Built with 💓 for a safer, cleaner internet. It always looks impossible until someone just goes ahead and does it.
Privacy isn't a crime, so go protect yours. It's what lets you decide who you are and who you want to be
Like this project? If it's helped you out, drop a ⭐ (top right) and join the stargazers club! Every star genuinely helps.
- Overview
- Multi light, hand brush: light protection
- Multi normal, broom: all-round protection
- Multi pro, big broom: extended protection (recommended): Full - Mini
- Multi pro++, sweeper: maximum protection (more aggressive): Full - Mini
- Multi ultimate, ultimate sweeper: aggressive protection: Full - Mini
- Fake, blocks scams, traps, and fake sites!
- Pop-Up Ads, stops annoying and malicious pop-ups!
- Threat Intelligence Feeds, a serious security boost (recommended): Full - Medium - Mini - IPs
- Newly Registered Domains - NRD/DGA, a favorite tool of threat actors for launching attacks!
- DoH/VPN/TOR/Proxy Bypass, stop people from sneaking around your DNS: Full - DoH only - DoH IPs
- Safesearch not supported, block search engines that skip Safesearch!
- Dynamic DNS, guard against dynamic DNS abuse!
- Badware Hoster, guard against malicious hosting services!
- URL Shortener, blocks link/URL shorteners!
- Most Abused TLDs, blocks known shady top-level domains!
- DNS Rebind Protection, stops attackers from pointing domains at your local network!
- Anti Piracy, blocks piracy sites!
- Gambling, blocks gambling content: Full - Medium - Mini
- Social Networks, blocks access to social networks!
- NSFW, blocks adult content!
- Native Tracker, built-in trackers from devices, apps, and OSes
- Recommendation: Which list version should I actually use?
- Online DNS Services: HaGeZi DNS - DNS Bunker
- About: Repository - Referral Domains - Support
- FAQ, frequently asked questions
- Where does the data come from, and how are the lists built?
- Which list version should I use?
- Which format should I use for my ad blocker or DNS server?
- Quick setup guide
- Why aren't referral domains blocked?
- Why aren't CMPs (cookie consent tools) blocked?
- Which lists are available on which DNS services?
- How current is the data, and where can I get it?
- Licensing and liability
- Getting help and reporting issues
- Glossary
- Discussions
- Update Interval/Official Mirrors
- Sources
- Disclaimer
- Contact
This is an all-in-one DNS blocklist that comes in several versions (light, normal, pro, pro++, and ultimate). You can run it standalone, and it works for any region. It blocks ads, affiliate links, trackers, metrics, telemetry, fake sites, phishing, malware, scams, cryptojacking, and other junk. It's built on various source blocklists, but that doesn't mean it's just a pile of lists glued together. Everything here has been optimized and extended so it actually cleans up the internet across the board.
Curious about the sources? Check out: Which sources are used for the lists and how are they compiled?
| Version | Entries | Pro++ | Pro | Nor mal |
Light | Fake | TIF | Nat ive |
PopUp Ads |
Bug Tracker |
|---|---|---|---|---|---|---|---|---|---|---|
| 📗Light | 42550 | 🟢 | 🟨 | 🟨 | ||||||
| 📘Normal | 186566 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 🟨 | |||
| 📒Pro | 222518 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 🟢 | 🟢 | |
| 📙Pro++ | 246594 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 🟢 | 🟢 |
| 📕Ultimate | 271264 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟢 | 🟢 | 🟢 |
🟢 fully includes the list named in the column header 🟨 partially includes the list named in the column header
| Version | Blocking level |
Blocking type |
|---|---|---|
| 📗Light | 📗 📗 | Relaxed |
| 📘Normal | 📘 📘 📘 | Relaxed/Balanced |
| 📒Pro | 📒 📒 📒 📒 | Balanced |
| 📙Pro++ | 📙 📙 📙 📙 📙 📙 | Balanced/Aggressive |
| 📕Ultimate | 📕 📕 📕 📕 📕 📕 📕 | Aggressive |
Hand brush edition. Cleans up the internet and protects your privacy without going overboard. Blocks ads, trackers, metrics, and some badware. Basically a size-optimized version of Multi NORMAL.
Note
Blocking type: Relaxed This version shouldn't cause any real restrictions. Great if there's no admin around to unblock stuff for you, or if your ad blocker chokes on big lists.
