FAQ
August 26, 2026 ยท View on GitHub
A practical guide to how these DNS blocklists get built, which version fits your setup, and why some domains are left unblocked on purpose. If a term looks unfamiliar, check the Glossary at the bottom, it covers terms from this FAQ, the Cheat Sheet, and the main README alike. For a quick, scannable overview of every individual list, see the Cheat Sheet.
Table of Contents
- Where does the data come from, and how are the lists built?
- Which list version should I use?
- Which format should I use for my ad blocker or DNS server?
- Quick setup guide
- Why aren't referral domains blocked?
- Why aren't CMPs (cookie consent tools) blocked?
- Which lists are available on which DNS services?
- How current is the data, and where can I get it?
- Licensing and liability
- Getting help and reporting issues
- How do mini variants, NRD/DGA, and the bypass lists relate to each other?
- Glossary
1. Where does the data come from, and how are the lists built?
These lists aren't just copy-pasted from somewhere else. Each version is built from a mix of core sources, custom extensions, domain categories, Newly Registered Domains (NRDs), and the seven Top 1M lists: Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, and DomCop. False positives and dead domains get cleaned out constantly, and domains the community reports get added too.
On top of that, network logs get reviewed regularly to catch domains worth blocking that haven't made it onto a list yet. The full base list currently sits at around 45 million domains, including entries from the Top 1M lists going back more than 24 months. This combined list also helps figure out which domains are genuinely popular, keeping the blocklists accurate over time instead of frozen in place.
Every list gets tested against a big sample of real websites, to make sure pages, navigation, images, and videos still work like they should.
Want the full list of base sources? Check sources.
2. Which list version should I use?
Pick the version that fits how much technical help you have on hand and how much risk of breakage you're okay with. Rule of thumb: the stricter the list, the more protection you get, but also the higher the odds something you actually wanted to use gets blocked by accident.
The "risk of breakage" ratings below are a general guide, not exact error rates. They just show how aggressively each version filters domains, not a precise false-positive percentage.
| Version | Best for | Risk of breakage |
|---|---|---|
| Light | No admin around to unblock stuff, or an ad blocker that can't handle big lists | Minimal. Built to avoid restrictions almost entirely |
| Normal | Everyday use, same crowd as Light | Low. Restrictions are rare and usually minor |
| Pro | Setups with an admin nearby who can unblock things if needed | Low to moderate. The go-to default for solid privacy without much hassle |
| Pro++ | Experienced users with an admin available | Moderate. Might include some false positives that limit functionality |
| Ultimate | Very experienced users with an admin available | High. Deliberately blocks some popular trackers, which can limit app or website functionality |
Warning
Ultimate comes with a few documented side effects worth knowing before you switch:
- Meta/Facebook: some Meta trackers get blocked, which limits Facebook and Facebook Messenger. WhatsApp's graph trackers are blocked too, affecting avatar creation, the in-app help center, and video effects. Everything else in WhatsApp still works fine.
- Windows/Xbox: some Microsoft trackers get blocked, which affects things like Windows Spotlight and Xbox Live Achievements Activity History.
- Location and IP trackers: blocking these is great for privacy, but it can trigger extra CAPTCHAs, wrong regional settings, or reduced functionality on some sites.
Running into one of these issues? Check the known-unblock lists for Meta and Microsoft, or the general known issues list.
Important
Whenever you can, pair your main list with the Threat Intelligence Feeds (TIF) list for extra protection against malicious domains. This is worth doing at every tier: Light carries next to no TIF-covered domains (the Inclusion Matrix marks it as not included, though a handful of overlapping domains can still turn up), while Normal, Pro, Pro++, and Ultimate already carry some TIF-covered domains as part of their normal build but never the full feed, so adding TIF on top still closes real coverage gaps at every tier. See the Cheat Sheet's Inclusion Matrix for exactly how much overlap exists per tier. If your ad blocker chokes on the full TIF list's size, grab the smaller medium or mini version instead. On AdGuard Home or AdGuard DNS, it's also worth adding Dandelion Sprout's Anti-Malware List. There's also an IPv4 list you can run alongside the TIF full, medium, or mini list.
Extra lists worth adding, depending on your goals:
- Security focus: combine TIF with the Dynamic DNS list (blocks dynamic DNS services often abused for phishing), the Badware Hoster list (blocks hosting providers whose infrastructure gets abused for malware a lot), the Most Abused TLDs list (blocks entire top-level domains with bad reputations, like
.top,.shop, or.gdn), and either the NRD lists for broad coverage of newly registered domains or the DGA lists for a narrower, lower-noise subset, not both at once (see section 11 for how NRD and DGA relate). - Protecting kids: combine the Gambling, Anti Piracy, Safesearch, DoH/VPN/TOR/Proxy Bypass, Social Networks, and NSFW lists. Heads up: the Social Networks list only blocks traditional platforms (Facebook, Instagram, TikTok, X, Snapchat), not messaging apps like WhatsApp or streaming platforms like Twitch.
Note
You usually don't need to add the Fake, Pop-Up Ads, or Native Tracker lists separately, they're already baked in, though coverage varies by version:
- The Fake list (scam shops, fake streaming sites, cost traps) isn't included in Light at all. It's fully included in Normal, Pro, Pro++, Ultimate, and in TIF, TIF medium, and TIF mini.
- The Pop-Up Ads list is only partially covered in Light, Normal, and TIF. It's fully included in Pro, Pro++, and Ultimate.
- The Native Tracker lists (device and app trackers for Amazon, Apple, Huawei, Microsoft, Samsung, TikTok, LG webOS, Roku, Vivo, OPPO/Realme, and Xiaomi) are integrated at three distinct strengths, not just "partial vs full": Light, Normal, and Pro all share the same baseline, blocking only native trackers that won't break functionality. Pro++ adds extra native-tracker blocking on top of that baseline, which can cause some restrictions. Ultimate is the only tier that blocks every native tracker for maximum privacy. Want full native-tracker coverage without moving all the way to Ultimate? Add the specific device lists you actually need on top of your current tier instead.
Two specialized lists sit outside the main tiers and aren't included anywhere by default: URL Shortener (mainly for high-security setups, since it can break legit short links) and DNS Rebind Protection (works with AdGuard, AdGuard Home, and AdGuard DNS, stops attackers from resolving external domains to your local network's private IP addresses). Other DNS blockers may already have their own rebind protection built in, check your tool's documentation first. If you do add this list, whitelist your local hostnames, since anything resolving to a local IP gets caught too, for example @@||fritz.box^ in AdGuard. Only add these two lists if your setup really needs them.
3. Which format should I use for my ad blocker or DNS server?
Every list comes in five formats. Just pick the row that matches your ad blocker or DNS server, the rest all contain the same data, just structured differently for that specific tool.
| Format | Use it with |
|---|---|
| Adblock | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini (see note below on size limits) |
| DNSMasq | DNSMasq (v2.86 or newer), Diversion (v5 or newer) |
| Wildcard (Asterisk) | Blocky (v0.23 or newer), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard (Domains only) | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS v8.40 or newer), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Bind, Knot, PowerDNS, Unbound, and other software supporting Response Policy Zones |
A few lists don't follow this pattern, and a few come with extra technical requirements worth knowing about before you subscribe:
- Little Snitch Mini has a rule-count limit, so it can't handle the larger lists. It's offered for Light, Normal, Fake, Pop-Up Ads, Anti Piracy, Social Networks, Dynamic DNS, Badware Hoster, URL Shortener, Safesearch Not Supported, both Bypass lists, Gambling Medium, Gambling Mini, and every Mini tier (Pro Mini, Pro++ Mini, Ultimate Mini, TIF Mini). It's not offered for the full Pro, Pro++, Ultimate, TIF, TIF Medium, Gambling, or NSFW lists, those are too big for it.
- The full TIF list is too big for AdGuard Mobile for iOS and needs at least 2 GB of RAM in AdGuard Home. Its RPZ version is also split into two files, and you need both. TIF Medium is lighter but still needs at least 1 GB of RAM in AdGuard Home if you're running into limits with the full list.
- Most Abused TLDs comes in AdGuard-specific, uBlock Origin-specific, and RPZ-specific variants instead of the usual five, since it relies on exclusion rules that work differently across tools. It also has an aggressive/allowlist pair for both the AdBlock and Wildcard formats.
- DNS Rebind Protection only works with AdGuard, AdGuard Home, and AdGuard DNS.
- NRD/DGA lists only come as Adblock and plain domain lists.
