README.md
August 17, 2026 ยท View on GitHub
:zap: DNS Blocklists - Let's make the internet a nicer place!
Built with :heartbeat: for a safer, cleaner internet. It always looks impossible until someone actually does it.
Privacy isn't a crime, so go protect yours. It's what lets you decide who you are and who you want to be :bangbang:
Like this project? If it's been useful to you, drop a :star: (top right) and join the stargazers club! Every star genuinely helps.
:bookmark_tabs: Table of Contents
- Overview
- Multi light - Hand brush: light protection
- Multi normal - Broom: all-round protection
- Multi pro - Big broom: extended protection (recommended): Full - Mini
- Multi pro++ - Sweeper: maximum protection (more aggressive): Full - Mini
- Multi ultimate - Ultimate sweeper: aggressive protection: Full - Mini
- Fake - Blocks scams, traps, and fake sites!
- Pop-Up Ads - Stops annoying and malicious pop-ups!
- Threat Intelligence Feeds - A serious security boost (recommended): Full - Medium - Mini - IPs
- Newly Registered Domains - NRD/DGA - A favorite tool of threat actors for launching attacks!
- DoH/VPN/TOR/Proxy Bypass - Stop people from sneaking around your DNS: Full - DoH only - DoH IPs
- Safesearch not supported - Block search engines that skip Safesearch!
- Dynamic DNS - Guard against dynamic DNS abuse!
- Badware Hoster - Guard against malicious hosting services!
- URL Shortener - Blocks link/URL shorteners!
- Most Abused TLDs - Blocks known shady top-level domains!
- DNS Rebind Protection - Stops attackers from pointing domains at your local network!
- Anti Piracy - Blocks piracy sites!
- Gambling - Blocks gambling content: Full - Medium - Mini
- Social Networks - Blocks access to social networks!
- NSFW - Blocks adult content!
- Native Tracker - Built-in trackers from devices, apps, and OSes
- Recommendation - Which list version should I actually use?
- Online DNS Services: HaGeZi DNS - DNS Bunker
- About: Repository - Referral Domains - Support
- FAQ - Frequently asked questions
- Where does the data come from, and how are the lists built?
- Which list version should I use?
- Which format should I use for my ad blocker or DNS server?
- Quick setup guide
- Why aren't referral domains blocked?
- Why aren't CMPs (cookie consent tools) blocked?
- Which lists are available on which DNS services?
- How current is the data, and where can I get it?
- Licensing and liability
- Getting help and reporting issues
- Glossary
- Discussions
- Update Interval/Official Mirrors
- Sources
- Disclaimer
- Contact
:books: Multi - Cleans up the internet and protects your privacy!
This is an all-in-one DNS blocklist that comes in several versions (light, normal, pro, pro++, and ultimate). You can run it as a standalone blocklist, and it works for any region. It blocks ads, affiliate links, trackers, metrics, telemetry, fake sites, phishing, malware, scams, cryptojacking, and other junk. It's built on various source blocklists, but that doesn't mean it's just a bunch of lists glued together. Everything here has been optimized and extended to properly clean up the internet across the board.
Curious about the sources? Check out: Which sources are used for the lists and how are they compiled?
