Repository navigation
Connecting to a remote dnscrypt proxy client from Android Pie using DNS over TLS
Frank Denis edited this page Sep 28, 2026
·
2 revisions
Since Android Pie supports configurable DNS-over-TLS, it is very easy to redirect DNS queries from a smartphone to your own server running dnscrypt-proxy (with your own blocklists, allowlists, time blocks, ad blocking, etc.). No additional app is required.
You will need:
- a server with dnscrypt-proxy, of course
- nginx with stream modules (built with --with-stream and --with-stream_ssl_module options)
- an open port 853
Just add this snippet to nginx.conf:
stream {
upstream dns-servers {
server 127.0.0.1:53;
}
server {
listen 853 ssl;
proxy_pass dns-servers;
ssl_certificate /etc/nginx/ssl/dot-server.crt;
ssl_certificate_key /etc/nginx/ssl/dot-server.key;
ssl_protocols TLSv1.2;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_handshake_timeout 10s;
ssl_session_cache shared:SSL:20m;
ssl_session_timeout 4h;
}
}
Restart nginx.
In Android Pie, go to Settings--Network--Advanced--Private DNS and add the name of your server. This setting will persist for Wi-Fi and mobile connections.
- Home
- Installation
- Configuration
- Checking that your DNS traffic is encrypted
- Automatic Updates
- Server sources
- Combining blocklists
- Public Blocklist and other configuration files
- Building from source
- Run your own DNSCrypt server in under 10 minutes
- DNS stamps specifications
- Windows tips
- dnscrypt-proxy in the media
- Planned Features