DnsCrypt on Ubuntu – Encrypted DNS Traffic

28/12/2020
DNS

DNSCrypt is an authentication protocol that facilitates the communication between DNS clients and DNS resolvers.  It’s an effective tool to prevent DNS spoofing where traffic is diverted to fake websites by manipulating DNS servers. DNSCrypt uses cryptographic signatures to authenticate traffic sources. So it’s easier to detect any manipulation of incoming information. It’s an open specification with multiple free and open-source implementation. DNSCrypt clients are available for Windows, MacOS, Unix, Android, iOS, and Linux.

Available DNS Resolvers with DNSCrypt Capability

There are a number of public DNS server with support for DNSCrypt protocol. You can also run your own DNS resolver.

You will need a DNSCrypt client to communicate with these servers.

DNSCrypt Clients

One of the most popular clients is dnscrypt-proxy. It has both a command line and a graphical user interface. It’s up-to-date to current DNSCrypt protocol and it is supported on Windows, macOS, Linux, OpenBSD, FreeBSD, NetBSD, Android, and iOS.

There are other clients like Simple DNSCrypt and DNSCrypt-OSXClient.

Benefits of DNSCrypt Clients

The DNSCrypt clients have the following benefits:

  • Reviews traffic integrity in real-time and detects any manipulation.
  • Provides control over rejecting ads, trackers, spam, malware or other harmful sites.
  • Caches responses and avoids IPv6 requests on IPv4-only networks to improve latency.
  • Mandatory TCP use through TCP-only tunnels or Tor
  • Local zone queries are protected

DNSCrypt Client dnscrypt-proxy Installation on Ubuntu

For Ubuntu 14.x, you can use Pascal’s DNSCrypt PPA:

    $ sudo add-apt-repository ppa:anton+/dnscrypt    $ sudo apt-get update    $ sudo apt-get install dnscrypt-proxy    

For Ubuntu 16.x and 17.x, dnscrypt-proxy is part of the Ubuntu repository. So you can directly install using the following command:

    $ sudo apt-get install dnscrypt-proxy    

After installation, add 127.0.0.2 to your DNS servers on your network configuration.

Next, start the dnscrypt-proxy service using the following command:

    $ service dnscrypt-proxy start    

It will create a user called “_dnscrypt-proxy” and run the service as that user. Check the service status using:

    $ service dnscrypt-proxy status    

Verifying Successful Installation

The following link verifies successful installations:

https://www.opendns.com/welcome

A successful installation should show the following page:

Alternatively, you can use the following command line

    $ dig txt debug.opendns.com    

You should get output like:

  $ dig txt debug.opndns.com    ; <<>> DiG 9.10.3-P4-Ubuntu <<>> txt debug.opndns.com  ;; global options: +cmd  ;; Got answer:  ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 41412  ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0    ;; OPT PSEUDOSECTION:  ; EDNS: version: 0, flags:; udp: 4096  ;; QUESTION SECTION:  ;debug.opndns.com.        IN    TXT    ;; ANSWER SECTION:  debug.opendns.com. 0 IN TXT "server 11.ash"  debug.opendns.com. 0 IN TXT "flags 20 0 70 5950800000000000000"  debug.opendns.com. 0 IN TXT "originid 0"  debug.opendns.com. 0 IN TXT "actype 0"  debug.opendns.com. 0 IN TXT "source [REDACTED-YOUR IP]"  debug.opendns.com. 0 IN TXT "dnscrypt enabled (71447764594D3377)"    ;; Query time: 74 msec  ;; SERVER: 127.0.0.2#53(127.0.0.2)  ;; WHEN: Sat Dec 09 11:26:16 UTC 2017  ;; MSG SIZE  rcvd: 249  

Notice the debug.opendns.com. 0 IN TXT “dnscrypt enabled (71447764594D3377)” line. If you have a similar line that means your DNSCrypt protocol is working.

ONET IDC thành lập vào năm 2012, là công ty chuyên nghiệp tại Việt Nam trong lĩnh vực cung cấp dịch vụ Hosting, VPS, máy chủ vật lý, dịch vụ Firewall Anti DDoS, SSL… Với 10 năm xây dựng và phát triển, ứng dụng nhiều công nghệ hiện đại, ONET IDC đã giúp hàng ngàn khách hàng tin tưởng lựa chọn, mang lại sự ổn định tuyệt đối cho website của khách hàng để thúc đẩy việc kinh doanh đạt được hiệu quả và thành công.
Bài viết liên quan

How to Install and Use DIG on Debian 9

The full form of DIG is Domain Information Groper. It is a command line utility for network administrators.The domain name...
29/12/2020

How to Configure dnsmasq on CentOS 7

dnsmasq is a very lightweight and simple DNS server. dnsmasq can be configured to be a DNS server and a DHCP server. In...
29/12/2020

How to use Nslookup in Debian

Nslookup or name server lookup is a tool used by network administrators to find the hostname, IP address or other DNS records...
29/12/2020
Bài Viết

Bài Viết Mới Cập Nhật

Mua proxy v4 chạy socks5 để chơi game an toàn, tốc độ cao ở đâu?
18/05/2024

Thuê mua proxy Telegram trọn gói, tốc độ cao, giá siêu hời
18/05/2024

Thuê mua proxy Viettel ở đâu uy tín, chất lượng và giá tốt? 
14/05/2024

Dịch vụ thuê mua proxy US UK uy tín, chất lượng số #1
13/05/2024

Thuê mua proxy Việt Nam: Báo giá & các thông tin MỚI NHẤT
13/05/2024