Simple DNSCrypt: the Windows desktop around dnscrypt-proxy
A simple management tool for dnscrypt-proxy
At a glance
- What is it?
- A WPF front end for jedisct1's dnscrypt-proxy that turns a text config file into tabbed settings for resolvers, routes and blacklists. Worth understanding the split, because the proxy and the app version at very different rates.
- Who is it for?
- Simple DNSCrypt solved a real problem, which is that dnscrypt-proxy is configured by editing a dnscrypt-proxy.toml file and most Windows users would rather click through tabs than learn that format. If you want the proxy without the editor, the honest comparison today is YogaDNS or configuring the toml file directly, since the last tagged release here is 0.7.1 from 11 April 2020 while the bundled proxy is at 2.1.15 and the repository saw a push on 19 March 2026.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Activity is slowing. The repository last received commits 6 months ago.
- What is it written in?
- Mainly C#, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.
Editorial analysis
A desktop shell for a program that ships as a text file
The repository description calls this a simple management tool for dnscrypt-proxy, and it is worth being precise about what that means. dnscrypt-proxy itself is a command line program by Frank Denis, commonly known as jedisct1, that handles encrypted DNS between a client and a resolver. Simple DNSCrypt does not implement any of that. It is a graphical front end that writes and manages dnscrypt-proxy's configuration.
That boundary explains the project's shape. The language is C#, the UI framework is WPF through MahApps.Metro, and the architecture is a single Visual Studio solution named SimpleDnsCrypt.sln with a SimpleDnsCrypt project directory beside it. The tree also carries an Uninstall directory, which is the output of the Advanced Installer packaging step rather than source code, along with two update manifests named update.yml and update64.yml.
The version numbers on each side of the boundary make the dependency direction obvious. The README's status line reads Uses dnscrypt-proxy: `2.1.15`, and a badge at the top of the file tracks the same number. Meanwhile the app's own releases stop at 0.7.1. The proxy is what gets security updates; the shell is what holds steady.
Installation is a signed MSI, x86 or x64, with the current links in the README pointing at the 0.7.1 assets on GitHub releases. For anyone who would rather not run an installer, the README also links a Chocolatey package maintained by someone other than the original author.
Verification instructions are the strongest part of the README
Most READMEs for desktop utilities stop at a download link. This one explains how to confirm the download is the one the author published, which matters more than usual for a tool that sits in front of every DNS query on a machine.
The MSI packages and the SimpleDnsCrypt.exe are signed with a COMODO RSA Code Signing CA under the name Christian Hermann, who is also the author listed in the README. The repository carries a minisign.pub file, and the README explains that you can verify the installers with minisign and gives you the exact command lines:
minisign -Vm SimpleDNSCrypt.msi -P RWTSM+4BNNvkZPNkHgE88ETlhWa+0HDzU5CN8TvbyvmhVUcr6aQXfssV
minisign -Vm SimpleDNSCrypt64.msi -P RWTSM+4BNNvkZPNkHgE88ETlhWa+0HDzU5CN8TvbyvmhVUcr6aQXfssVBoth signatures share one public key, and the .minisig files sit next to the installers on the releases page. Publishing a key in the repository root rather than only on a website is the right call, because it lets anyone archive the key and compare it later.
The update mechanism is described in a single sentence: Simple DNSCrypt will automatically search for the latest version at startup. There is no mention of a signature check on the update payload itself, which is a gap a security minded reader will notice. The update manifests in the tree root suggest a conventional updater rather than something bespoke, so the automatic update path is worth trusting a little less than the manual, verifiable download until the bundled proxy version is checked.
Uninstalling is described plainly, through the Windows Control Panel under Programs and Features. Nothing surprising there.
Reading the dependency list as a design summary
The README ends with a section listing every library the app uses, and that list is more informative than most architecture documents. It is a fairly long one, roughly twenty entries, and it divides into three groups.
The first group is the MVVM and UI plumbing: Caliburn.Micro for the view model pattern, MahApps.Metro and MahApps.Metro.SimpleChildWindow for the Windows look, ControlzEx for window chrome behaviour, gong-wpf-dragdrop for drag and drop, notifyicon-wpf for the system tray icon, and XAMLMarkupExtensions for terser markup.
The second group is crypto and signing: libsodium-net for the cryptographic primitives dnscrypt-proxy depends on, and minisign-net, a managed implementation of the same signature format the README tells you to use on the installer. The author wrote both minisign-net and DnsCrypt.Toolbox, so the DNS specific helper code comes from the same person as the shell around it.
The third group is plumbing and packaging: Newtonsoft.Json and YamlDotNet for config formats, NLog for logging, Costura.Fody to embed dependencies into the executable, Fody itself as the weaving tool, WPFLocalizationExtension for translations, and Baseclass.Contrib.Nuget.Output. Costura is the one with visible consequences, since embedding dependencies is why a single portable executable is plausible as a build artifact.
Localization runs through POEditor, and the README links a public project so translators can join directly. For a security utility used across countries, having the interface in the user's language is a real usability benefit rather than a cosmetic one, since the settings a user is most likely to get wrong are things like route selection and logging.
