Skip to content

Connecting to a remote dnscrypt proxy client from Android Pie using DNS over TLS

Frank Denis edited this page Sep 28, 2026 · 2 revisions

Since Android Pie supports configurable DNS-over-TLS, it is very easy to redirect DNS queries from a smartphone to your own server running dnscrypt-proxy (with your own blocklists, allowlists, time blocks, ad blocking, etc.). No additional app is required.

You will need:

  • a server with dnscrypt-proxy, of course
  • nginx with stream modules (built with --with-stream and --with-stream_ssl_module options)
  • an open port 853

Just add this snippet to nginx.conf:

stream {
    upstream dns-servers {
        server    127.0.0.1:53;
    }

    server {
        listen 853 ssl;
        proxy_pass dns-servers;

        ssl_certificate            /etc/nginx/ssl/dot-server.crt;
        ssl_certificate_key        /etc/nginx/ssl/dot-server.key;

        ssl_protocols        TLSv1.2;
        ssl_ciphers          HIGH:!aNULL:!MD5;
        
        ssl_handshake_timeout    10s;
        ssl_session_cache        shared:SSL:20m;
        ssl_session_timeout      4h;
    }
}

Restart nginx.

In Android Pie, go to Settings--Network--Advanced--Private DNS and add the name of your server. This setting will persist for Wi-Fi and mobile connections.

Clone this wiki locally