dnscry.pt - Road to 100 resolvers
➜ ~ whois dnscry.pt
Domain: dnscry.pt
Domain Status: Registered
Creation Date: 10/01/2023 10:26:12
It's been almost two years since I started the project with about 30 resolvers taken from my collection of idlers. And while I still love idling servers, it felt good to have them do something useful. But what is this all about?
The dnscry.pt project is a personal initiative by a developer known as @brueggus. It focuses on enhancing DNS security and privacy through the use of the DNSCrypt protocol. Here are some key points about the project:
- DNSCrypt Protocol: This protocol authenticates and encrypts DNS requests between clients and resolvers, preventing third parties (like ISPs) from spying on or tampering with your DNS queries.
- Public Resolvers: The project operates public DNSCrypt, DNS over HTTPS (DoH), and DNS over TLS (DoT) resolvers in various locations worldwide. These resolvers are uncensored, unfiltered, encrypted, and support DNSSEC.
- No Logging: The project ensures privacy by not storing any query logs.
- Accessibility: The resolvers can be used with any client implementing the DNSCrypt protocol, with dnscrypt-proxy being a recommended option.
If you’re interested in securing your DNS traffic, dnscry.pt offers a robust solution. Would you like to know more about how to set it up?
Thanks, Microsoft Copilot. While I wouldn't consider myself a developer, the rest is pretty accurate.
Since then, the project has been growing steadily and while I started it to promote the DNSCrypt protocol, which I still prefer over DoT/DoH, I eventually decided to support these two protocols as well on popular demand. My resolvers have been added to the official DNSCrypt resolver list and I am aware of a handful of open source projects which use my resolvers to circumvent censorship in countries which don't have the privilege of free internet access.
If you haven't looked into switching to an encrypted protocol to prevent your ISP, employer, Google or Cloudflare from analyzing or even tampering with your DNS traffic, I encourage you to do so. Chances are good that there's a dnscry.pt resolver near you.
This wouldn't have been possible without the help of generous providers sponsoring the project. Most of them are active here as well – show them some love, please!
At the moment, I am running 88 resolvers around the globe. 12 to go to reach my next milestone of 100 resolvers worldwide.
I'm particularly interested in expanding in Africa and South America and am still looking into providing a proper solution for Chinese users. But what would you be interested in? Any particular location in mind? Features you are missing? Let me know!
Hey Copilot, tell me a joke about DNSCrypt.
Sure, here’s a lighthearted one for you:
Why did the DNSCrypt protocol go to therapy?
Because it had too many unresolved queries! 😄
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/

Comments
Unfortunately I don't have anything meaningful to contribute at the moment, but I just wanted to say thank you to you and your sponsors for running these resolvers and allowing people to use them for free through dnscry.pt!
I noticed your post back when you started this project, and I was interested in keeping an eye on your progress. I've noticed, over the last few months, that my own Pi-Hole has started using some of your resolvers occasionally through DNSCrypt. It's awesome that dnscry.pt's resolvers were added to the official DNSCrypt resolver list.
Thanks again, it's all very much appreciated, and keep up the great work!
(P.S. - If you have stickers left or plan on having more made, I would love some!)
@Brueggus I see you dont have Redditch, UK location. Lets add that?
Will do Brisbane in future
https://www.kuroit.com - Managed cPanel Hosting & VPS Hosting in UK
What pain points do you see for users from China?
DM us for private tracker invite.
Sent you a PM. Thanks
The RTT and/or packet loss, for sure. None of the resolvers has "China-optimized bandwith" and from what I've been able to check using public looking glasses, this makes a huge difference. But services with direct links to Chinese ISPs are outside my comfort zone price-wise.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
@brueggus
Happy to be part of your project, when I saw the map, I was like:
Keep up the nice work! and congratulations.
As we will expand our operations, I will DM you for further additions to the location list.
Host-C | Storage by Design | AS211462
“If it can’t guarantee behavior under load, it doesn’t belong in production.”
Thank you a lot for your feedback! Having the resolvers added to the official list has definitely boosted the visibility of the project. Someone even created a script to sync the dnscry.pt resolvers with the official repo which I am very thankful for.
And sure thing - I still have some stickers left as well as some new merch. Just shoot me a message with your address and I'll get them shipped next week.
Thanks for your support
It means a lot to me. As said before, growing the project to its current extend wouldn't have been possible without providers like you backing it up.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
All valid pain points
Do you want to try https://hk.skywolf.cloud/store/sjc-vps?language=english? I have been following them on telegram and they seem to be a pretty solid provider.