Blocklist versions and sizes at a glance:
| Version | Entries | Pro++ | Pro | Nor mal | Light | Fake | TIF | Nat ive | PopUp Ads | Bug Tracker |
|---|---|---|---|---|---|---|---|---|---|---|
| :green_book:Light | 41528 | :green_circle: | :yellow_square: | :yellow_square: | ||||||
| :blue_book:Normal | 183588 | :green_circle: | :green_circle: | :green_circle: | :yellow_square: | :yellow_square: | :yellow_square: | |||
| :ledger:Pro | 217939 | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :yellow_square: | :yellow_square: | :green_circle: | :green_circle: | |
| :orange_book:Pro++ | 241676 | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :yellow_square: | :yellow_square: | :green_circle: | :green_circle: |
| :closed_book:Ultimate | 266389 | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :yellow_square: | :green_circle: | :green_circle: | :green_circle: |
:green_circle: fully includes the list named in the column header :yellow_square: partially includes the list named in the column header
Blocking intensity:
| Version | Blocking level | Blocking type |
|---|---|---|
| :green_book:Light | :green_book::green_book: | Relaxed |
| :blue_book:Normal | :blue_book::blue_book::blue_book: | Relaxed/Balanced |
| :ledger:Pro | :ledger::ledger::ledger::ledger: | Balanced |
| :orange_book:Pro++ | :orange_book::orange_book::orange_book::orange_book::orange_book::orange_book: | Balanced/Aggressive |
| :closed_book:Ultimate | :closed_book::closed_book::closed_book::closed_book::closed_book::closed_book::closed_book: | Aggressive |
Tip
:information_desk_person: Not sure which version fits you? Check this out.
:green_book: Multi LIGHT - Basic protection
Hand brush edition. Cleans up the internet and protects your privacy without going overboard. Blocks ads, trackers, metrics, and some badware. It's basically a size-optimized version of Multi NORMAL.
Note
Blocking type: Relaxed This version shouldn't cause any real restrictions. Great if there's no admin around to unblock stuff for you, or if your ad blocker chokes on big lists.
Important
Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
Entries: 41528
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:blue_book: Multi NORMAL - All-round protection
Broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Relaxed/Balanced This one mostly won't cause restrictions either. Good pick if you don't have an admin handy to unblock anything.
Important
Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
Entries: 183588
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:ledger: Multi PRO - Extended protection (recommended)
Big broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Balanced Restrictions here are rare. Works best if you've got an admin nearby who can unblock something if needed. This is my personal go-to recommendation for solid ad blocking with good privacy without much hassle.
Warning
Referral domains (affiliate and tracking links): Most referral domains are still allowed here, but a handful get blocked anyway, mainly ones that double as regular trackers or are commonly tied to scam and spam links. Details: Referral domains
Entries: 217939
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:ledger: Multi PRO mini (best for browser/mobile ad blockers)
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. This only contains domains from the full Pro list that show up on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 55550
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:orange_book: Multi PRO++ - Maximum protection
Sweeper edition. This one cleans up the internet aggressively and protects your privacy hard. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Balanced/Aggressive This is the more aggressive sibling of Multi PRO. It might block a few legit domains by mistake, so it's best for experienced users. Ideally have an admin ready to unblock things that break.
Warning
Referral domains (affiliate and tracking links): A handful of referral domains that double as regular trackers are blocked here too. Details: Referral domains
Entries: 241676
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:orange_book: Multi PRO++ mini
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. Contains only domains from the full Pro++ list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 66892
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:closed_book: Multi ULTIMATE - Aggressive protection
Ultimate sweeper edition. Strictly cleans up the internet and locks down your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Aggressive This is a stricter version of Multi PRO++. It contains domains that can limit app or website functionality, including some popular trackers that will cause hiccups. Only use this if you know what you're doing, and make sure someone can unblock things when needed.
Warning
Referral domains (affiliate and tracking links): A few referral domains that also act as regular trackers get blocked. Details: Referral domains
Facebook: Ultimate blocks some META trackers, which limits Facebook and Facebook Messenger app functionality. It also blocks WhatsApp's graph trackers, which can mess with avatar creation, the in-app help center, and video effects. Other than that, WhatsApp works fine. If you use META apps alongside Ultimate, unblock these domains as needed: META Tracker
Windows/Xbox: Some Microsoft trackers are blocked too, which can affect things like Windows Spotlight and Xbox Live Achievements Activity History. Check here for details on which domains to unblock for which feature: Microsoft Tracker.
Location and IP trackers: Certain trackers that websites use to pin down your IP or location get blocked. Great for privacy, but it might trigger wrong regional settings, extra CAPTCHAs, or reduced site functionality here and there. These trackers are usually used for hidden analytics and ad targeting.
Anything else: More known quirks are listed here.