- The three DoH/VPN/TOR/Proxy Bypass lists build on each other: Bypass Full covers encrypted DNS servers plus VPN/TOR/proxy services, DoH only is the narrower encrypted-DNS-only subset, and DoH IPs is the IPv4 companion specifically for the DoH-only list, not for VPN/TOR/proxy services (which don't resolve to a fixed IP set). Both Bypass Full and DoH only work best paired with a firewall rule that also blocks outbound ports 53 and 853, otherwise devices can still reach unencrypted or TLS-based DNS servers directly.
- DoH IPs and TIF IPs are IP-level lists, so if you run AdGuard Home alongside either one, disable IPv6 resolution in AdGuard Home, otherwise a device can slip past the block by resolving the same server over IPv6 instead.
- Badware Hoster and Most Abused TLDs also ship as a ControlD folder you can import straight into a ControlD profile. Of the two referral lists (see section 5), only the Referral Allowlist has a ControlD folder, the Referral Blocklist doesn't.
- Legacy Subdomain and Host formats aren't part of the five above, they were moved out of the main repository into a separate dns-blocklists-legacy repository. The Subdomains format (the full domain plus every subdomain spelled out) works with older tool versions like Blocky (before v0.23) and Diversion (before v5), plus PersonalBlocklist and pfBlockerNG. The Hosts format (with a compressed variant) works with AdAway, uMatrix, OpenSnitch, DNS66, NetGuard, and plain Linux hosts files. Only a limited set of lists actually exist in these formats: Light, Normal, Pro, Pro++, Ultimate, TIF, the DoH-only bypass list, and the Native Tracker device lists in both formats, plus the two referral lists in Subdomains format only. Everything else, including every Mini variant, Fake, Pop-Up Ads, NRD/DGA, and the specialty lists, was never built out this way. The maintainer's own warning applies: these formats can't reliably catch dynamic or previously unknown subdomains, so treat them as a fallback for tools that specifically need them, not a first choice.
4. Quick setup guide
Here's the fast track to getting protection running, no need to read the rest of the FAQ first.
- Pick a version. Not sure? Start with Pro, it's the go-to recommendation for solid protection without much breakage. Check section 2 if you want a different balance of strictness and risk.
- Figure out your setup. Are you blocking DNS network-wide (Pi-hole, AdGuard Home, TechnitiumDNS, OPNsense) or using a browser content blocker (uBlock Origin, AdGuard browser extension)? Network-wide blocking protects every device on your network, while a browser blocker only covers that one browser.
- Grab the right format. Check section 3 for what your tool expects, then copy the matching list URL from the README into your tool's blocklist or filter subscription settings.
- Add Threat Intelligence Feeds (TIF). Add the TIF list (or its medium/mini version if your tool struggles with size) alongside your main list for extra protection against malware and phishing, no matter which tier you picked.
- No self-hosted DNS server? Use one of the online DNS services instead, they let you turn these lists on without running your own setup.
- Layer on a browser content blocker too. DNS-level blocking catches most ads, trackers, and malware, but not everything, some ads and scripts load from otherwise legit domains. A browser content blocker like uBlock Origin or AdGuard closes that gap. Think of the DNS list as your network-wide baseline and the browser blocker as the fine-tuned layer on top.
- Test it out. Browse normally for a day. If something breaks, check section 2 for known side effects (especially with Pro++ and Ultimate), unblock the specific domain in your tool, and check section 10 if you need to report a false positive or a missed domain.
- Keep it current. These lists update regularly. If your tool doesn't auto-refresh subscribed lists, set a reminder to re-download, and check section 8 if you want the freshest data possible.
5. Why aren't referral domains blocked?
Referral domains are the affiliate and tracking links you often see on deal sites like Slickdeals, in emails, or in search results. They're allowed here on purpose, since they usually only fire when someone clicks a link, not automatically like ads do.
Blocking them would break things like the first result link in a search, and some of these domains double as newsletter unsubscribe links, so blocking them could trap you in unwanted emails instead of freeing you from them.
Here's the breakdown by list version:
- Light and Normal: all referral domains are allowed.
- Pro: most referral domains are still allowed, but a few get blocked if they're mainly used for other tracking or commonly tied to scam or spam links, even if they could technically also be used for link tracking.
- Pro++ and Ultimate: some referral domains that aren't used exclusively for link tracking get blocked, including a handful like
ad.doubleclick.net,adservice.google.*,app.adjust.*, andanalytics.adjust.*. The majority of referral domains that are still used mainly for link tracking stay allowed even at these tiers.