Important
Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
Entries: 42550
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Relaxed/Balanced This one mostly won't cause restrictions either. Good pick if you don't have an admin handy to unblock anything.
Important
Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
Entries: 186566
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Big broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Balanced Restrictions here are rare. Works best if you've got an admin nearby who can unblock something if needed. This is my personal go-to recommendation for solid ad blocking with good privacy without much hassle.
Warning
Referral domains (affiliate and tracking links): Most referral domains are still allowed here, but a handful get blocked anyway, mainly ones that double as regular trackers or are commonly tied to scam and spam links. Details: Referral domains
Entries: 222518
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. This only contains domains from the full Pro list that show up on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 57935
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Sweeper edition. This one cleans up the internet aggressively and protects your privacy hard. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Balanced/Aggressive This is the more aggressive sibling of Multi PRO. It might block a few legit domains by mistake, so it's best for experienced users. Ideally have an admin ready to unblock things that break.
Warning
Referral domains (affiliate and tracking links): A handful of referral domains that double as regular trackers are blocked here too. Details: Referral domains
Entries: 246594
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. Contains only domains from the full Pro++ list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 69437
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Ultimate sweeper edition. Strictly cleans up the internet and locks down your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Blocking type: Aggressive This is a stricter version of Multi PRO++. It contains domains that can limit app or website functionality, including some popular trackers that will cause hiccups. Only use this if you know what you're doing, and make sure someone can unblock things when needed.
Warning
Referral domains (affiliate and tracking links): A few referral domains that also act as regular trackers get blocked. Details: Referral domains
Facebook: Ultimate blocks some META trackers, which limits Facebook and Facebook Messenger app functionality. It also blocks WhatsApp's graph trackers, which can mess with avatar creation, the in-app help center, and video effects. Other than that, WhatsApp works fine. If you use META apps alongside Ultimate, unblock these domains as needed: META Tracker
Windows/Xbox: Some Microsoft trackers are blocked too, which can affect things like Windows Spotlight and Xbox Live Achievements Activity History. Check here for details on which domains to unblock for which feature: Microsoft Tracker.
Location and IP trackers: Certain trackers that websites use to pin down your IP or location get blocked. Great for privacy, but it might trigger wrong regional settings, extra CAPTCHAs, or reduced site functionality here and there. These trackers are usually used for hidden analytics and ad targeting.
Anything else: More known quirks are listed here.
Entries: 271264
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. Contains only domains from the full Ultimate list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 84219
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
This blocklist targets fake stores, fake streaming sites, rip-offs, subscription traps, and similar scams.
| Light | Normal | Pro | Pro++ | Ultimate | TIF TIF medium |
|
|---|---|---|---|---|---|---|
| Included in | ❌ | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 |
🟢 yes 🟨 partially ❌ no
Entries: 16974
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Targets pop-up ads that range from annoying to outright malicious.
| Light | Normal | Pro | Pro++ | Ultimate | TIF | |
|---|---|---|---|---|---|---|
| Included in | 🟨 | 🟨 | 🟢 | 🟢 | 🟢 | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 54146
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
This blocklist targets malware, cryptojacking, scams, spam, and phishing. It blocks domains known for spreading malware, running phishing attacks, and hosting command-and-control servers.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | 🟨 | 🟨 | 🟨 | 🟨 |
🟢 yes 🟨 partially ❌ no
Warning
This list is huge and can eat up a lot of memory depending on your ad blocker. If that's an issue, grab the medium or mini version instead.
Entries: 2119183
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard ( |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ (split) |
1️⃣ Link 2️⃣ Link |
Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A medium-sized version of the TIF list, built for ad blockers that struggle with the full-size version. Includes only the most important feeds.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | 🟨 | 🟨 | 🟨 | 🟨 |
🟢 yes 🟨 partially ❌ no
Entries: 439389
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard ( |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A size-optimized version of the TIF Medium list, for ad blockers that even struggle with that one.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | 🟨 | 🟨 | 🟨 | 🟨 |
🟢 yes 🟨 partially ❌ no
Entries: 174889
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
There's also an IPv4 version of this list, in plain IP format for firewalls and AdGuard Home format, which extends the regular TIF list.
Tip
If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
Newly registered domains (NRDs) are a favorite tool for threat actors running phishing, malware, and command-and-control operations, since these domains are easy to throw away and help dodge detection.