Entries: 266389
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:closed_book: Multi ULTIMATE mini
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. Contains only domains from the full Ultimate list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 81908
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:trollface: Fake - Blocks scams, traps, and fake sites!
This blocklist targets fake stores, fake streaming sites, rip-offs, subscription traps, and similar scams.
| Light | Normal | Pro | Pro++ | Ultimate | TIF TIF medium | |
|---|---|---|---|---|---|---|
| Included in | :x: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 16861
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:tada: Pop-Up Ads - Stops annoying and malicious pop-ups!
Targets pop-up ads that range from annoying to outright malicious.
| Light | Normal | Pro | Pro++ | Ultimate | TIF | |
|---|---|---|---|---|---|---|
| Included in | :yellow_square: | :yellow_square: | :green_circle: | :green_circle: | :green_circle: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 53493
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:closed_lock_with_key: Threat Intelligence Feeds - A serious security boost (recommended)
This blocklist targets malware, cryptojacking, scams, spam, and phishing. It blocks domains known for spreading malware, running phishing attacks, and hosting command-and-control servers.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :yellow_square: | :yellow_square: | :yellow_square: | :yellow_square: |
:green_circle: yes :yellow_square: partially :x: no
Warning
This list is huge and can eat up a lot of memory depending on your ad blocker. If that's an issue, grab the medium or mini version instead.
Entries: 2064237
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ (split) | :one: Link :two: Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound :warning: Note: this list had to be split into two parts because of its size. You need both. |
:closed_lock_with_key: Threat Intelligence Feeds - Medium version (best for browser/mobile ad blockers)
A medium-sized version of the TIF list, built for ad blockers that struggle with the full-size version. Includes only the most important feeds.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :yellow_square: | :yellow_square: | :yellow_square: | :yellow_square: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 391374
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:closed_lock_with_key: Threat Intelligence Feeds - Mini version
A size-optimized version of the TIF Medium list, for ad blockers that even struggle with that one.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :yellow_square: | :yellow_square: | :yellow_square: | :yellow_square: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 170098
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:closed_lock_with_key: Threat Intelligence Feeds - IPs
There's also an IPv4 version of this list, in plain IP format for firewalls and AdGuard Home format, which extends the regular TIF list.
Tip
If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
:new: Newly Registered Domains (NRD/DGA)
Newly registered domains (NRDs) are a favorite tool for threat actors running phishing, malware, and command-and-control operations, since these domains are easy to throw away and help dodge detection.
There are two variants:
- NRDs: every newly registered domain, no filtering.
- Entropy NRDs/DGAs: only newly registered domains with high entropy, meaning they were likely generated by a Domain Generation Algorithm (DGA). These have a random-looking structure and are commonly used by malware for resilient command-and-control channels.
Warning
These lists are big and resource-heavy. They can spike memory usage and include false positives, since some legit domains are new too. Use with care and whitelist important services if needed.
Caution
Use these at your own risk. NRD lists come as-is, with no guarantees, no support, and no formal process for fixing false positives.
Important
The base data comes from Stamus Labs. Stamus Labs doesn't promise daily updates, so the data can sometimes lag by a few days.
Current status of the data:
- Stamus Labs: :green_circle: - Mon, 17 Aug 2026 04:11:18 UTC / 10503908 domains
:new: NRDs: all newly registered domains, unfiltered
| Time period | Entries | Format AdBlock | Format Domains |
|---|---|---|---|
| 7 days ago to yesterday | 3005552 | Link | Link |
| 14 days ago to 8 days ago | 2949418 | Link | Link |
| 21 days ago to 15 days ago | 2319698 | Link | Link |
| 28 days ago to 22 days ago | 2389823 | Link | Link |
| 35 days ago to 29 days ago | 2698146 | Link | Link |
Note
Want to block NRDs from the last 14 days? Combine the 7-day and 14-day lists. For the last 21 days, add in the 21-day list too, and so on.
Tip
Besides the formats here, NRDs are also available elsewhere:
- Wildcard (Asterisk): Cebeerre/dnsblocklists
:capital_abcd: Entropy NRDs/DGAs: only newly registered, high-entropy domains generated by DGAs
Note
These domains are already part of the full NRD list, just filtered down.
| Time period | Entries | Format AdBlock | Format Domains |
|---|---|---|---|
| Past 7 days | 554751 | Link | Link |
| Past 14 days | 1193427 | Link | Link |
| Past 30 days | 2473339 | Link | Link |
:outbox_tray: DoH/VPN/TOR/Proxy Bypass - Stop people from sneaking around your DNS!
Blocks common ways to bypass your DNS setup.
Note
To make sure your DNS server is actually the one being used, you'll need to redirect or block standard DNS traffic (TCP/UDP 53) and also block DNS over TLS/QUIC (TCP/UDP 853) outbound.
This list comes in two flavors:
Complete edition: encrypted DNS servers, VPN, TOR, proxies
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 16593
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:outbox_tray: Encrypted DNS servers only
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 3370
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:outbox_tray: Encrypted DNS server IPs
There's also an IPv4 version in plain IP format for firewalls, and an AdGuard Home format.
Tip
If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
:mag: Safesearch not supported - Blocks search engines that skip Safesearch!
Blocks search engines that don't support Safesearch.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 205
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:lock_with_ink_pen: Dynamic DNS blocking - Guards against dynamic DNS abuse!
Blocks dynamic DNS services that get abused for phishing campaigns and other shady activity.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 1521
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:computer: Badware Hoster blocking - Guards against malicious hosting services!
Blocks known hosting providers that repeatedly host badware through user-uploaded content.
Important
This list blocks the root domains of hosting providers that keep showing up in threat feeds because of malicious subdomains. That means legit sites hosted there will get blocked too, so think it through before using this one.
If you use this list, you're on your own for unblocking any subdomains you actually need.
Caution
Blocking whole hosting providers is overkill for most setups and can break legit services. In high-security environments though, that trade-off might make sense.
| Light | Normal | Pro | Pro++ | Ultimate | TIF | |
|---|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 1238
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
| ControlD | Link | ControlD folder |
:calling: URL Shortener - Blocks link shorteners!
Blocks every known URL/link shortener out there.
Warning
Not really meant for everyday setups. Blocking all URL shorteners makes the most sense in high-security environments, since shorteners can hide where a link actually leads and help enable attacks. In lower-risk settings, keeping an eye on things or just being careful usually does the job.
If you use this list, you're on your own for unblocking any domains you actually need.
| Light | Normal | Pro | Pro++ | Ultimate | TIF | |
|---|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 9875
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:crystal_ball: Most Abused TLDs - Blocks known shady top-level domains! (recommended)
Blocks the most abused top-level domains, combining data from Cloudflare Radar, Netcraft, and SpamHaus.
Warning
This list blocks entire top-level domains (like *.top, *.shop, *.gdn) that have a bad reputation overall. Yes, that means some legit sites get caught in the crossfire too, but it's really effective against spam, scams, phishing, malware, and other garbage. Know what you're signing up for.
Only well-known, reputable domains that show up on major top lists (Umbrella, Cloudflare, Tranco, Chrome, DomCop, etc.) or are essential for popular apps get considered for exclusion. Illegal domains, including piracy sites, stay blocked no matter what. Anything that doesn't clearly qualify gets reviewed case by case, and if there's no good reason to unblock it, it stays blocked. If you need access to something specific, add it to your personal allowlist.
This selective approach exists because AdGuard and uBlock Origin have technical limits on rule length when using denyallow/domain modifiers. Trying to exclude every legit domain would eventually break important rules, so exclusions have to stay limited and carefully picked.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
| Format | Links | Should be used for |
|---|---|---|
| AdGuard | Link | AdGuard, AdGuard Home |
| uBlock Origin | Link | uBlock Origin, Adblock Plus |
| AdBlock | Link | Pi-hole, TechnitiumDNS Only includes spam TLDs with no exclusions. |
| AdBlock (Aggressive) Allowlist | Link Link | Pi-hole, TechnitiumDNS |
| Wildcard Domains Allowlist | Link Link | DNSCrypt |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound Only includes spam TLDs with no exclusions. |
| RPZ (Aggressive) | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound Includes all spam TLDs, matching the AdGuard/uBlock Origin version without exclusions. |
| ControlD | Link | ControlD folder |
:shield: DNS Rebind Protection - Stops attackers from pointing domains at your local network!
