Skip to content

Repository files navigation

License: GPL-3.0GitHub last commitGitHub issuesGitHub closed issuesGitHub repo sizeshields.io Stars

⚡ DNS Blocklists, let's make the internet a nicer place!

Built with 💓 for a safer, cleaner internet. It always looks impossible until someone just goes ahead and does it.

Privacy isn't a crime, so go protect yours. It's what lets you decide who you are and who you want to be ‼️

Like this project? If it's helped you out, drop a ⭐ (top right) and join the stargazers club! Every star genuinely helps.

What this is: a set of DNS blocklists that block ads, trackers, telemetry, phishing, malware, scams, and other unwanted domains network-wide. They work for any region and with every common DNS server, ad blocker, and content blocker.

New here? Start with Multi PRO plus the Threat Intelligence Feeds list, pick the format that matches your tool, and follow the quick setup guide. Unsure which version fits you? See which list version should I use.


📑 Table of Contents

  1. Overview: Which format do I need?
  2. Multi LIGHT, hand brush: basic protection
  3. Multi NORMAL, broom: all-round protection
  4. Multi PRO, big broom: extended protection (recommended): Full - Mini
  5. Multi PRO++, sweeper: maximum protection (more aggressive): Full - Mini
  6. Multi ULTIMATE, ultimate sweeper: aggressive protection: Full - Mini
  7. Fake, block scams, traps, and fake sites!
  8. Pop-Up Ads, stop annoying and malicious pop-ups!
  9. Threat Intelligence Feeds, a serious security boost (recommended): Full - Medium - Mini - IPs
  10. Newly Registered Domains (NRD/DGA), a favorite tool of threat actors for launching attacks!
  11. DoH/VPN/TOR/Proxy Bypass, stop people from sneaking around your DNS: Full - DoH only - DoH IPs
  12. Safesearch not supported, block search engines that skip Safesearch!
  13. Dynamic DNS (DynDNS), guard against dynamic DNS abuse!
  14. Badware Hoster, guard against malicious hosting services!
  15. URL Shortener, block link shorteners!
  16. Most Abused TLDs, block known shady top-level domains!
  17. DNS Rebind Protection, stop attackers from pointing domains at your local network!
  18. Anti Piracy, block piracy sites!
  19. Gambling, block gambling content: Full - Medium - Mini
  20. Social Networks, block access to social networks!
  21. NSFW, block adult content!
  22. Native Tracker, block built-in trackers from devices, apps, and OSes!
  23. Blocklists Cheat Sheet, quick reference table for every list at a glance
  24. Recommendation: Which list version should I actually use?
  25. Online DNS Services: HaGeZi DNS - DNS Bunker
  26. About: Repository - Referral Domains - Support
  27. FAQ, frequently asked questions, including the quick setup guide and the glossary
  28. Discussions
  29. Update Interval/Official Mirrors
  30. Sources
  31. Disclaimer
  32. Contact

📚 Multi, cleans up the internet and protects your privacy!

This is an all-in-one DNS blocklist that comes in several versions (light, normal, pro, pro++, and ultimate). You can run it standalone, and it works for any region. It blocks ads, affiliate links, trackers, metrics, telemetry, fake sites, phishing, malware, scams, cryptojacking, and other junk. It's built on various source blocklists, but that doesn't mean it's just a pile of lists glued together. Everything here has been optimized and extended so it actually cleans up the internet across the board.

Curious about the sources? Check out: Which sources are used for the lists and how are they compiled?

Blocklist versions and sizes at a glance:

Version Entries Light Normal Pro Pro++ Fake TIF Nat
ive
PopUp
Ads
Error
Tracker
📗Light 41865 🟢 🟨 🟨
📘Normal 190873 🟢 🟢 🟢 🟨 🟨 🟨
📒Pro 226870 🟢 🟢 🟢 🟢 🟨 🟨 🟢 🟢
📙Pro++ 251363 🟢 🟢 🟢 🟢 🟢 🟨 🟨 🟢 🟢
📕Ultimate 271045 🟢 🟢 🟢 🟢 🟢 🟨 🟢 🟢 🟢
  • 🟢 fully includes the list named in the column header
  • 🟨 partially includes the list named in the column header
  • (empty cell) does not include the list named in the column header

Ultimate has no column of its own, since it's the top tier and no other version contains it.

