Free public DNSCrypt and DNS-over-HTTPS server in Amsterdam, NL.


  • DNSSEC validation for better security
  • Caching
  • No logs
  • No censoring and filtering
  • Query prefetching to reduce latency
  • Query minimization for improved privacy
  • No forwarding to external/upstream DNS servers (recursive)
  • Daily certificate rotation for forward secrecy
  • Supporting the latest DNSCrypt v2 protocol version
  • Pi-hole compatible

DNSCrypt v2 server

Server namednscrypt.nl-ns0, dnscrypt.nl-ns0-ipv6
Provider name2.dnscrypt-cert.ns0.dnscrypt.nl
IPv4 address45.76.35.212
IPv6 address2001:19f0:5001:30a:5400:ff:fe58:7140

DNS-over-HTTPS server

Server namednscrypt.nl-ns0-doh
IPv4 address108.61.199.170
IPv6 address2001:19f0:5000:8067:5400:ff:fe27:25a2
Query URLhttps://doh.dnscrypt.nl/dns-query

Recursive DNS server

The recursive DNS server software being used is the most recent version of Unbound and the DNS resolver hostname is ns0.dnscrypt.nl with the IP address By using either one of the servers, it makes queries to this DNS server which is only accepting queries from DNSCrypt and DNS-over-HTTPS capable clients.

Public key and DNS stamps and verification

Provider key (pkey.ns0)
dnscrypt.nl-ns0 (stamp.ipv4.ns0)
dnscrypt.nl-ns0-ipv6 (stamp.ipv6.ns0)
dnscrypt.nl-ns0-doh (stamp.doh.ns0)

Server details can be verified by checking out my Keybase public files which are PGP signed by me. Alternatively use dig as shown below.

dig A +short +dnssec ns0.dnscrypt.nl
dig TXT +short +dnssec pkey.ns0.dnscrypt.nl
dig TXT +short +dnssec pname.ns0.dnscrypt.nl
dig TXT +short +dnssec sname.ns0.dnscrypt.nl
dig TXT +short +dnssec ips.ns0.dnscrypt.nl
dig TXT +short +dnssec port.ns0.dnscrypt.nl
dig TXT +short +dnssec stamp.ipv4.ns0.dnscrypt.nl
dig TXT +short +dnssec stamp.ipv6.ns0.dnscrypt.nl
dig TXT +short +dnssec stamp.doh.ns0.dnscrypt.nl

To verify that you are actually making use of DNSCrypt.nl DNS server do a DNS Leak test.