DNS Rebind Protection stops attackers from messing with DNS responses to make a domain point to a private or local IP address. This blocks malicious scripts from using DNS rebinding attacks to reach your internal network.
Important
This only works with AdGuard/AdGuard Home, and it's also selectable in AdGuard DNS. Other DNS blockers may already have their own rebind protection built in.
Since rebind protection blocks anything resolving to a local IP, your internal hostnames might get caught too.
In AdGuard, whitelist your local domains, something like: @@||fritz.box^
| Format | Links | Should be used for |
|---|---|---|
| AdGuard | Link | AdGuard, AdGuard Home |
:skull: Anti Piracy - Blocks piracy sites!
Blocks sites and services mainly used for illegally distributing copyrighted content.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 41599
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:slot_machine: Gambling - Blocks gambling content!
Blocks gambling-related sites.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 450018
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:slot_machine: Gambling - Medium version
A medium-sized version for ad blockers that have trouble with the full gambling list.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 154739
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:slot_machine: Gambling - Mini version
A size-optimized version of the Gambling Medium list. Only contains domains that show up on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 105922
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:speech_balloon: Social Networks - Blocks access to social networks!
Blocks social networks like Facebook, Instagram, TikTok, X (formerly Twitter), Snapchat, and others.
Note
This list won't block messaging apps like WhatsApp or streaming platforms like Twitch. It's strictly aimed at classic social networking sites.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 898
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:underage: NSFW - Blocks adult content!
Blocks adult content.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :x: | :x: | :x: | :x: | :x: |
:green_circle: yes :yellow_square: partially :x: no
Entries: 112390
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
:calling: Native Tracker - Built-in trackers from devices, apps, and OSes
Blocks the native trackers baked into devices, services, and operating systems that quietly track what you do.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | :yellow_square: | :yellow_square: | :yellow_square: | :yellow_square: | :green_circle: |
:green_circle: yes :yellow_square: partially :x: no
Important
Native tracker lists cover everything used to monitor user activity, which can occasionally limit functionality too. They're integrated across all the standard tiers (Light, Normal, Pro, Pro++, Ultimate), each at a different blocking level:
- Light through Pro: only block native trackers that won't break functionality, for a smooth experience.
- Pro++ (aggressive): blocks extra native trackers that might cause some restrictions or limit certain features.
- Ultimate: the most thorough option, blocking all native trackers for max privacy.
Pick whichever tier matches how aggressive you want to be about native tracker blocking.
When combining native tracker lists with the standard lists, you might need to manually unblock a specific tracker here or there.
| Device/Service | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| Amazon (Devices, Shopping, Video) | Link | Link | Link | Link | Link |
| Apple (iOS, macOS, tvOS) | Link | Link | Link | Link | Link |
| Huawei (Devices) | Link | Link | Link | Link | Link |
| Microsoft (Windows, Office, MSN) | Link | Link | Link | Link | Link |
| Samsung | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) Aggressive | Link | Link | Link | Link | Link |
| LG webOS | Link | Link | Link | Link | Link |
| Roku | Link | Link | Link | Link | Link |
| Vivo | Link | Link | Link | Link | Link |
| OPPO/Realme | Link | Link | Link | Link | Link |
| Xiaomi | Link | Link | Link | Link | Link |
:bulb: Recommendation
For network-wide DNS blocking, I'd recommend AdGuard Home, Pi-hole, TechnitiumDNS, Blocky (if you're comfortable with advanced setups), adblock-lean (for OpenWrt), or eBlocker.