What the screenshot filenames say about scope
The README links eight screenshots from the img/preview directory, and their names are an unusually complete inventory of the feature set. Reading them in order gives you the shape of the application.
mainmenu.png is the entry point. resolvers.png is the important one, covering server selection. route.png covers routing, which decides which queries go through the encrypted resolver and which stay local. advanced.png covers advanced settings. blacklist.png and blocklog.png are a pair: the blacklist and the log of what it caught. settings.png is application configuration.
The pairing of blacklist and blocklog is what distinguishes this from a bare wrapper. A proxy can block domains, but showing the user a running list of what was blocked turns an invisible filter into something you can audit. The 0.6.9 release added a dnscrypt-proxy logfile option with advanced settings, and a set working directory on startup, which is consistent with an app that wants to expose proxy state rather than hide it.
Release 0.7.0 exists only to fix a small issue in 0.6.9 where relays were not added as a source on update, and 0.7.1 added remember window size alongside updated languages, updated dependencies, and dnscrypt-proxy 2.0.42. Reading that list, the project closed out its feature work around 2019.
Anonymized DNS support arrived in 0.6.9, linking the dnscrypt-proxy wiki page on the topic. That was the feature that made this configuration worth doing for people who care about resolver-side logging, and it is the one piece of history here worth knowing about.
Commits in 2026, but no release since 2020
Here is the thing to hold onto when deciding whether to install this. The default branch is master, the project is not archived, and the most recent push to it landed on 19 March 2026. On its own that suggests an active project.
The release history says something different. The three releases captured in the repository metadata are 0.7.1 from 11 April 2020, 0.7.0 from 17 November 2019, and 0.6.9 from 16 November 2019. So for most of the last six years there has been a tagged installer pointing at a proxy version well behind the one the README advertises today.
The two facts are not contradictory if you understand what kind of change is happening on master. Updates to dnscrypt-proxy binaries, dependency bumps, and translation pulls all produce commits without producing a release. The README status line showing 2.1.15 while the installer in releases is 0.7.1 with proxy 2.0.42 is the concrete symptom: the source tree tracks the proxy, the shipped installer does not.
For a reader deciding whether this is abandoned or merely finished, the honest answer is that the security-relevant half lives in another repository and has its own cadence. jedisct1's dnscrypt-proxy is where CVE fixes land. Simple DNSCrypt is the wrapper, and it has been feature complete for a long time.
The repository also has an open issue count of 146, which is a large number but consistent with a mature tool that accumulates requests. There are contributors listed separately in Contributors.md, and the README asks translators to update that file if they contribute a language.
Where this sits against YogaDNS and hand editing the config
The related searches attached to this project cluster around how to use Simple DNSCrypt, dnscrypt-proxy itself, dnscrypt-check, YogaDNS, and Simple DNSCrypt on Reddit and Android. That list is a fair map of what a person in this situation is actually weighing.
Dnscrypt-proxy on its own is a small, fast, dependency free program with an excellent wiki and a config file that is well documented. If you are comfortable editing toml and restarting a service, the proxy alone is the more honest choice, and it is the component that actually matters. Nothing in Simple DNSCrypt makes a query more private; it makes configuring the proxy easier.
YogaDNS shows up for the same reason this app exists. When someone wants per-app or per-domain routing on Windows, with a GUI that writes the rules for them, that is the shape of tool being looked for. Both projects are front ends over routing that is awkward to configure by hand.
The Android and mobile entries in the search set point to a different constraint entirely: encrypted DNS on a phone, where there is no dnscrypt-proxy to install, so the choices are a VPN-mode client or a local app. Simple DNSCrypt does not apply there.
The remaining comparison is the old one about desktop utilities generally. A signed MSI with a documented minisign verification path, a published signing key, and a tabbed settings UI is a better experience than a config file for most people, and worse for anyone who wants the proxy to run as a service without a GUI session.
Editorial conclusion
Simple DNSCrypt solved a real problem, which is that dnscrypt-proxy is configured by editing a dnscrypt-proxy.toml file and most Windows users would rather click through tabs than learn that format. If you want the proxy without the editor, the honest comparison today is YogaDNS or configuring the toml file directly, since the last tagged release here is 0.7.1 from 11 April 2020 while the bundled proxy is at 2.1.15 and the repository saw a push on 19 March 2026. That gap is the whole story about this project: the app is stable and finished, and the security-relevant component inside it keeps moving without the app following. Check the bundled proxy version on the Status tab before trusting an install, and verify the MSI with minisign before running it, because that check is documented well enough to be the most useful thing in the README.
Frequently asked questions
What is DNSCrypt used for?
In this project, DNSCrypt means dnscrypt-proxy, the program that sends DNS queries between a client and a resolver over an encrypted channel. Simple DNSCrypt exists to configure that program on Windows rather than to provide the encryption itself, which comes from libsodium through dnscrypt-proxy.
Which version of dnscrypt-proxy does Simple DNSCrypt bundle?
The README status line states Uses dnscrypt-proxy: `2.1.15`, and the latest tagged installer, version 0.7.1 from April 2020, was built against proxy 2.0.42. Since the source tree tracks the proxy but releases have not been cut since 2020, the version you get depends on whether you install the MSI or use a preview build.
How do I verify the Simple DNSCrypt installer is genuine?
The README documents verification with minisign, and publishes a minisign.pub key in the repository root alongside .minisig files next to each installer. The installers are also signed with a COMODO RSA Code Signing CA under the name Christian Hermann, so Windows will also report a publisher.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/dnscrypt-simplednscrypt)