This was the original.
Other than having to modify their ksh script, it is painless to set up.
In my opinion, authoritative nameservers, and therefore DNSCurve forwarders like CurveDNS, are more important than recursive resolvers/caches such as OpenDNS and DNSCrypt.
A recursive resolver should be authoritative for nothing. They are middlemen. Companies that offered this "service", such as OpenDNS, had to pander to advertisers, or were run by advertising companies themselves, e.g., Google.
The "rules" of DNS are easily broken. This applies to caches. One does not need to look very far to find resolvers that someone has designated as "authoritative". dnsq: "weird ra". This often means an open resolver IME.
A while back some companies including the ones named above if I am not mistaken were pushing for extensions in DNS to put at least part of user IP addresses into DNS packets so cache operators could track them. The reason? Advertising. (Although maybe they would cite other reasons.) Not sure what ever happened with that. BIND had started to implement it. Thankfully djbdns will never support this garbage.
This kind of nonsense is why I cannot get excited about the latest extensions to internet protocols anymore.
Too often they are for the benefit of web companies and advertisers, not users.
The "encrypted DNS revolution", if it ever comes, is not going to be initiated by companies running recursive resolvers. (Unless they also run authoritative nameservers.)
Note: When the user runs their own cache on localhost there is no need to determine nearest POP.