http://ciisqbg45nggykdl6rjdrq3wc64csga4vkphu66qsi65mypeitqedoad.onion/blog/anondns
But before they can connect to the VPN, they'll need to use DNS to resolve the VPN server's hostname (unless they're using IPs in their configs, which we recommend against because our IPs change sometimes, but the hostnames rarely do). DNSCrypt encrypts those DNS queries so that 3rd parties can't monitor or manipulate the traffic. We don't know that a client is a client until after they login to the VPN, so all of our DNSCrypt (and regular DNS) servers are accessible to everyone.