# secure-dns-proxy

A lightweight proxy that handles secure DNS (DoH/DoT/DoQ) upstream while exposing a standard unencrypted DNS interface on `127.0.0.35:53`.

Since the proxy listens only on a local address, unencrypted DNS is not a concern. All outbound DNS queries are securely forwarded using HTTPS, TLS, or QUIC.

### Example Flow

[https://doh.archuser.org/dns-query](https://doh.archuser.org/dns-query) *(encrypted: HTTPS protocol)* → **secure-dns-proxy** *(unencrypted: standard DNS protocol)* → `127.0.0.35:53`

# LEGAL

This project is licensed under the AGPL version 3. Note the license terms, which are summarized at [https://choosealicense.com/licenses/agpl-3.0/](choosealicense.com).