For a full inclusion matrix that also covers the standalone lists, see the Cheat Sheet.

Blocking intensity:

Version Blocking type Risk of breakage
📗Light Relaxed Minimal
📘Normal Relaxed/Balanced Low
📒Pro Balanced Low to moderate
📙Pro++ Balanced/Aggressive Moderate
📕Ultimate Aggressive High

Each version is named after a cleaning tool, which is where the "hand brush", "broom", and "sweeper" wording in the sections below comes from: Light is the hand brush, Normal the broom, Pro the big broom, Pro++ the sweeper, and Ultimate the ultimate sweeper. The bigger the tool, the more thoroughly it cleans, and the more likely it is to sweep up something you wanted to keep.

Which format do I need?

Every list below is published in the same five formats. Pick the row that matches your tool, the content is identical, only the structure differs.

Format Use it with
Adblock Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini (smaller lists only)
DNSMasq DNSMasq (v2.86+), Diversion (v5+)
Wildcard Asterisk Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS
Wildcard Domains DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro
RPZ Response Policy Zone, Bind, Knot, PowerDNS, Unbound

The legacy Subdomains and Hosts formats live in a separate repository. For the complete format-to-tool breakdown, see the FAQ.


📗 Multi LIGHT, basic protection

Hand brush edition. Cleans up the internet and protects your privacy without going overboard. Blocks ads, trackers, metrics, and some badware. Basically a size-optimized version of Multi NORMAL, built only from domains that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop). That's also why the Fake list isn't part of Light: fake shops and fake streaming sites generally don't rank on those lists in the first place.

Note

This version shouldn't cause any real restrictions. Great if there's no admin around to unblock stuff for you, or if your ad blocker chokes on big lists.

Important

Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.

Entries: 41865

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📘 Multi NORMAL, all-round protection

Broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.

Note

This one mostly won't cause restrictions either. Good pick if you don't have an admin handy to unblock anything.

Important

Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.

Entries: 190873

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📒 Multi PRO, extended protection (recommended)

Big broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.

Note

Restrictions here are rare. Works best if you've got an admin nearby who can unblock something if needed. This is my personal go-to recommendation for solid ad blocking with good privacy without much hassle.

Warning

Referral domains (affiliate and tracking links): Most referral domains are still allowed here, but a handful get blocked anyway, mainly ones that double as regular trackers or are commonly tied to scam and spam links. Details: Referral domains

Entries: 226870

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📒 Multi PRO mini (best for browser/mobile ad blockers)

A size-optimized version made for DNS or browser blockers, like devices with limited RAM. This only contains domains from the full Pro list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).

Entries: 56926

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📙 Multi PRO++, maximum protection

Sweeper edition. This one cleans up the internet aggressively and protects your privacy hard. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.

Note

This is the more aggressive sibling of Multi PRO. It might block a few legit domains by mistake, so it's best for experienced users. Ideally have an admin ready to unblock things that break.

Warning

Referral domains (affiliate and tracking links): More referral domains get blocked than in Pro, specifically the ones that aren't used exclusively for link tracking. The bulk of the category still stays allowed. Details: Referral domains

Entries: 251363

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📙 Multi PRO++ mini

Built the same way as Pro mini, but from the full Pro++ list: only its domains that appear on the Top 1M/10M lists make the cut. For DNS or browser blockers on limited hardware.

Entries: 68533

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📕 Multi ULTIMATE, aggressive protection

Ultimate sweeper edition. Strictly cleans up the internet and locks down your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.