There are two variants:
- NRDs: every newly registered domain, no filtering.
- Entropy NRDs/DGAs: only newly registered domains with high entropy, meaning they were likely generated by a Domain Generation Algorithm (DGA). These have a random-looking structure and are commonly used by malware for resilient command-and-control channels.
Warning
These lists are big and resource-heavy. They can spike memory usage and include false positives, since some legit domains are new too. Use with care and whitelist important services if needed.
Caution
Use these at your own risk. NRD lists come as-is, with no guarantees, no support, and no formal process for fixing false positives.
Important
The base data comes from Stamus Labs. Stamus Labs doesn't promise daily updates, so the data can sometimes lag by a few days.
Current status of the data:
- Stamus Labs: 🟢 - Wed, 19 Aug 2026 04:18:45 UTC / 10601791 domains
| Time period |
Entries | Format AdBlock |
Format Domains |
|---|---|---|---|
| 7 days ago to yesterday | 3070996 | Link | Link |
| 14 days ago to 8 days ago | 2753908 | Link | Link |
| 21 days ago to 15 days ago | 2690105 | Link | Link |
| 28 days ago to 22 days ago | 2329226 | Link | Link |
| 35 days ago to 29 days ago | 2698104 | Link | Link |
Note
Want to block NRDs from the last 14 days? Combine the 7-day and 14-day lists. For the last 21 days, add in the 21-day list too, and so on.
Tip
Besides the formats here, NRDs are also available elsewhere:
- Wildcard (Asterisk): Cebeerre/dnsblocklists
Note
These domains are already part of the full NRD list, just filtered down.
| Time period |
Entries | Format AdBlock |
Format Domains |
|---|---|---|---|
| Past 7 days | 609318 | Link | Link |
| Past 14 days | 1193680 | Link | Link |
| Past 30 days | 2438878 | Link | Link |
Blocks common ways to bypass your DNS setup.
Note
To make sure your DNS server is actually the one being used, you'll need to redirect or block standard DNS traffic (TCP/UDP 53) and also block DNS over TLS/QUIC (TCP/UDP 853) outbound.
This list comes in two flavors:
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 16647
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 3371
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
There's also an IPv4 version in plain IP format for firewalls, and an AdGuard Home format.
Tip
If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
Blocks search engines that don't support Safesearch.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 205
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks dynamic DNS services that get abused for phishing campaigns and other shady activity.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 1521
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks known hosting providers that repeatedly host badware through user-uploaded content.
Important
This list blocks the root domains of hosting providers that keep showing up in threat feeds because of malicious subdomains. That means legit sites hosted there will get blocked too, so think it through before using this one.
If you use this list, you're on your own for unblocking any subdomains you actually need.
Caution
Blocking whole hosting providers is overkill for most setups and can break legit services. In high-security environments though, that trade-off might make sense.
| Light | Normal | Pro | Pro++ | Ultimate | TIF | |
|---|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 1238
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
| ControlD | Link | ControlD folder |
Blocks every known URL/link shortener out there.
Warning
Not really meant for everyday setups. Blocking all URL shorteners makes the most sense in high-security environments, since shorteners can hide where a link actually leads and help enable attacks. In lower-risk settings, keeping an eye on things or just being careful usually does the job.
If you use this list, you're on your own for unblocking any domains you actually need.
| Light | Normal | Pro | Pro++ | Ultimate | TIF | |
|---|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 9920
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks the most abused top-level domains, combining data from Cloudflare Radar, Netcraft, and SpamHaus.
Warning
This list blocks entire top-level domains (like *.top, *.shop, *.gdn) that have a bad reputation overall. Yes, that means some legit sites get caught in the crossfire too, but it's really effective against spam, scams, phishing, malware, and other garbage. Know what you're signing up for.
Only well-known, reputable domains that show up on major top lists (Umbrella, Cloudflare, Tranco, Chrome, DomCop, etc.) or are essential for popular apps get considered for exclusion. Illegal domains, including piracy sites, stay blocked no matter what. Anything that doesn't clearly qualify gets reviewed case by case, and if there's no good reason to unblock it, it stays blocked. If you need access to something specific, add it to your personal allowlist.
