pkg.sopackage field notes

brew / rank 2441

Install dnscrypt-proxy with Homebrew

Secure communications between a client and a DNS resolver. Version 2.1.18 via Homebrew; verified 2026-07-18.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install dnscrypt-proxy

provider-native install command

overview

Package summary

Secure communications between a client and a DNS resolver

Commands and aliases

  • dnscrypt-proxy

history

Project history and usage

dnscrypt-proxy is the long-running client proxy for encrypted DNS in the DNSCrypt project. It sits between local applications and upstream resolvers, giving package-manager users a daemonized way to use DNSCrypt and related encrypted-DNS transports without changing every application.

Project history

The project grew out of DNSCrypt, a protocol for authenticating communication between DNS clients and resolvers. The DNSCrypt project documents the protocol as a way to protect DNS traffic from spoofing and tampering, and dnscrypt-proxy became the practical client-side program that made that protocol usable on Unix-like systems, Windows, and package-managed desktops.

The modern dnscrypt-proxy repository is written in Go and presents itself as a flexible DNS proxy rather than a single-protocol experiment. Its documentation and repository cover DNSCrypt, DNS-over-HTTPS, relay support, filtering, caching, and service installation, which is why it has remained the default packaged client for users who want encrypted recursive DNS without running a full resolver stack.

Adoption history

dnscrypt-proxy has unusually broad package-manager coverage for a DNS privacy daemon: it appears in Homebrew, Debian and Ubuntu, Fedora/DNF, Arch, Alpine, MacPorts, Nix, Chocolatey, Scoop, Winget, and openSUSE-style packaging. That spread reflects both the cross-platform Go implementation and the recurring sysadmin need for a local encrypted-DNS forwarder.

The project also became part of a wider DNS privacy ecosystem around public resolver lists, DNS stamp configuration, and anonymized DNS relays. Those surrounding lists and conventions matter to adoption because they let packaged clients work from shared resolver metadata rather than hard-coded vendor endpoints.

How it is used

Typical use is to run dnscrypt-proxy as a local service listening on localhost or a LAN address, then point the operating system, dnsmasq, Unbound, or another resolver toward it. The package is popular with users who want encrypted upstream DNS, filtering, cache control, and resolver selection from a single small daemon.

In package-manager culture, dnscrypt-proxy is also the command-line counterpart to GUI DNS privacy settings: it gives power users a text configuration file, service manager integration, and auditable resolver lists.

Why package nerds care

dnscrypt-proxy is significant because it carried DNSCrypt from protocol idea to reinstallable infrastructure component. It is the package people reach for when they want encrypted DNS as a local Unix service rather than as a browser feature.

It also marks the period when DNS privacy packaging stopped being just resolver software and started including local forwarders, public resolver metadata, relay lists, and policy knobs such as filtering and blocklists.

Timeline

  • 2011: DNSCrypt public resolver infrastructure and resolver metadata begin the long-running public-list tradition.
  • 2017: The current Go-based dnscrypt-proxy release line reaches public 2.x releases.
  • 2019: The DNSCrypt project documents anonymized DNSCrypt relays, extending the ecosystem beyond simple client-to-resolver encryption.
  • 2020s: dnscrypt-proxy remains packaged across major Unix, Windows, and macOS package managers as a local encrypted-DNS daemon.

Related projects

  • Related projects include dnscrypt-wrapper on the server side, DNSCrypt resolver-list repositories, dnsmasq and Unbound as local forwarders that can chain to dnscrypt-proxy, and dnsdist for higher-volume DNS traffic management.

security posture

Risk level: orange

broad file, network, media, or database tool signal. formula declares a Homebrew service.

Risk classifier

orange risk · medium confidence · infrastructure

Why

  • broad file, network, media, or database tool signal
  • formula declares a Homebrew service

Signals

  • metadata:service
  • text:client

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
dnscrypt-proxy.toml

executables

Installed executables

CommandKindExposureNote
dnscrypt-proxyexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2.1.18
manager updated2026-07-18
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:dnscrypt-proxy
Version2.1.18
Package managerHomebrew
Homepagehttps://dnscrypt.info
Repositoryhttps://github.com/DNSCrypt/dnscrypt-proxy
Last updated2026-07-18T15:14:20Z
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation