Listing Thumbnail

    dnscrypt-proxy - Encrypted DNS Proxy - AMI by cloudimg

     Info
    Sold by: cloudimg 
    Deployed on AWS
    Free Trial
    AWS Free Tier
    This product has charges associated with it for seller support. dnscrypt-proxy, the flexible encrypting DNS proxy, preinstalled and running as a hardened systemd service within minutes of launch. It accepts ordinary DNS on port 53 and forwards every query to public upstreams over encrypted transports (DNSCrypt v2 and DNS over HTTPS), choosing DNSSEC validating, no log, non filtering resolvers automatically. Secure by default with no shared credentials. Backed by 24/7 cloudimg expert support.

    Overview

    Open image

    This is a repackaged open source software product wherein additional charges apply for cloudimg support services.

    dnscrypt-proxy is a flexible DNS proxy that encrypts your DNS traffic. It sits between your clients and the public internet, accepting ordinary DNS queries on port 53 and forwarding every one of them to a public upstream resolver over an encrypted transport, so your internet provider and any network between you and the resolver can no longer see or tamper with the names you look up. It supports the modern encrypted DNS protocols including DNSCrypt v2, DNS over HTTPS, Anonymized DNSCrypt and Oblivious DoH. This image delivers dnscrypt-proxy fully installed and configured as a hardened systemd service, so an encrypted resolver for your whole network is answering queries within minutes of launch.

    dnscrypt-proxy is a single self contained binary whose behaviour is defined by one plain text configuration file. There is no database and no web console. On this image it listens for DNS on port 53 over both UDP and TCP across all interfaces, and forwards to upstreams selected automatically from a cryptographically signed public resolver list by lowest latency. Upstream selection is restricted to resolvers that validate DNSSEC, keep no logs, and apply no filtering, so you get authentic, private, unfiltered answers.

    Application stack: dnscrypt-proxy runs as a dedicated non root service with only the Linux CAP_NET_BIND_SERVICE capability so it can bind the privileged DNS port. The operating system stub resolver listener is disabled so dnscrypt-proxy owns port 53 cleanly, while the operating system keeps resolving names through its own upstream list. The proxy resolves the hostnames of its encrypted upstreams and refreshes the signed resolver list through its built in bootstrap resolvers, so it never depends on the host resolver.

    Secure by default: this image ships with no shared or default credentials of any kind, since dnscrypt-proxy has no login. It binds all interfaces so it can serve a network, but access to port 53 is governed entirely by the security group. Because dnscrypt-proxy has no built in allow from access control list, the security group is your access control: open UDP and TCP 53 only to the client subnets you control, never to the whole internet, so the resolver is never abused as an open resolver.

    Key capabilities: transparent encrypted DNS for every client that points at this resolver; automatic selection of DNSSEC validating, no log, non filtering encrypted upstreams; support for DNSCrypt v2, DNS over HTTPS, Anonymized DNSCrypt and Oblivious DoH; optional local blocklists, allow lists, cloaking and forwarding rules shipped as ready to edit example files; and a single binary with no runtime dependencies.

    Get started: point your clients, or your virtual network DNS setting, at this instance on port 53, and restrict the security group to your own subnets. cloudimg engineers can help with upstream selection, per client access policy, blocklists and forwarding rules, and monitoring after purchase.

    All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.

    Highlights

    • dnscrypt-proxy, the flexible encrypting DNS proxy, fully installed as a hardened systemd service. It accepts plain DNS on port 53 over UDP and TCP and forwards every query to public upstreams over encrypted transports including DNSCrypt v2, DNS over HTTPS, Anonymized DNSCrypt and Oblivious DoH, so on path networks cannot see or tamper with your lookups.
    • Secure by default: upstream selection is restricted to DNSSEC validating, no log and non filtering encrypted resolvers, chosen automatically from a cryptographically signed public resolver list. No shared or default credentials ship, since dnscrypt-proxy has no login. It binds all interfaces to serve a network, while the security group governs access to port 53 until you open it to your own client subnets.
    • 24/7 expert technical support from cloudimg with a one hour average response time for critical issues. Our engineers help with upstream and protocol selection, per client access policy through the security group, DNSSEC and no log requirements, local blocklists, allow lists, cloaking and forwarding rules, and dnscrypt-proxy version upgrades.

    Details

    Sold by

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 7 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    dnscrypt-proxy - Encrypted DNS Proxy - AMI by cloudimg

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (800)

     Info
    • ...
    Dimension
    Description
    Cost/hour
    m5.large
    Recommended
    m5.large
    $0.08
    t2.micro
    t2.micro instance type
    $0.04
    t3.micro
    t3.micro instance type
    $0.04
    c7i.48xlarge
    c7i.48xlarge instance type
    $0.24
    m7a.4xlarge
    m7a.4xlarge instance type
    $0.24
    i3en.large
    i3en.large instance type
    $0.08
    c6i.16xlarge
    c6i.16xlarge instance type
    $0.24
    vt1.24xlarge
    vt1.24xlarge instance type
    $0.24
    r7iz.16xlarge
    r7iz.16xlarge instance type
    $0.24
    c8id.32xlarge
    c8id.32xlarge instance type
    $0.24

    Vendor refund policy

    Refunds available on request.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Initial release of dnscrypt-proxy 2.1.18 as a ready to use encrypted DNS proxy: a hardened systemd service listening on port 53 over UDP and TCP, forwarding every query to DNSSEC validating, no log, non filtering public upstreams over encrypted transports (DNSCrypt v2, DNS over HTTPS, Anonymized DNSCrypt, Oblivious DoH), with no baked credentials.

    Additional details

    Usage instructions

    Connect via SSH on port 22 as the default login user for your operating system variant (for the Ubuntu 24.04 variant the user is ubuntu). dnscrypt-proxy starts automatically at boot as a systemd service listening on 0.0.0.0:53 over UDP and TCP; confirm it with 'systemctl status dnscrypt-proxy' and test a lookup with 'dig @127.0.0.1 example.com'. dnscrypt-proxy has no login or password and this image ships no baked credentials. Its entire behaviour is the single TOML file at /etc/dnscrypt-proxy/dnscrypt-proxy.toml; edit it then run 'sudo systemctl reload dnscrypt-proxy'. To serve clients, point them (or your VPC DNS setting) at this instance on port 53, and IMPORTANT: dnscrypt-proxy has no built in allow from access control, so the security group is your access control. Open UDP and TCP 53 only to the client subnets you control, never to 0.0.0.0/0, or the instance becomes an open resolver. Full guide: https://www.cloudimg.co.uk/guides/dnscrypt-proxy-aws/ 

    Resources

    Vendor resources

    Support

    Vendor support

    cloudimg provides 24/7 technical support for this product by email and live chat. Our engineers help with deployment, configuration, updates, performance tuning and troubleshooting; critical issues receive a one hour average response. Contact support@cloudimg.co.uk .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.