This selective approach exists because AdGuard and uBlock Origin have technical limits on rule length when using denyallow/domain modifiers. Trying to exclude every legit domain would eventually break important rules, so exclusions have to stay limited and carefully picked.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
| Format | Links | Should be used for |
|---|---|---|
| AdGuard | Link | AdGuard, AdGuard Home |
| uBlock Origin | Link | uBlock Origin, Adblock Plus |
| AdBlock | Link | Pi-hole, TechnitiumDNS Only includes spam TLDs with no exclusions. |
| AdBlock (Aggressive) Allowlist |
Link Link |
Pi-hole, TechnitiumDNS |
| Wildcard Domains Allowlist |
Link Link |
DNSCrypt |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound Only includes spam TLDs with no exclusions. |
| RPZ (Aggressive) |
Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound Includes all spam TLDs, matching the AdGuard/uBlock Origin version without exclusions. |
| ControlD | Link | ControlD folder |
DNS Rebind Protection stops attackers from messing with DNS responses to make a domain point to a private or local IP address. This blocks malicious scripts from using DNS rebinding attacks to reach your internal network.
Important
This only works with AdGuard/AdGuard Home, and it's also selectable in AdGuard DNS. Other DNS blockers may already have their own rebind protection built in.
Since rebind protection blocks anything resolving to a local IP, your internal hostnames might get caught too.
In AdGuard, whitelist your local domains, something like: @@||fritz.box^
| Format | Links | Should be used for |
|---|---|---|
| AdGuard | Link | AdGuard, AdGuard Home |
Blocks sites and services mainly used for illegally distributing copyrighted content.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 42766
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks gambling-related sites.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 456750
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A medium-sized version for ad blockers that have trouble with the full gambling list.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 157183
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
A size-optimized version of the Gambling Medium list. Only contains domains that show up on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 109241
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks social networks like Facebook, Instagram, TikTok, X (formerly Twitter), Snapchat, and others.
Note
This list won't block messaging apps like WhatsApp or streaming platforms like Twitch. It's strictly aimed at classic social networking sites.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 898
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks adult content.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | ❌ | ❌ | ❌ | ❌ | ❌ |
🟢 yes 🟨 partially ❌ no
Entries: 113814
| Format | Links | Should be used for |
|---|---|---|
| Adblock | Link | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam |
| DNSMasq | Link | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk |
Link | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains |
Link | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Link | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
Blocks the native trackers baked into devices, services, and operating systems that quietly track what you do.
| Light | Normal | Pro | Pro++ | Ultimate | |
|---|---|---|---|---|---|
| Included in | 🟨 | 🟨 | 🟨 | 🟨 | 🟢 |
🟢 yes 🟨 partially ❌ no
Important
Native tracker lists cover everything used to monitor user activity, which can occasionally limit functionality too. They're integrated across all the standard tiers (Light, Normal, Pro, Pro++, Ultimate), each at a different blocking level:
- Light through Pro: only block native trackers that won't break functionality, for a smooth experience.
- Pro++ (aggressive): blocks extra native trackers that might cause some restrictions or limit certain features.
- Ultimate: the most thorough option, blocking all native trackers for max privacy.
Pick whichever tier matches how aggressive you want to be about native tracker blocking.
When combining native tracker lists with the standard lists, you might need to manually unblock a specific tracker here or there.
| Device/Service | Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|---|
| Amazon (Devices, Shopping, Video) | Link | Link | Link | Link | Link |
| Apple (iOS, macOS, tvOS) | Link | Link | Link | Link | Link |
| Huawei (Devices) | Link | Link | Link | Link | Link |
| Microsoft (Windows, Office, MSN) | Link | Link | Link | Link | Link |
| Samsung | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) Aggressive | Link | Link | Link | Link | Link |
| LG webOS | Link | Link | Link | Link | Link |
| Roku | Link | Link | Link | Link | Link |
| Vivo | Link | Link | Link | Link | Link |
| OPPO/Realme | Link | Link | Link | Link | Link |
| Xiaomi | Link | Link | Link | Link | Link |
For network-wide DNS blocking, I'd recommend AdGuard Home, Pi-hole, TechnitiumDNS, Blocky (if you're comfortable with advanced setups), adblock-lean (for OpenWrt), or eBlocker.