DNS blockers do a great job protecting your privacy by cutting off trackers, metrics, and telemetry. They can also block most ads, malware, scams, and fake sites, but they can't catch everything since some of that stuff doesn't work through DNS.
That's why I also recommend pairing this with a browser content blocker like AdGuard, uBlock Origin, or Ghostery.
Check out Yokoffing's Recommended Filters for uBlock Origin for good content blocker filter lists.
Tip
:information_desk_person: Still not sure which version to pick?
:department_store: Online DNS Services
Don't run your own DNS server at home, or want extra protection for your phone when it's off your home network? These DNS services have you covered.
Which lists are available where:
| Service | Light | Nor mal | Pro | Pro ++ | Ulti mate | TIF | By pass | Dyn DNS | Hoster | TLDs | Anti Piracy | Gam bling | ... |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AdGuard DNS | :x: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
| ControlD | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :yellow_square: | :yellow_square: | :notebook: | :notebook: | :yellow_square: | :yellow_square: | :x: |
| Rethink DNS | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :x: | :x: | :x: | :x: |
| DNS warden | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :x: | :x: | :x: | :x: | :x: | :x: | :x: |
:yellow_square: Included as part of ControlD's native category lists. :notebook: Available as a ControlD folder.
:department_store: AdGuardDNS - limited free / unlimited trial / paid
On AdGuardDNS you can use:
- Normal, Pro, Pro++, Ultimate
- Threat Intelligence Feeds (TIF), Most Abused TLDs, Badware Hoster, DynDNS, DNS Rebind Protection, URL Shortener
- DoH/VPN/TOR/Proxy Bypass
- Gambling
- Anti Piracy
- Native Tracker (Apple, OPPO & Realme, Samsung, Vivo, Windows/Office, Xiaomi)
- Allowlist Referral
:department_store: ControlD - free / paid
On ControlD you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
Free:
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC | Legacy DNS | Apple |
|---|---|---|---|---|
| Light | https://freedns.controld.com/x-hagezi-light | x-hagezi-light.freedns.controld.com | 76.76.2.37 76.76.10.37 2606:1a40::37 2606:1a40:1::37 | Link |
| Normal | https://freedns.controld.com/x-hagezi-normal | x-hagezi-normal.freedns.controld.com | 76.76.2.40 76.76.10.40 2606:1a40::40 2606:1a40:1::40 | Link |
| Pro | https://freedns.controld.com/x-hagezi-pro | x-hagezi-pro.freedns.controld.com | 76.76.2.41 76.76.10.41 2606:1a40::41 2606:1a40:1::41 | Link |
| Pro Plus | https://freedns.controld.com/x-hagezi-proplus | x-hagezi-proplus.freedns.controld.com | 76.76.2.42 76.76.10.42 2606:1a40::42 2606:1a40:1::42 | Link |
| Ultimate | https://freedns.controld.com/x-hagezi-ultimate | x-hagezi-ultimate.freedns.controld.com | 76.76.2.45 76.76.10.45 2606:1a40::45 2606:1a40:1::45 | Link |
| TIF | https://freedns.controld.com/x-hagezi-tif | x-hagezi-tif.freedns.controld.com | 76.76.2.46 76.76.10.46 2606:1a40::46 2606:1a40:1::46 | Link |
Paid:
Check out Yokoffing's ControlD Config Guide for good ControlD settings.
Automation:
controld-hagezi-sync: automatically syncs HaGeZi folder blocklists to ControlD profiles via API. Supports TOML config, dry-run mode, multi-profile mappings, and daily GitHub Actions syncs.
:department_store: HaGeZi DNS (EU: Germany/Finland, balanced blocking) - free
HaGeZi DNS runs free, non-commercial public resolvers for Europe, mixing privacy and security with minimal restrictions using the Multi Pro and Threat Intelligence Feed lists.
More details in the project repository.