DM us for private tracker invite.
also the possible that blocked by gfw(try not use default path like /dns-query ,gfw have active scan)
I think it makes public DNSCrypt useless and changing URI to something else won't help much but defer block for a bit.
Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden
@Brueggus can I put my weed in it?
The Yeti has left the building.
Sure.
("weed" appears to be on the list of naughty words, so I had to replace them with dandelions.)
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
You bad boy you, breaking all the rules
The Yeti has left the building.
Sniffing dandelions
Host-C | Storage by Design | AS211462
“If it can’t guarantee behavior under load, it doesn’t belong in production.”
i mean DoH
Send me an email to [email protected]. I'm considering supporting this project with a vm in vienna and one in amsterdam.
Anyway, my point is that dnscry.pt runs a public service that publishes the list of DNSCrypt/DoT/DoH servers, making it not useful for circumventing censorship due to service design. Also, maintenance of censorship-resistant public service, like Tor Bridges or anything similar is pretty time-consuming and expensive task.
Given all of that, I see no sense in attempting changing some connection parameters as they will be inevitably leaked to censorship operators due to publicity.
Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden
It's been about two years since I came up with the wet idea to turn my idlers into something useful for the public. Today, I am running 106 resolvers worldwide. Oopsie.
This wouldn't have been possible without the generosity of the sponsors of this project, of course. Most of them are active members of the LowEnd community.
I'd like to celebrate this by giving away two of these brand new dnscry.pt mugs:
ChatGPT and I have created a small CTF challenge which can be found at https://raffle.dnscry.pt/
More information on how to participate can be found here.
If you don't live in the EU or rather spend your time on smashing F5 in the Christmas thread, I still have few dnscry.pt stickers in stock. Just shoot me a PM - I ship these worldwide.
Good luck and Merry Christmas!
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
Merry Christmas @Brueggus!!! Thank You for all the hard work!!!
The Yeti has left the building.
Where can I buy that mug?
This was really fun! Unfortunately I'm not in the EU
You mean, you already cracked it? I had a look at the page, but have no idea where to start!
Click around.
Common thing about CTF challenges is that stuff is hidden in "plain sight". Look a bit deeper into things that might seem normal (but probably isn't). Everything you need is contained within
raffle.dnscry.ptone way or another.Website: thomassen.sh
I had 'participate in a CTF' somewhere on the vague to-do list in the back of my mind, so I couldn't let this opportunity slip.
With your hint I had a new look at the html, CSS and other files downloaded, and did get some further. Thanks!
Not to spoil the fun I won't go through my few steps or publicly ask for hints on the specific step where I got stuck. I won't be able to solve this without more help, so I hereby disqualify myself ;-)
What I actually find interesting is that you seem to be using mxroute, but with IPv6 - I didn't think mxroute had IPv6 support?
Great work with this.
Changed do dnscry.pt on all my PiHoles and worked superb and have a good latency to one of the Stockholm servers.
Keep up the good work
They don't (officially) support it, but I noticed that the server I am on had IPv6 enabled and working, so I'm using it. It works only for incoming mail, outgoing mails go through IPv4 relays.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
Wohoo! That was fun indeed. Thanks Decicus for the help!
Good job!
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
One of the Stockholm server is ours, may I know if it is the best for you? 👀
Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden
fyi, i recommend absolutehosting for Johannesburg
@skhron STO2 so the one sponsored by you guys.
3MS to STO2 vs 8MS to STO1
STO2 is actually in Stockholm, STO1 is in Hudiksvall, just wrongly named, so that would explain the latency difference.
Yes and no, ISP peering factor a lot.
That considering that Hetzner in Finland Tuusula ( or how its spelled ) is close 3rd with around 10MS even though the distance is greater.
@Brueggus you could send at least one mug to each of the sponsors for Christmas
No, he can’t. Dude rents 300+ servers from his own pocket.
I've just updated the location on the resolver list on the website. This bugs me since you (I think?) made me aware of it. But I am hesitant to change it in the backend, because then its hostname would change as well as its id on the lists for
dnscrypt-proxyand company, which would be a breaking change for those who use that resolver.The issue with the mugs is that I would need to send them as parcel and international shipping is crazy expensive in Germany. A parcel to another EU country costs around EUR 15, to a non-EU country twice as much.
I got three of these mugs for 10 bucks (Christmas promo), so shipping fees would be 5-10 times as much as the mug is worth. Doesn't make any sense to me.
And, most important, I don't want the people who donate their money to the project to help with covering the server cost see me burning it for mugs and shipping.
I get the point and I agree - it would be nice to give something back to the sponsors on Christmas. But I need to figure out a way so that I don't make a loss.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
Yeah, I also mentioned the ITDLC one, but I get your point, just wanted to clarify it to the guy. Totally okay for me to keep it that way
Ummm soo, 15 eur is a loss for you, but sponsoring services that you get are not a loss for sponsoring ISPs? Okay then I as sponsor , I agree to pay shipping then, i am waiting one of the mugs.
He's trying to be a good financial steward with project donations. I see this as a Good Thing (tm).
I appreciate each and every sponsor, no matter if they sponsor a single or a dozen locations for the project. Therefore, every sponsor deserves a mug. But: If a US company sponsors a single location and I ship a mug to the US to show my appreciation, I am making a loss. I would have been cheaper for me if I paid for the service. That's the point I wanted to make.
Even with the sponsors, dnscry.pt is operating at a loss financially - which shouldn't be surprising. I spend about 300,- Euro every month from my pocket to keep things running. And I am happy to do it as long as I can afford it, because I feel like I'm doing something useful for the internet community (and I can satisfy my craving for having tons of VPS in different locations).
There's no surplus I could spend on shenanigans. And I wouldn't have ordered any mugs at all if it wasn't the Christmas promo where I got three for the price of one.
There are around 25 companies and people sponsoring the project at the moment. If I spend 20,- EUR for mug + shipping on average, this would be 400,- Euro in total. My apologies to anyone who would enjoy gazing at the dnscry.pt logo while drinking their morning coffee, but I (as an individual) have better use for that amount of money in the pre-Christmas season than shipping mugs around the world.
@Hosteroid I appreciate your contribution to my project and I understand that you would appreciate a mug. So I'll make that happen. May I use the address in the footer of your website for shipping?
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
@Brueggus , may be that's a suggestion that you need to sell some merch ?
No luck for me...
And it would have been so nice next to my PowerDNS mug:
Looks like there's a real demand for the mugs
I'll try to figure out if I can produce and ship them cheaper somehow.
Oh, and there's still a small chance that one of the winners doesn't claim their prize. I'll do a re-roll in that case.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
This is a very cool service and I greatly appreciate OP spending the time and effort to build and maintain it. Previously I was using Quad9 given they support DNSCrypt and are one of the few who can give me low latency, but for something as critical as DNS, they really aren't that reliable. I had a mysterious middle of the night multi-hour outage and I stupidly didn't put in any alternative resolvers as I trusted them to be competent at their one job.
After that I found dnscry.pt when looking for usable alternatives, and it was really the only service that ticked all the boxes for me: DNSSEC, no net-nanny bullshit, and usable latency. I kept Quad9 in the list for some time, but after they blocked a legitimate domain I wished to visit while giving no means to opt-out and keep DNSSEC, I decided "fuck it" and threw caution to the wind by sending all my DNS traffic through dnscry.pt.
All this happened about 6 months ago now and it's been smooth sailing since. I'm a little bummed to see Adelaide bit the dust though. Would you be interested in setting up a node in Perth on BinaryLane? I can donate a VM.
I am in for a MUG if you finger it out!!!!
The Yeti has left the building.
Vistaprint etc could be produced easily may be it would be cost effective to give the image of the logo in high quality PNG and just anyone interested in the mug could send it to be produced locally. Example for Spain. The production is like 5 euros+ shipping total 9 euros or so. If you produce them in Germany or any another country just the shipping them take more time and it is more expensive . Causes more CO2 not good for the climate neither the wallet. So just provide the image and if there are interest people would print them locally. Just my 2cents
I believe in good luck. Harder that I work ,luckier i get.
Sometimes such events happens due to routing issues, not necessarily it is the server operator to blame. Having an alternate/backup is a must IMO.
Check our KVM VPS plans in 🇵🇱 Warsaw, Poland and 🇸🇪 Stockholm, Sweden
Got something in the mail yesterday, decided to put it on the back of my Steam Deck (well, on the case I have for it anyway). Thanks @Brueggus!
Website: thomassen.sh
Nice, good to see that they arrived safely!
I've packaged the mugs for the winners of the CTF today and will ship them tomorrow. Hopefully the post office treats them as careful as your stickers...
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/