Note

This is a stricter version of Multi PRO++. It contains domains that can limit app or website functionality, including some popular trackers that will cause hiccups. Only use this if you know what you're doing, and make sure someone can unblock things when needed.

Warning

Referral domains (affiliate and tracking links): Same as Pro++: referral domains that aren't used exclusively for link tracking are blocked, the rest of the category stays allowed. Details: Referral domains

Facebook: Ultimate blocks some META trackers, which limits Facebook and Facebook Messenger app functionality. It also blocks WhatsApp's graph trackers, which can mess with avatar creation, the in-app help center, and video effects. Other than that, WhatsApp works fine. If you use META apps alongside Ultimate, unblock these domains as needed: META Tracker

Windows/Xbox: Some Microsoft trackers are blocked too, which can affect things like Windows Spotlight and Xbox Live Achievements Activity History. Check here for details on which domains to unblock for which feature: Microsoft Tracker.

Location and IP trackers: Certain trackers that websites use to pin down your IP or location get blocked. Great for privacy, but it might trigger wrong regional settings, extra CAPTCHAs, or reduced site functionality here and there. These trackers are usually used for hidden analytics and ad targeting.

Anything else: More known quirks are listed here.

Entries: 271045

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📕 Multi ULTIMATE mini

Built the same way as Pro mini, but from the full Ultimate list: only its domains that appear on the Top 1M/10M lists make the cut. For DNS or browser blockers on limited hardware.

Entries: 79658

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

:trollface: Fake, blocks scams, traps, and fake sites!

This blocklist targets fake stores, fake streaming sites, rip-offs, subscription traps, and similar scams.

Entries: 17284

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🎉 Pop-Up Ads, stops annoying and malicious pop-ups!

Targets pop-up ads that range from annoying to outright malicious.

Entries: 54178

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🔐 Threat Intelligence Feeds, a serious security boost (recommended)

This blocklist targets malware, cryptojacking, scams, spam, and phishing. It blocks domains known for spreading malware, running phishing attacks, and hosting command-and-control servers.

Warning

This list is huge and can eat up a lot of memory depending on your ad blocker. If that's an issue, grab the medium or mini version instead. It's too big for the iOS AdGuard mobile app, and AdGuard Home needs at least 2 GB RAM. The RPZ version had to be split into two files because of its size, you need both.

Entries: 2167242

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
(split)
Link Link Link Link 1️⃣ Link
2️⃣ Link

🔐 Threat Intelligence Feeds, medium version (best for browser/mobile ad blockers)

A medium-sized version of the TIF list, built for ad blockers that struggle with the full-size version. Includes only the most important feeds.

Warning

Too big for the iOS AdGuard mobile app. AdGuard Home needs at least 1 GB RAM.

Entries: 331321

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🔐 Threat Intelligence Feeds, mini version

A size-optimized version of the TIF Medium list, for ad blockers that even struggle with that one.

Entries: 176834

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🔐 Threat Intelligence Feeds, IPs

There's also an IPv4 version of this list, in plain IP format for firewalls and AdGuard Home format, which extends the regular TIF list.

Tip

If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home: Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses


🆕 Newly Registered Domains (NRD/DGA)

Newly registered domains (NRDs) are a favorite tool for threat actors running phishing, malware, and command-and-control operations, since these domains are easy to throw away and help dodge detection.

There are two variants:

  • NRDs: every newly registered domain, no filtering.
  • Entropy NRDs/DGAs: only newly registered domains with high entropy, meaning they were likely generated by a Domain Generation Algorithm (DGA). These have a random-looking structure and are commonly used by malware for resilient command-and-control channels.

Warning

These lists are big and resource-heavy. They can spike memory usage and include false positives, since some legit domains are new too. Use with care and whitelist important services if needed.

Caution

Use these at your own risk. NRD lists come as-is, with no guarantees, no support, and no formal process for fixing false positives.