DNS blockers do a great job protecting your privacy by cutting off trackers, metrics, and telemetry. They can also block most ads, malware, scams, and fake sites, but they can't catch everything since some of that stuff doesn't work through DNS.
That's why I also recommend pairing this with a browser content blocker like AdGuard, uBlock Origin, or Ghostery.
Check out Yokoffing's Recommended Filters for uBlock Origin for good content blocker filter lists.
Don't run your own DNS server at home, or want extra protection for your phone when it's off your home network? These DNS services have you covered.
Which lists are available where:
| Service | Light | Nor mal |
Pro | Pro ++ |
Ulti mate |
TIF | By pass |
Dyn DNS |
Hoster | TLDs | Anti Piracy |
Gam bling |
... |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AdGuard DNS |
❌ | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 |
| ControlD | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 📓 | 📓 | 🟨 | 🟨 | ❌ |
| Rethink DNS |
🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | ❌ | ❌ | ❌ | ❌ |
| DNS warden |
🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
🟨 Included as part of ControlD's native category lists. 📓 Available as a ControlD folder.
On AdGuardDNS you can use:
- Normal, Pro, Pro++, Ultimate
- Threat Intelligence Feeds (TIF), Most Abused TLDs, Badware Hoster, DynDNS, DNS Rebind Protection, URL Shortener
- DoH/VPN/TOR/Proxy Bypass
- Gambling
- Anti Piracy
- Native Tracker (Apple, OPPO & Realme, Samsung, Vivo, Windows/Office, Xiaomi)
- Allowlist Referral
On ControlD you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
Free:
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC | Legacy DNS | Apple |
|---|---|---|---|---|
| Light | https://freedns.controld.com/x-hagezi-light |
x-hagezi-light.freedns.controld.com |
76.76.2.37 76.76.10.37 2606:1a40::37 2606:1a40:1::37 |
Link |
| Normal | https://freedns.controld.com/x-hagezi-normal |
x-hagezi-normal.freedns.controld.com |
76.76.2.40 76.76.10.40 2606:1a40::40 2606:1a40:1::40 |
Link |
| Pro | https://freedns.controld.com/x-hagezi-pro |
x-hagezi-pro.freedns.controld.com |
76.76.2.41 76.76.10.41 2606:1a40::41 2606:1a40:1::41 |
Link |
| Pro Plus | https://freedns.controld.com/x-hagezi-proplus |
x-hagezi-proplus.freedns.controld.com |
76.76.2.42 76.76.10.42 2606:1a40::42 2606:1a40:1::42 |
Link |
| Ultimate | https://freedns.controld.com/x-hagezi-ultimate |
x-hagezi-ultimate.freedns.controld.com |
76.76.2.45 76.76.10.45 2606:1a40::45 2606:1a40:1::45 |
Link |
| TIF | https://freedns.controld.com/x-hagezi-tif |
x-hagezi-tif.freedns.controld.com |
76.76.2.46 76.76.10.46 2606:1a40::46 2606:1a40:1::46 |
Link |
Paid:
Check out Yokoffing's ControlD Config Guide for good ControlD settings.
Automation:
controld-hagezi-sync: automatically syncs HaGeZi folder blocklists to ControlD profiles via API. Supports TOML config, dry-run mode, multi-profile mappings, and daily GitHub Actions syncs.
HaGeZi DNS runs free, non-commercial public resolvers for Europe, mixing privacy and security with minimal restrictions using the Multi Pro and Threat Intelligence Feed lists.
More details in the project repository.
Blocks ads, trackers, analytics, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config |
Recommended for |
|---|---|---|---|---|
| Germany, Falkenstein | DoH/DoH3 | https://root.hagezi.org/dns-query |
Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK |
| DoT/QUIC | root.hagezi.org |
|||
| Do53 | 188.34.161.2102a01:4f8:c17:1c66::1 |
|||
| Germany, Nuremberg | DoH/DoH3 | https://wurzn.hagezi.org/dns-query |
Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | wurzn.hagezi.org |
|||
| Do53 | 159.69.155.942a01:4f8:1c1c:d363::1 |
|||
| Finland, Helsinki | DoH/DoH3 | https://juuri.hagezi.org/dns-query |
Link QR | DK, EE, FI, LT, LV, NO, SE |
| DoT/QUIC | juuri.hagezi.org |
|||
| Do53 | 95.217.163.172a01:4f9:c013:dc4e::1 |
| Location | Protocols | Endpoint/URL | Apple Config |
Recommended for |
|---|---|---|---|---|
| Germany, Nuremberg | DoH/DoH3 | https://ctif.hagezi.org/dns-query |
Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | ctif.hagezi.org |
|||
| Do53 | 162.55.58.402a01:4f8:1c19:6c19::1 |
DNSBUNKER.org is a hardened, privacy-first DNS resolver based in Germany.
