Hardened dnscrypt-proxy module for Android.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
quindecim 75b4a2216e
[up] Update to `2.1.1-3`
17 hours ago
.github/ISSUE_TEMPLATE Fix formatting in bug_report.md file 5 months ago
META-INF/com/google/android [UPSTREAM] - Require Magisk v20.4+ 2 years ago
binary [UPSTREAM] - Update binary files to 2.1.1 9 months ago
config [toml] More optimizations on relays 3 days ago
.gitattributes initial release 4 years ago
CHANGELOG.md [up] Update to `2.1.1-3` 17 hours ago
LICENSE.md [UPDATE] - 2022 6 months ago
README.md [docs] Update `plan9` resolvers 3 days ago
customize.sh [up] Update to `2.1.1-3` 17 hours ago
module.prop [up] Update to `2.1.1-3` 17 hours ago
post-fs-data.sh [UPDATE] - Remove unused spaces 1 year ago
service.sh [CONFIG] - Use the emulated path for the config. files 1 year ago
uninstall.sh [CONFIG] Loops the command until the boot is complete and add more path variants to removal 5 months ago
update.json [up] Update to `2.1.1-3` 17 hours ago

README.md

DNSCrypt Proxy 2 for Android

GitHub release (latest by date) GitHub all releases

A flexible DNS proxy, with support for modern encrypted DNS protocols such as DNSCrypt v2, DNS-over-HTTPS, Anonymized DNSCrypt and ODoH (Oblivious DoH).

Features

Pre-built binaries

Up-to-date, pre-built binaries are available for:

  • Android/arm
  • Android/arm64
  • Android/x86
  • Android/x86_64

All the binary files are downloaded from the official release page.

Differences from the main project

  • server_names = acsacsar-ams-ipv4 [NLD], altername [RUS], ams-dnscrypt-nl [NLD], d0wn-tz-ns1 [TZA], dns.watch [DEU], dnscrypt.be [BEL], dnscrypt.ca-1 [CAN], dnscrypt.ca-2 [CAN], dnscrypt.eu-nl [NLD], dnscrypt.pl [POL], dnscrypt.uk-ipv4 [GBR], dnswarden-asia-uncensor-dcv4 [SGP], dnswarden-eu-uncensor-dcv4 [DEU], dnswarden-us-uncensor-dcv4 [USA], meganerd [NLD], moulticast-fr-ipv4 [FRA], moulticast-sg-ipv4 [SGP], moulticast-uk-ipv4 [GBR], plan9dns-fl [USA], plan9dns-mx [MEX], plan9dns-nj [USA], pryv8boi [DEU], pwoss.org-dnscrypt [DEU], resolver4.dns.openinternet.io [USA], scaleway-ams [NLD], scaleway-fr [FRA], serbica [NLD], techsaviours.org-dnscrypt [DEU], v.dnscrypt.uk-ipv4 [GBR] are the resolvers in use.

  • doh_servers = false (disable servers implementing the DNS-over-HTTPS protocol)

  • require_dnssec = true (server must support DNSSEC security extension)

  • force_tcp = true (fix for mobile data intial connection random issues if routes have been set and skip_incompatible = true, see DNSCrypt/dnscrypt-proxy/discussions/2020)

  • timeout = 1000 (set the max. response time of a single DNS query from 5000 to 1000 ms.)

  • blocked_query_response = 'refused' (set refused response to blocked queries)

  • # log_level = 0 (set the log level of the dnscrypt-proxy.log file to very verbose, but keep it disabled by default)

  • dnscrypt_ephemeral_keys = true (create a new, unique key for every single DNS query)

  • bootstrap_resolvers = ['91.239.100.100:53', '89.233.43.71:53'] (use UncensoredDNS (Anycast & Unicast) instead CloudFlare)

  • netprobe_address = '91.239.100.100:53' (use UncensoredDNS (Anycast) instead CloudFlare)

  • block_ipv6 = true (immediately respond to IPv6-related queries with an empty response)

  • blocked-names.txt, blocked-ips.txt, allowed-names.txt and allowed-ips.txt files enabled. (to know more specifics about this, please refer to the Filters (optional) section below)

  • anonymized_dns feature enabled. (routes are indirect ways to reach DNSCrypt servers, each resolver has 2 relays assigned)

  • skip_incompatible = true (skip resolvers incompatible with anonymization instead of using them directly)

  • direct_cert_fallback = false (prevent direct connections through the resolvers for failed certificate retrieved via relay)

Installation

1. Download the latest dnscrypt-proxy-android-*.zip file from the Releases page and flash it with Magisk:

Magisk > Modules > Install from storage > dnscrypt-proxy-android-*.zip

2. Reboot your device.

3. Test your DNS at https://dnsleaktest.com/

Configuration (optional)

You can edit the dnscrypt-proxy.toml file as you wish located on storage/emulated/0/dnscrypt-proxy path.

For a more detailed configuration you can refer to the official documentation or simply join our group on Telegram, at dnscrypt-proxy-android | CHAT.

Filters (optional)

Filters are a powerful set of built-in features, that let you control exactly what domain names and IP addresses your device are allowed to connect to. This can be used to block ads, trackers, malware, or anything you don't want your device to load.

This module comes with the filtering feature enabled by default, that's why you can see files designed for this operation inside the internal folder. Out of the box these files are empty and are used only to ensure the correct start of dnscrypt-proxy service.
To know more about it you can consult the official documentation, or in a simpler way through my block repository.

I'm also providing the allowed-names.txt and blocked-names.txt files regularly updated at dnscrypt-proxy-filters | CHANNEL. The sources used for this merge are among the hardest on the web.

You can contribute to this blocklist at anytime, opening a New Issue here or simply reporting the issue at dnscrypt-proxy-filters | CHAT on Telegram.

Changelog

Version numbers

dnscrypt-proxy-android version numbers consist of 4 parts: MAJOR.MINOR.BUILD-PATCH.

MAJOR, MINOR and BUILD will be updated according to the main project, these values will always be in sync with it. PATCH is an optional value that will be set on my side when I release a build before the original project.

Donations

  • BTC address: 126Y2BJQyPq8CHAaFMCyVH5QcbSViQz89e
  • ETH address: 0x16b917Bb585D2411b9c9C81b03de72471f3f072F
  • XMR address: 41jXybL88etPg1nGuPsMZbFSzKzbXYat4Xak3QssPy7LNs4VBWXDxbhjSdtLJDA138cx7cTq8JhFoiTTVLhWrTNAUywgGFD

Credits