Allowlist (keeps all known link trackers unblocked):
| Format | Link |
|---|---|
| Adblock (AdGuard, AdGuard Home, uBlock Origin, etc.) | Download |
| Adblock (Pi-hole v6+, TechnitiumDNS, etc.) | Download |
| Wildcard domains | Download |
| ControlD folder | Download |
Want to actually block referral domains anyway? (Not recommended.) Use the lists below. It's better to apply these in a browser content blocker like uBlock Origin instead of network-wide at the DNS level, since DNS-level blocking is a lot harder to fine-tune once it's live. Note that this list doesn't have a ControlD folder, only the Allowlist above does.
| Format | Link |
|---|---|
| Adblock | Download |
| Wildcard domains | Download |
6. Why aren't CMPs (cookie consent tools) blocked?
Blocking CMPs network-wide breaks a ton of websites and actually takes away your ability to choose what you're consenting to. In practice, blocking a CMP usually just makes the site assume everything's accepted anyway, since it can no longer show you the consent choice in the first place (see this discussion).
Deciding whether to block or auto-allow a specific CMP is really a job for content blockers with dedicated filter lists, since those tools can tell which sites should be excluded from blocking a given CMP domain and which shouldn't. Take a look at the exclusion lists used by established cookie filter lists and it becomes pretty obvious why blanket DNS-level blocking just doesn't cut it here, it can't make the nuanced, per-site calls that a proper filter list can.
7. Which lists are available on which DNS services?
Not every DNS provider offers every list. Here's what's currently available:
| Service | Light | Nor mal | Pro | Pro ++ | Ulti mate | TIF | By pass | Dyn DNS | Hoster | TLDs | Anti Piracy | Gam bling |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AdGuard DNS | :x: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: |
| ControlD | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :yellow_square: | :yellow_square: | :notebook: | :notebook: | :yellow_square: | :yellow_square: |
| Rethink DNS | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :x: | :x: | :x: |
| DNS warden | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :green_circle: | :x: | :x: | :x: | :x: | :x: | :x: |
Legend:
- :green_circle: Fully available as a native list on that service.
- :x: Not available.
- :yellow_square: Included in ControlD's own native lists for that category, no separate list needed.
- :notebook: Available as a separate ControlD folder.
Note
A few other free services bundle these lists with fixed presets instead of letting you pick individual versions: HaGeZi DNS (EU resolvers running Pro + TIF), DNSBUNKER.org (Pro + TIF), Public RDNS (aggressive, family-safe preset), RobinGroppe.de (TIF only), and OpenBLD.net (Pro + TIF). Heads up: RethinkDNS only updates its copies once a week, so expect a bit of a lag compared to the source repository.
8. How current is the data, and where can I get it?
The primary source for all lists is the GitHub repository. GitHub and its two full mirrors, GitLab and Codeberg, update in sync, once a day:
| Source | Update frequency |
|---|---|
| GitHub/jsDelivr (primary) | Once a day |
| gitlab.com/hagezi/mirror | Once a day, in sync with GitHub |
| codeberg.org/hagezi/mirror2 | Once a day, in sync with GitHub |
| hagezi-mirror.dnsbunker.org | Every 4 to 8 hours |
Tip
Need the freshest data possible? Use hagezi-mirror.dnsbunker.org. It's connected directly to the build system and gets each new list version the moment it's built, ahead of the daily GitHub, GitLab, and Codeberg update.
Note
The GitHub repository occasionally gets compressed and reinitialized to keep its size down. That resets the commit history and invalidates existing forks, worth knowing if you maintain a fork or rely on commit history for tracking changes.
9. Licensing and liability
The lists are published under the GPL-3.0 license, so you can redistribute, modify, or adapt them, but only within the terms of that license. Check the license in the repository before redistributing the lists as part of your own product or service.
The maintainer ("the Provider") publishes the lists as-is, with no warranty of accuracy, completeness, or fitness for any particular purpose, and no guarantee that every malicious domain is caught or that no legitimate domain ever gets blocked by mistake. You use them entirely at your own risk, and the Provider isn't liable for damages from use or misuse, except in cases of willful misconduct, gross negligence, or death/personal injury caused by negligence.
Basically, treat these lists as one layer in a bigger security setup, not a standalone fix. They don't replace firewalls, antivirus or EDR tools, intrusion detection systems, or your own judgment about risk.
This FAQ entry is a plain-language summary and doesn't cover every detail. The Disclaimer section in the repository is the full, legally binding version. If anything here ever conflicts with it, the Disclaimer section governs.
10. Getting help and reporting issues
Found a legitimate domain that got blocked, or spotted one that should be blocked but isn't? Report it through the issue tracker on GitHub. That's the fastest way to get a false positive fixed or a coverage gap closed. You can also reach out by email at support@hagezi.org.
Got general questions or just want to chat? Head to the GitHub Discussions page. There's also a public Matrix support chat if you'd rather talk things through directly. Prefer to reach out personally? support@hagezi.org works too.
11. How do mini variants, NRD/DGA, and the bypass lists relate to each other?
A few lists in this collection sound similar or get recommended together, but they aren't interchangeable and aren't always meant to be combined. Here's how they actually relate.
Mini variants aren't a universal category, each one is a size-optimized cut of exactly one specific list:
- Light is the README's own size-optimized version of Normal ("basically a size-optimized version of Multi NORMAL"), it just isn't named "Normal Mini".
- Pro Mini, Pro++ Mini, and Ultimate Mini are each a cut of that exact tier only, limited to domains that also appear on the Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, or DomCop Top 1M/10M lists.
- TIF Mini is a cut of TIF Medium, not the full TIF list directly.
- Gambling Mini is a cut of Gambling Medium, not the full Gambling list directly.
- Light has no further mini version of its own, it's already the leanest tier in the Multi family.
Tip
Pick the mini version of the tier you actually want. Grabbing a random "mini" list without matching it to your target tier defeats the purpose, since each one only contains that specific tier's domains, shrunk down.
NRD and DGA are two alternatives, not two ingredients to combine. DGA domains are already part of the full NRD list, just filtered down to the high-entropy subset likely generated by malware. Pick full NRD for broader coverage with more noise, or DGA alone for a narrower, lower-noise subset, not both at once.
NRD and DGA also split their day ranges differently, and the README treats them differently too:
- The full NRD list is split into five files, each covering a distinct, non-overlapping window: 7 days ago to yesterday, 14 days ago to 8 days ago, 21 days ago to 15 days ago, 28 days ago to 22 days ago, and 35 days ago to 29 days ago. The README says explicitly that these bands are meant to be stacked: "Want to block NRDs from the last 14 days? Combine the 7-day and 14-day lists." Want 21 days? Add the 21-day list too, and so on.
- The DGA list is split into just three files: Past 7 days, Past 14 days, and Past 30 days. The README doesn't give the same explicit combining instruction for DGA that it gives for NRD. Based on the standard meaning of "past X days" (a rolling window counting back from today, not a separate slice like NRD's bands), Past 30 days should already contain everything in Past 14 days and Past 7 days. Going by that reading, picking the single DGA file that matches how far back you want to go makes more sense than combining them, since stacking dga7 with dga14 or dga30 would likely just add duplicate domains, but this part is an inference from the naming, not a rule stated outright in the README.
The three DoH/VPN/TOR/Proxy Bypass lists build on each other:
- Bypass Full covers encrypted DNS servers plus VPN, TOR, and proxy services, the broadest of the three.
- DoH only is the narrower encrypted-DNS-only subset.
- DoH IPs is the IPv4 companion specifically for the DoH-only list, not for VPN/TOR/proxy services, since those don't resolve to a fixed, enumerable IP set the same way encrypted DNS servers do.
12. Glossary
This glossary covers unfamiliar terms from this FAQ, the Cheat Sheet, and the main README, since all three documents share it.
| Term | What it means |
|---|---|
| Adblock format | One of the formats these lists come in. Looks like classic ad blocker filter rules and works with tools like Pi-hole, AdGuard, AdGuard Home, and uBlock Origin. |
| AdGuard / AdGuard Home / AdGuard DNS | Three different things with confusingly similar names. AdGuard is a browser extension or app that only protects that one browser or device. AdGuard Home is a separate DNS server you run yourself, often on something like a Raspberry Pi, protecting every device on your network at once. AdGuard DNS is neither of those, it's a hosted public DNS resolver you can point your devices at without running any server yourself, similar in role to ControlD, RethinkDNS, or DNSwarden. |
| Admin (network admin) | Whoever manages the DNS server or router setup and can manually unblock a domain if a blocklist accidentally breaks something. Some list versions assume you have one on hand, others are built so you don't need one. |
| Allowlist (whitelist) | The opposite of a blocklist. Domains here always get through, even if a blocklist would otherwise catch them. |
| Blocklist (denylist) | A list of domains that get blocked so they can't load, usually to stop ads, trackers, or malware. |
| C2 server (command-and-control server) | A server attackers use to remotely control malware already running on infected devices. Threat Intelligence Feeds specifically target the domains these servers rely on. |
| Cisco Umbrella Top 1M | A ranking of the top 1 million most-visited domains, published by Cisco. It's the same Umbrella list referenced under "Top 1M list" below, just doing double duty here: it's one of the seven build-source lists this project uses, and it's also the basis for the roughly 10,000-page set the lists have been tested against, to check that pages, navigation, images, and videos still work correctly, the same set also gets referenced through whotracks.me (see below). |
| Cloudflare Radar / Netcraft / SpamHaus | Three separate threat-intelligence sources whose combined data feeds the Most Abused TLDs list, per the README. Cloudflare Radar tracks internet traffic and abuse trends, Netcraft specializes in phishing and fraud detection, and SpamHaus maintains reputation blocklists for spam and malware sources, that's general background on each provider, not something the README itself spells out. Together they're how the project identifies which top-level domains (like .top or .gdn) have unusually bad reputations. Note that Cloudflare Radar is a different product from the plain "Cloudflare" ranking mentioned under "Top 1M list" below, one is a threat/traffic dashboard, the other is a domain-popularity ranking. |
| CMP (Consent Management Platform/Provider) | The tech behind cookie consent pop-ups on websites, letting visitors choose what data a site can collect about them. Common examples include OneTrust, Cookiebot, and Usercentrics. |
| ControlD folder | A ControlD-specific feature for grouping custom rules into a reusable set you can apply across profiles. |
| Crash/error tracker | Software development tools like Bugsnag, Crashlytics, Firebase, Instabug, and Sentry that apps use to automatically report crashes and bugs back to developers. They're a form of telemetry, so blocking them is a privacy feature, but the earliest tiers (Light, Normal) leave them unblocked to stay as compatible as possible. Pro is the first tier to block them. |
| Cryptojacking | When a website or app secretly uses your device's processing power to mine cryptocurrency in the background, usually without you noticing anything besides a slower device and a bigger power bill. |
| Defense-in-depth | A security strategy that layers multiple independent protections on top of each other, so if one layer fails, the others still catch the problem. These blocklists are meant to be one layer in that kind of setup, not a complete solution on their own, see section 9 and the repository's Disclaimer for how that plays out here. |
| Denyallow / domain modifier | A rule type in filter lists used to carve out exceptions from a blocking rule. These modifiers have a technical length limit, so you can't cram unlimited exceptions into one rule, that's why exclusion lists sometimes stay short on purpose. |
| DGA (Domain Generation Algorithm) | A technique malware uses to automatically generate tons of random-looking domains on the fly, making it harder for defenders to block all of them in advance. This project's DGA lists come as three files (Past 7, 14, and 30 days). Reading "past X days" the normal way, they overlap rather than stack, so picking one instead of combining them makes more sense, though the README doesn't spell this out the way it does for NRD, see section 11. |
| DNS (Domain Name System) | The system that translates website names, like example.com, into the numeric IP addresses computers use to find each other. Every blocklist works by intercepting these translations for unwanted domains. |
| DNS rebind protection | A safeguard against DNS rebinding attacks, where an attacker tricks a public domain into suddenly pointing at a private, local IP address to sneak into your home network. Available for AdGuard, AdGuard Home, and AdGuard DNS. Some other DNS blockers already have their own version of this built in, worth checking before you add a separate list. |