| Blocklists | DNS-over-HTTPS/3 | DNS-over-TLS/QUIC | Apple |
|---|---|---|---|
| Pro + TIF | https://dnsbunker.org/dns-query |
dnsbunker.org |
Link |
Public RDNS is a free, no-log recursive resolver for families that uses HaGeZi lists to aggressively block ads, trackers, malware, NSFW content, piracy, gambling, and other unwanted domains.
More info on the project page.
RobinGroppe.de DNS is a free, privacy-focused DNS service. It doesn't log your queries and protects your connection by blocking malware, phishing, and other online threats using the HaGeZi Threat Intelligence Feeds.
On RethinkDNS you can use Light, Normal, Pro, Pro++, Ultimate, TIF, DynDNS, and Badware Hoster.
Note
RethinkDNS only updates its lists once a week.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://sky.rethinkdns.com/1:AAkACAQA |
1-aaeqacaeaa.max.rethinkdns.com |
| Normal + TIF | https://sky.rethinkdns.com/1:AAkACAgA |
1-aaeqacaiaa.max.rethinkdns.com |
| Pro + TIF | https://sky.rethinkdns.com/1:AAoACBAA |
1-aafaacaqaa.max.rethinkdns.com |
| Pro plus + TIF | https://sky.rethinkdns.com/1:AAoACAgA |
1-aafaacaiaa.max.rethinkdns.com |
| Ultimate + TIF | https://sky.rethinkdns.com/1:gAgACABA |
1-qaeaacaaia.max.rethinkdns.com |
On DNSwarden you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://dns.dnswarden.com/00000000000000000000048 |
00000000000000000000048.dns.dnswarden.com |
| Normal + TIF | https://dns.dnswarden.com/00000000000000000000028 |
00000000000000000000028.dns.dnswarden.com |
| Pro + TIF | https://dns.dnswarden.com/00000000000000000000018 |
00000000000000000000018.dns.dnswarden.com |
| Pro plus + TIF | https://dns.dnswarden.com/0000000000000000000000o |
0000000000000000000000o.dns.dnswarden.com |
| Ultimate + TIF | https://dns.dnswarden.com/0000000000000000000000804 |
0000000000000000000000804.dns.dnswarden.com |
OpenBLD.net combines the Pro list with the TIF blocklist.
| Blocklists | DNS-over-HTTPS |
|---|---|
| Pro + TIF | https://ric.openbld.net/dns-query/hagezi |
"If the plan doesn't work, change the plan, not the goal."
There's no place like 127.0.0.1!
These blocklists are built on various sources plus my own denylists and extensions. The goal has always been to avoid false positives as much as possible without giving up effectiveness. Dead entries get pruned regularly to keep the lists lean. Built with 💓 for a safer, cleaner internet.
Every list gets tested against 10,000 websites from the Cisco Umbrella Top 1 million list. I check whether pages load properly, content displays correctly, navigation works, images load, videos play, and so on.
So no, these aren't just random lists stitched together from other sources. They've been optimized and extended to genuinely clean up the internet across every category. Curious how? Check out: Which sources are used and how are the lists compiled?
Here's how each version performed against the 10,000 whotracks.me pages. All pages were opened and fully loaded in batch via Edge with privacy features turned off, and cookies accepted.
| List | Total queries | Blocked queries | % blocked | % gap to light |
|---|---|---|---|---|
| Ultimate | 299646 | 131093 | 43.75 | 12.85 |
| Pro++ | 299646 | 119681 | 39.94 | 9.05 |
| Pro | 299646 | 97508 | 32.54 | 1.65 |
| Normal | 299646 | 93258 | 31.12 | 0.23 |
| Light | 299646 | 92576 | 30.90 | |
| ---- | 299646 | 67888 | 22.66 | -8.24 |
Give it a try, share your feedback, and report anything that should (or shouldn't) be blocked.
