summaryrefslogtreecommitdiff
path: root/network/dnscrypt-proxy/dnsmasq.conf
blob: 9700cb2df9b91192d2b6be1c92274ba3a46e0dc3 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
# Use dnsmasq as a caching DNS forwarder to dnscrypt-proxy. This configuration
# assumes dnscrypt-proxy is running on port 55.

# Never forward plain names (without a dot or domain part)
domain-needed

# Never forward addresses in the non-routed address spaces.
bogus-priv

# Don't use /etc/resolv.conf. Forward all queries to dnscrypt-proxy.
no-resolv

# Use the resolver on localhost port 55 (dnscrypt-proxy)
server=127.0.0.1#55

# Listen on localhost. Default port 53
listen-address=127.0.0.1

# Pass on the upstream DNSSEC flag. Only enable this if you trust the upstream
# resolver.
#proxy-dnssec