Blocks ads, trackers, analytics, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Falkenstein | DoH/DoH3 | https://root.hagezi.org/dns-query | Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK |
| DoT/QUIC | root.hagezi.org | |||
| Do53 | 188.34.161.2102a01:4f8:c17:1c66::1 | |||
| Germany, Nuremberg | DoH/DoH3 | https://wurzn.hagezi.org/dns-query | Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | wurzn.hagezi.org | |||
| Do53 | 159.69.155.942a01:4f8:1c1c:d363::1 | |||
| Finland, Helsinki | DoH/DoH3 | https://juuri.hagezi.org/dns-query | Link QR | DK, EE, FI, LT, LV, NO, SE |
| DoT/QUIC | juuri.hagezi.org | |||
| Do53 | 95.217.163.172a01:4f9:c013:dc4e::1 |
Blocks ONLY phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Nuremberg | DoH/DoH3 | https://ctif.hagezi.org/dns-query | Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | ctif.hagezi.org | |||
| Do53 | 162.55.58.402a01:4f8:1c19:6c19::1 |
:department_store: DNSBUNKER.org (EU: Germany, balanced blocking) - free
DNSBUNKER.org is a hardened, privacy-first DNS resolver based in Germany.
| Blocklists | DNS-over-HTTPS/3 | DNS-over-TLS/QUIC | Apple |
|---|---|---|---|
| Pro + TIF | https://dnsbunker.org/dns-query | dnsbunker.org | Link |
:department_store: Public RDNS (EU: Finland, family-safe, aggressive blocking) - free
Public RDNS is a free, no-log recursive resolver for families that uses HaGeZi lists to aggressively block ads, trackers, malware, NSFW content, piracy, gambling, and other unwanted domains.
More info on the project page.
:department_store: RobinGroppe.de (EU: Germany, threat blocking) - free
RobinGroppe.de DNS is a free, privacy-focused DNS service. It doesn't log your queries and protects your connection by blocking malware, phishing, and other online threats using the HaGeZi Threat Intelligence Feeds.
:department_store: RethinkDNS - free
On RethinkDNS you can use Light, Normal, Pro, Pro++, Ultimate, TIF, DynDNS, and Badware Hoster.
Note
RethinkDNS only updates its lists once a week.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://sky.rethinkdns.com/1:AAkACAQA | 1-aaeqacaeaa.max.rethinkdns.com |
| Normal + TIF | https://sky.rethinkdns.com/1:AAkACAgA | 1-aaeqacaiaa.max.rethinkdns.com |
| Pro + TIF | https://sky.rethinkdns.com/1:AAoACBAA | 1-aafaacaqaa.max.rethinkdns.com |
| Pro plus + TIF | https://sky.rethinkdns.com/1:AAoACAgA | 1-aafaacaiaa.max.rethinkdns.com |
| Ultimate + TIF | https://sky.rethinkdns.com/1:gAgACABA | 1-qaeaacaaia.max.rethinkdns.com |
:department_store: DNSwarden - free
On DNSwarden you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://dns.dnswarden.com/00000000000000000000048 | 00000000000000000000048.dns.dnswarden.com |
| Normal + TIF | https://dns.dnswarden.com/00000000000000000000028 | 00000000000000000000028.dns.dnswarden.com |
| Pro + TIF | https://dns.dnswarden.com/00000000000000000000018 | 00000000000000000000018.dns.dnswarden.com |
| Pro plus + TIF | https://dns.dnswarden.com/0000000000000000000000o | 0000000000000000000000o.dns.dnswarden.com |
| Ultimate + TIF | https://dns.dnswarden.com/0000000000000000000000804 | 0000000000000000000000804.dns.dnswarden.com |
:department_store: OpenBLD.net - free
OpenBLD.net combines the Pro list with the TIF blocklist.
| Blocklists | DNS-over-HTTPS |
|---|---|
| Pro + TIF | https://ric.openbld.net/dns-query/hagezi |
:loudspeaker: About
"If the plan doesn't work, change the plan, not the goal."
There's no place like 127.0.0.1!
These blocklists are built on various sources plus my own denylists and extensions. The goal has always been to avoid false positives as much as possible without giving up effectiveness. Dead entries get pruned regularly to keep the lists lean. Built with :heartbeat: for a safer, cleaner internet.