| DNS resolver | The server that actually performs the DNS lookup for your device, sometimes also called a recursive resolver. AdGuard DNS, ControlD, RethinkDNS, and DNSwarden are all examples of resolvers that support these blocklists. |
| DNSMasq | A lightweight, widely used piece of software for DNS and DHCP, often running on routers or small home servers. One of the five formats these lists come in is built specifically for it. |
| Do53 | The classic, unencrypted way of doing DNS, over port 53. The name literally means "DNS over port 53", as opposed to encrypted options like DoH or DoT. |
| DoH / DoT (DNS-over-HTTPS / DNS-over-TLS) | Methods of encrypting DNS traffic so it can't be read or tampered with in transit. DoT typically runs over port 853, which is why some bypass lists recommend also blocking that port at the firewall. These encrypted methods can also bypass DNS-level blocklists by routing around your configured resolver, which is why a dedicated bypass list exists. |
| DoH3 / DoQ | Newer variants of encrypted DNS that run over QUIC instead of the older TCP-based connection, making lookups faster. Some DNS providers offer this as an extra connection option alongside regular DoH. |
| Dynamic DNS (DynDNS) | A service that gives a constantly changing IP address (common with home internet connections) a fixed, memorable domain name. Frequently abused for phishing campaigns, which is why there's a dedicated blocklist for it. |
| EDR (Endpoint Detection and Response) | A category of security software that watches individual devices for suspicious behavior and can respond automatically, more advanced than classic antivirus. Another extra protection layer these blocklists complement rather than replace. |
| Entropy / high-entropy | A measure of how random or unpredictable a string of characters looks. A domain like xj4k9qz2.com has high entropy, since there's no readable pattern to it, while a domain like news-site.com has low entropy. Malware-generated domains tend to be high-entropy, which is exactly what the DGA lists filter for. |
| False positive | A domain that gets mistakenly blocked even though it isn't actually harmful or unwanted, usually breaking a website or app feature. |
| Filter subscription | The setting in an ad blocker or DNS tool where you paste a blocklist's URL so the tool automatically downloads and keeps that list current, instead of you updating it by hand. |
| Fingerprinting | A tracking method that combines lots of small technical details about your device or browser to recognize you again, without needing a classic cookie. |
| GPL-3.0 | The GNU General Public License, version 3, an open-source license that allows redistribution and modification of the licensed material, as long as any redistributed or modified version is also published under the same license terms. |
| IDS/IPS (Intrusion Detection/Prevention System) | Security tools that watch network traffic for attack patterns. An IDS just flags suspicious activity, an IPS can actively block it. Another example of the extra protection layers these blocklists don't replace on their own. |
| IPv4 / IPv6 | Two versions of the internet protocol that hand out IP addresses. IPv4 uses the older, shorter-style addresses, IPv6 the newer, much longer ones. Some blocklists also ship as plain IP lists, since a domain could otherwise slip past a domain-only block by resolving over IPv6. |
| jsDelivr | A free content delivery network (CDN) that mirrors files straight from GitHub and npm onto a fast global server network. Links with @latest always point to the newest version of a file. Since jsDelivr caches everything, it keeps serving files even if GitHub is temporarily down, which is why the project uses jsDelivr links for some of its lists. |
| Legacy formats (Subdomains/Hosts) | Two older list formats that moved out of the main repository into a separate dns-blocklists-legacy repository. Subdomains works with tools like older Blocky/Diversion versions, PersonalBlocklist, and pfBlockerNG. Hosts (plus a compressed variant) works with AdAway, uMatrix, OpenSnitch, DNS66, NetGuard, and plain Linux hosts files. Only a limited set of lists exist in these formats, see section 3 for exactly which ones. |
| List tiers (Light/Normal/Pro/Pro++/Ultimate) | The five main strictness levels these blocklists come in, from Light (barely any restrictions) up to Ultimate (blocks aggressively, including some popular trackers). Each step up means more blocking power but also a higher chance something you actually wanted breaks. |
| Little Snitch Mini | A lightweight macOS/iOS firewall app. It has a rule-count limit, so it only supports the smaller lists in this collection, not the full-size Pro, Pro++, Ultimate, TIF, TIF Medium, Gambling, or NSFW lists, see section 3 for the full breakdown. |
| Malware | An umbrella term for malicious software of all kinds, viruses, trojans, spyware, you name it, that infects a device, steals data, or lets someone else control it remotely. |
| Mirror | An exact copy of a project hosted elsewhere, for example on GitLab or Codeberg instead of GitHub. Acts as a backup source in case the main one is ever unreachable. |
| Native tracker | Trackers baked directly into devices, apps, or operating systems, think Amazon, Apple, Samsung, or Windows. They run quietly in the background collecting usage data, no matter which website you're actually visiting. Coverage builds up in three steps across the tiers: Light, Normal, and Pro share the same baseline, Pro++ adds extra blocking on top of that, and Ultimate is the only tier with full coverage, see section 2 for the breakdown. |
