or Windows
  • protect DNS queries on public Wi-Fi

When to choose

  • you want a lightweight, dedicated DNS-over-TLS stub resolver for a desktop or laptop
  • you need strict privacy mode with authenticated upstream resolvers
  • you are comfortable editing YAML configuration and changing system DNS settings
  • you want a cross-platform (Linux/macOS/Windows) daemon maintained by the getdns team

When to avoid

  • you need DNS-over-HTTPS support, which is not yet available
  • you want a fully user-friendly GUI experience (GUIs are alpha/experimental)
  • you need a full recursive or caching resolver rather than a stub resolver
  • you prefer DNSCrypt protocol instead of DNS-over-TLS

Facets

application · maturity active

security privacy networking cli proxy privacy networking security self-hosted windows cross-platform cli dns dns-over-tls stub-resolver dns-privacy daemon getdns c command-line linux macos

10 sources

Member repositories

RepositoryRoleHealth v2
getdnsapi/stubbymain37

For agents

markdown · JSON · MCP: product_card(name="getdnsapi/stubby")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem