With interesting new ephemeral keying option: https://github.com/jedisct1/dnscrypt-proxy/releases More info about it: "DNSCrypt is about authentication, not secrecy. If you are using it for privacy, it might do the opposite of what you are trying to achieve. It verifies that responses you get from a DNS provider have been actually sent by that provider. But providers receive queries that include your public key, and can use it to track you even if your public IP changes. Version 1.5.0 introduces ephemeral keys in order to mitigate that."