$ prt-get depinst dnscrypt
Dnscrypt by default resolves to dnscrypt.eu-nl, file /usr/share/dnscrypt-proxy/dnscrypt-resolvers.csv contains list of compatible serers. Sysdoc dnscrypt-proxy port contains init script configured to use DNSCrypt.eu resolver and run as nobody user. Basic usage example;
$ sudo dnscrypt-proxy --daemonize --resolver-name=<resolver name>
Edit resolv.conf;
# Local dnsmasq server nameserver 127.0.0.1 # OpenNIC Servers # nameserver 192.71.249.83 # nameserver 5.135.183.146
Make sure daemons like dhcpd don't change it, turn on immutable attribute;
$chattr +i resolv.conf
Dnsmasq provides dns caching and dhcpd, example configuration files: dnsmasq.conf (change interface), resolv.conf.dnsmasq and hosts.dnsmasq.