Every list gets tested against 10,000 websites from the Cisco Umbrella Top 1 million list. I check whether pages load properly, content displays correctly, navigation works, images load, videos play, and so on.
So no, these aren't just random lists stitched together from other sources. They've been optimized and extended to genuinely clean up the internet across every category. Curious how? Check out: Which sources are used and how are the lists compiled?
Here's how each version performed against the 10,000 whotracks.me pages. All pages were opened and fully loaded in batch via Edge with privacy features turned off, and cookies accepted.
| List | Total queries | Blocked queries | % blocked | % gap to light |
|---|---|---|---|---|
| Ultimate | 299646 | 131093 | 43.75 | 12.85 |
| Pro++ | 299646 | 119681 | 39.94 | 9.05 |
| Pro | 299646 | 97508 | 32.54 | 1.65 |
| Normal | 299646 | 93258 | 31.12 | 0.23 |
| Light | 299646 | 92576 | 30.90 | |
| ---- | 299646 | 67888 | 22.66 | -8.24 |
Give it a try, share your feedback, and report anything that should (or shouldn't) be blocked.
:octocat: Repository
The repository gets compressed (reinitialized) every now and then to keep its size in check. Heads up: this invalidates forks and wipes the commit history.
:cyclone: Referral Domains
Wondering why referral domains (affiliate and tracking links) aren't blocked? Here's the answer: FAQ on referral domains
:dizzy: Support
If this project has been useful to you, drop a :star: (top right) and join the stargazers!
This project only exists because of a genuinely supportive community. It's free for everyone and stays up to date thanks to ongoing care, updates, and contributions from people who actually want to make things better.
Feedback, ideas, domain reports, false-positive reports, whatever you've got, it's all appreciated. Every bit of help, big or small, makes the internet a little safer and cleaner for everyone.
See: Getting help and reporting issues
Thanks for being part of this!
:floppy_disk: Update Interval/Official Mirrors
The primary source for all lists is the GitHub repository. The GitHub repository and its two full mirrors, GitLab and Codeberg, are updated in sync, once a day:
| Source | Update frequency |
|---|---|
| GitHub/jsDelivr (primary) | Once a day |
| gitlab.com/hagezi/mirror | Once a day, in sync with GitHub |
| codeberg.org/hagezi/mirror2 | Once a day, in sync with GitHub |
| hagezi-mirror.dnsbunker.org | Every 4 to 8 hours |
Tip
If you need the freshest possible data, use hagezi-mirror.dnsbunker.org. It's connected directly to the build system and receives each new list version as soon as it's built, ahead of the daily GitHub, GitLab, and Codeberg update.
:warning: Disclaimer
Important
No warranty. These DNS blocklists ("the Lists") are provided free of charge, "as is" and "as available," with no warranty of any kind, express, implied, or statutory. The creator/operator of the Lists ("the Provider") makes no promises about accuracy, completeness, timeliness, reliability, or fitness for any particular purpose. There's no guarantee that every malicious or unwanted domain is covered, and no guarantee that legitimate domains won't get blocked by mistake.
Assumption of risk. Using the Lists is entirely at your own risk. The Provider disclaims any and all direct, indirect, incidental, or consequential liability for damages arising from using, misusing, or being unable to use the Lists, except where such damages result from willful misconduct or gross negligence on the Provider's part.
A supplement, not a substitute. The Lists are meant to be one part of a broader defense-in-depth strategy, not the whole thing. They don't replace your own responsibility to do due diligence, run your own risk assessments, or use additional protections (firewalls, antivirus/EDR, IDS/IPS, etc.). There's no guarantee of compatibility with any specific system, platform, or setup.
Redistribution and licensing. You can redistribute, modify, and adapt the Lists only under the terms of the open-source license they're published under. It's on you to read, understand, and follow those license terms before using or redistributing anything.
Accepting these terms. By accessing, downloading, or using these DNS blocklists, you agree to everything laid out in this disclaimer.
