"As most DNSCrypt servers
run on port 443, it may be reasonable to allow only that port." is not good enough.
dnscrypt-proxy can download markdown from github for latest servers. Similar to this, encrypt-dns-server could download same list daily to restrict the client's relay destination.
[anonymized_dns]
restrict_destination = true # default is false.
# If true, download [sources] to collect "IP:Port" lists.
# 1. When the client tries to connect to destination:dPort not on the list, kill the connection.
# 2. If the clients still tries to connect to destination not on the list REPEATEDLY, ban the IP for 1 hour.
...
[sources]
[sources.public-resolvers]
urls = [ 'https://raw.githubusercontent.com/DNSCrypt/dnscrypt-resolvers/master/v3/public-resolvers.md' ]
cache_file = 'public-resolvers.md'
minisign_key = 'RWQf6LRCGA9i53mlYecO4IzT51TGPpvWucNSCh1CBM0QTaLn73Y7GFO3'
refresh_delay = 73
prefix = ''
"As most DNSCrypt servers
run on port 443, it may be reasonable to allow only that port." is not good enough.
dnscrypt-proxycan download markdown from github for latest servers. Similar to this,encrypt-dns-servercould download same list daily to restrict the client's relay destination.