Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Frank Denis edited this page Jul 18, 2026 · 80 revisions

Installation

How do I install DNSCrypt?

You can't. Because DNSCrypt is just a specification.

However, that specification has been implemented in software such as unbound, dnsdist, dnscrypt-wrapper, Simple DNSCrypt and dnscrypt-proxy.

dnscrypt-proxy is a flexible DNS proxy. It runs on your computer or router, and can locally block unwanted content, reveal where your devices are silently sending data to, make applications feel faster by caching DNS responses, and improve security and confidentiality by communicating to upstream DNS servers over secure channels.

OS-specific instructions

Graphical front-ends

  • Simple DNSCrypt is a simple management tool to configure dnscrypt-proxy on Windows-based systems.
  • AdGuard Pro for iOS, Android, macOS and Windows embeds dnscrypt-proxy in a slick user interface.
  • dnscrypt-proxy switcher is a plugin for Bitbar on macOS, to control dnscrypt-proxy usage from the menu bar.

Not-graphical front-ends

Setting up dnscrypt-proxy (general guidelines)

  1. Extract and adjust the configuration file dnscrypt-proxy.toml to your needs. In case you started fresh, ensure you back up your modified dnscrypt-proxy.toml file.

Note: You can choose a set of preferred servers in the dnscrypt-proxy.toml file.

Look for:

# server_names = ['scaleway-fr', 'google', 'yandex']

Change to the servers you would like to use and remove the leading #.

Example:

server_names = ['google', 'cloudflare']

When doing this, filters are ignored if you explicitly name the set of resolvers to use ['google', 'cloudflare'].

Filters are used when the list is empty, which means all resolvers from configured sources, matching the filters.

  1. Make sure that nothing else is already listening to port 53 on your system and run (in a console with elevated privileges on Windows) the dnscrypt-proxy application.

Change your DNS settings to the configured IP address and check that everything works as expected.

./dnscrypt-proxy -resolve example.com

should return one of the chosen DNS servers instead of your ISP's resolver.

  1. Register as a system service.

Verification of downloaded files

Pre-compiled binaries can be verified with Minisign:

(warning: long line, that may require horizontal scrolling if you use a large font. Make sure to copy the whole of it; the last characters are jB5)

minisign -Vm dnscrypt-proxy-*.tar.gz -P RWTk1xXqcTODeYttYMCMLo0YJHaFEHn7a3akqHlb/7QvIQXHVPxKbjB5

On Windows, archives are ZIP files, not .tar.gz files, so use dnscrypt-proxy-*.zip in the command above.

The public key can also be obtained using a (DNSSEC-signed) DNS query:

dig txt dnscrypt-proxy.key.dnscrypt.info.

Storing the application and its configuration in different directories

This approach is feasible. However, the developers chose to keep them together for simplicity.

If you do decide to store them separately, you must specify the configuration file using an absolute path with the -config option when running any command that requires the configuration file but is not located in the current directory.

The subordinate files (such as allow/block lists, source/log files, and so on) use relative paths based on the location of the dnscrypt-proxy.toml file.

Upgrading

Assuming that the official package from this repository was installed, here's how to upgrade to a new version:

  1. Check the change log for configuration files that need to be updated. When in doubt, start over from the example configuration files.
  2. Check that the new version can properly load the old configuration files: /path/to/new/dnscrypt-proxy -config /path/to/old/dnscrypt-proxy.toml -check (it shouldn't print any error)
  3. Replace the old dnscrypt-proxy file with the new one.
  4. Restart the service.

Clone this wiki locally