NOTICE: DoH services are now live!
Last check: 2019-11-22 at 19:00 Eastern time. Server names shown in green are currently up, server names shown in red are currently down. The script only checks IPv4, so if you think any or all of the servers are experiencing problems, feel free to contact me to let me know. DNSCrypt services are provided on port 443 with dnscrypt-wrapper and DoH services are provided on port 453 with routedns.
I have no corporate affiliation, and I have nothing to do with the development of DNSCrypt, RouteDNS, or Unbound. I am just some retired infrastructure guy who has strong opinions about privacy and security. I use these dnscrypt'ed servers for my own name resolution, there is no compensation for the time spent managing the servers, and my costs are partially covered by donations from users like you.
The dnscrypt.ca servers are Virtual Private Servers I rent from ULayer.net. Each server has an IPv4 address and an IPv6 address. On each server I run Unbound which receives DNS queries and looks up the IP addresses for them. The dnscrypt-wrapper and RouteDNS services allow you to connect with an appropriate client application which will forward your queries to the local Unbound service.
Both servers are in Montreal, both support DNSSEC (a feature of DNS that ensures you are getting the correct answers to your queries), both are uncensored, and these servers record no query logs. Unbound has some built in metrics that allow me to see that lately [as of 2019-11-20] the servers are doing about 3.2 million queries per day, but that is all I know. There is no record of who connects to these servers, or what names they resolve to IP addresses.
Pretty much everything you do with your Internet-connected device require a DNS lookup [or many lookups] to function. DNS turns names like dnscrypt.ca in to IP addresses like 220.127.116.11. Unfortunately, DNS is almost always unencrypted. As a result, it might be possible for someone to know what DNS names you are requesting, and ultimately what services you are using (even if you are connecting to an encrypted service). DNSCrypt is a way to encrypt your DNS queries, hiding them from prying eyes.