| Network-wide blocking | Blocking domains for every device on a network at once, phones, laptops, smart TVs, everything, typically by changing the DNS server for the whole router. The opposite of a browser-only blocker, which only protects the browser it's installed in. |
| NRD (Newly Registered Domain) | A domain registered very recently, typically within the last 14 to 30 days. Threat actors often use fresh domains for scams or malware since they haven't been flagged by security tools yet. The underlying data for this project's NRD lists comes from Stamus Labs (see below). The full NRD list is split into five non-overlapping day-range files, and the README explicitly says to stack them for broader coverage, unlike DGA's files, which read as overlapping windows rather than bands, see section 11. |
| OpenWrt | An open-source, Linux-based firmware for routers, popular for advanced home-networking setups. adblock-lean, one of the network-wide DNS blockers this project points to, is built specifically to run on OpenWrt. |
| Phishing | Scam attempts where fake websites or messages try to trick you into handing over passwords, banking details, or other sensitive info. |
| Pi-hole | A popular, free, open-source tool for running your own DNS server at home that blocks ads and trackers network-wide, commonly installed on a Raspberry Pi. |
| QUIC | A newer, UDP-based network protocol that sets up connections faster and encrypts them more efficiently than classic TCP. It's the foundation behind DoH3 and DoQ. |
| Referral domain | A domain used in affiliate or tracking links, commonly found on deal websites, in emails, and in search results. These typically only activate when a link is clicked, unlike ad domains, which load automatically. |
| Root domain | The base part of a domain name without any subdomains, like example.com in shop.example.com or cdn.example.com. Some blocklists, like Badware Hoster, deliberately block at the root domain level, which means every subdomain underneath gets blocked too, including any legitimate ones hosted on the same provider. |
| RPZ (Response Policy Zone) | A DNS server feature (used by Bind, Knot, PowerDNS, and Unbound) that lets a resolver apply blocklists directly at the server level, instead of through a separate ad-blocking app. |
| Scam / fake shop | Fraudulent websites posing as fake online stores, bogus streaming sites, or hidden subscription traps, all designed to grab your money or your data. |
| Stamus Labs | A threat-research team whose data feeds this project's NRD (Newly Registered Domain) lists. They don't guarantee same-day updates, so the underlying NRD data can occasionally lag by a few days. |
| TIF (Threat Intelligence Feeds) | A list built from security research sources that tracks domains actively known to be involved in malware, phishing, command-and-control servers, or other live threats. Worth adding on top of any tier, since none of the tiers include the full feed, see section 2. |
| TLD (Top-Level Domain) | The last segment of a domain name, like .com, .net, or a country code like .de. Some TLDs, like .top, .shop, or .gdn, get abused for spam or scams way more often than others. |
| Top 1M list | A ranking of the one million most-visited domains on the internet, used to identify which domains are genuinely popular and worth extra trust. Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, and DomCop each publish their own version, and all seven feed into this project's base sources and mini variants (Umbrella also doubles as the project's testing benchmark, see "Cisco Umbrella Top 1M" above). |
| Tranco | A research-oriented ranking of the top million websites, built by averaging several other popularity rankings over a 30-day period, making it more stable and harder to manipulate than a single-source ranking. |
| uBlock Origin | A free, open-source ad and content blocker that runs as a browser extension. Works at the browser level, adding finer-grained filtering on top of a network-wide DNS blocklist. |
| VPN/TOR/Proxy bypass | Techniques that reroute traffic outside the local network's normal DNS path, which can accidentally or deliberately skip past blocklists. |
| whotracks.me | A public research project that catalogs tracker and privacy data gathered from real websites. The roughly 10,000-page set the project's lists have been tested against (see "Cisco Umbrella Top 1M" above) is cross-referenced through whotracks.me's own site list, so both names point to essentially the same benchmark. |
| Wildcard (Asterisk) format | One of the two wildcard formats these lists come in. Each entry is written with a placeholder asterisk, like *.example.com, so a single line covers the domain and all its subdomains without listing them one by one. Used by tools like Blocky, Nebulo, NetDuma, OPNsense, and YogaDNS. |
| Wildcard (Domains only) format | The other wildcard format. Each entry is just the plain domain name, like example.com, with no asterisk, since these tools already treat a listed domain as covering all its subdomains automatically. Used by tools like DNSCloak, DNSCrypt, FRITZ!Box, TechnitiumDNS, adblock-lean, PersonalDNSfilter, and InviZible Pro. |