The repository gets compressed (reinitialized) every now and then to keep its size in check. Heads up, this invalidates forks and wipes the commit history.
Wondering why referral domains (affiliate and tracking links) aren't blocked? Here's the answer: FAQ on referral domains
If this project has been useful to you, drop a ⭐ (top right) and join the stargazers!
This project only exists because of a genuinely supportive community. It's free for everyone and stays up to date thanks to ongoing care, updates, and contributions from people who actually want to make things better.
Feedback, ideas, domain reports, false-positive reports, whatever you've got, it's all appreciated. Every bit of help, big or small, makes the internet a little safer and cleaner for everyone.
See: Getting help and reporting issues
Thanks for being part of this!
The primary source for all lists is the GitHub repository. The GitHub repository and its two full mirrors, GitLab and Codeberg, are updated in sync, once a day:
| Source | Update frequency |
|---|---|
| GitHub/jsDelivr (primary) | Once a day |
| gitlab.com/hagezi/mirror | Once a day, in sync with GitHub |
| codeberg.org/hagezi/mirror2 | Once a day, in sync with GitHub |
| hagezi-mirror.dnsbunker.org | Every 4 to 8 hours |
Tip
If you need the freshest possible data, use hagezi-mirror.dnsbunker.org. It's connected directly to the build system and receives each new list version as soon as it's built, ahead of the daily GitHub, GitLab, and Codeberg update.
Important
Scope. This disclaimer applies only to these DNS blocklists ("the Lists"). It does not extend to any other services the Provider may separately operate (e.g., public DNS resolvers), which may be subject to their own terms.
No warranty. The Lists are provided free of charge, "as is" and "as available," with no warranty of any kind, express, implied, or statutory. The creator/operator of the Lists ("the Provider") makes no promises about accuracy, completeness, timeliness, reliability, or fitness for any particular purpose. There's no guarantee that every malicious or unwanted domain is covered, and no guarantee that legitimate domains won't get blocked by mistake. The Lists are compiled in part from third-party sources; the Provider does not control and is not responsible for errors originating in those sources.
Assumption of risk. Using the Lists is entirely at your own risk. The Provider disclaims any and all direct, indirect, incidental, or consequential liability for damages arising from using, misusing, or being unable to use the Lists, except where such damages result from willful misconduct or gross negligence on the Provider's part, or from death or personal injury caused by the Provider's negligence.
A supplement, not a substitute. The Lists are meant to be one part of a broader defense-in-depth strategy, not the whole thing. They don't replace your own responsibility to do due diligence, run your own risk assessments, or use additional protections (firewalls, antivirus/EDR, IDS/IPS, etc.). There's no guarantee of compatibility with any specific system, platform, or setup.
No guarantee of availability, fair use. The Lists are a free, personal/community project, made available internationally, and no one is automatically entitled to their continued availability. The Provider may modify, suspend, restrict, or discontinue the Lists (in whole or in part) at any time and for any reason — including excessive query volume, abusive, or disproportionate use — without notice and without liability, and is under no obligation to maintain, update, or continue providing them. The Provider makes reasonable efforts to fix faults once discovered, but does not guarantee any particular response or resolution time.
Redistribution and licensing. The Lists are published under the GNU General Public License v3.0 (GPL-3.0). You may redistribute, modify, and adapt the Lists only under the terms of that license. This disclaimer applies in addition to, and does not replace, the warranty and liability terms already contained in the GPL-3.0 (Sections 15–16). It's on you to read, understand, and follow the license terms before using or redistributing anything.
Governing law. The Provider is based in Germany, and the Lists are made available for international use. This disclaimer is governed by the laws of Germany, without regard to conflict-of-law principles, to the extent permitted by applicable law. Nothing in this disclaimer limits any mandatory consumer-protection rights you may have under the law of your country of residence.
Severability. If any provision of this disclaimer is found invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision will be replaced by a valid one that most closely reflects its intended effect.
Changes to this disclaimer. The Provider may update this disclaimer from time to time. The version published alongside the Lists at the time of your access or use applies. Continued use of the Lists after an update constitutes acceptance of the updated disclaimer.
Accepting these terms. By accessing, downloading, or using these DNS blocklists, you agree to be bound by everything laid out in this disclaimer. If you do not agree, do not access, download, or use the Lists.