Important

The base data comes from Stamus Labs. Stamus Labs doesn't promise daily updates, so the data can sometimes lag by a few days.

Current status of the data:

  • Stamus Labs: 🟢 - Sat, 29 Aug 2026 04:25:59 UTC / 10888781 domains

🆕 NRDs: all newly registered domains, unfiltered

Time
period
Entries Format
Adblock
Format
Domains
7 days ago to yesterday 2708008 Link Link
14 days ago to 8 days ago 2930214 Link Link
21 days ago to 15 days ago 2703429 Link Link
28 days ago to 22 days ago 2864733 Link Link
35 days ago to 29 days ago 2370684 Link Link

Note

The five files are non-overlapping bands, so stack them for wider coverage: nrd7 plus nrd14-8 covers the last 14 days, add nrd21-15 for 21 days, and so on.

Tip

Besides the formats here, NRDs are also available elsewhere:

🔠 Entropy NRDs/DGAs: only newly registered, high-entropy domains generated by DGAs

Note

These domains are already part of the full NRD list, just filtered down.

Time
period
Entries Format
Adblock
Format
Domains
Past 7 days 517158 Link Link
Past 14 days 1088259 Link Link
Past 30 days 2455768 Link Link

📤 DoH/VPN/TOR/Proxy Bypass, stop people from sneaking around your DNS!

Blocks common ways to bypass your DNS setup.

Note

To make sure your DNS server is actually the one being used, you'll need to redirect or block standard DNS traffic (TCP/UDP 53) and also block DNS over TLS/QUIC (TCP/UDP 853) outbound.

This list comes in two flavors:

📤 Complete edition: encrypted DNS servers, VPN, TOR, proxies

Entries: 16718

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📤 Encrypted DNS servers only

Entries: 3367

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📤 Encrypted DNS server IPs

There's also an IPv4 version in plain IP format for firewalls, and an AdGuard Home format.

Tip

If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home: Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses


🔍 Safesearch not supported, blocks search engines that skip Safesearch!

Blocks search engines that don't support Safesearch.

Entries: 205

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🔏 Dynamic DNS (DynDNS), guards against dynamic DNS abuse!

Blocks dynamic DNS services that get abused for phishing campaigns and other shady activity.

Entries: 1540

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

💻 Badware Hoster, guards against malicious hosting services!

Blocks known hosting providers that repeatedly host badware through user-uploaded content.

Important

This list blocks the root domains of hosting providers that keep showing up in threat feeds because of malicious subdomains. That means legit sites hosted there will get blocked too, so think it through before using this one.

If you use this list, you're on your own for unblocking any subdomains you actually need.

Caution

Blocking whole hosting providers is overkill for most setups and can break legit services. In high-security environments though, that trade-off might make sense.

Entries: 1238

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ ControlD
Link Link Link Link Link Link

🔗 URL Shortener, blocks link shorteners!

Blocks every known URL/link shortener out there.

Warning

Not really meant for everyday setups. Blocking all URL shorteners makes the most sense in high-security environments, since shorteners can hide where a link actually leads and help enable attacks. In lower-risk settings, keeping an eye on things or just being careful usually does the job.

If you use this list, you're on your own for unblocking any domains you actually need.

Entries: 9922

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🔮 Most Abused TLDs, blocks known shady top-level domains!

Blocks the most abused top-level domains, combining data from Cloudflare Radar, Netcraft, and SpamHaus.

Warning

This list blocks entire top-level domains (like *.top, *.shop, *.gdn) that have a bad reputation overall. Yes, that means some legit sites get caught in the crossfire too, but it's really effective against spam, scams, phishing, malware, and other garbage. Know what you're signing up for.

Only well-known, reputable domains that show up on major top lists (Umbrella, Cloudflare, Tranco, Chrome, DomCop, etc.) or are essential for popular apps get considered for exclusion. Illegal domains, including piracy sites, stay blocked no matter what. Anything that doesn't clearly qualify gets reviewed case by case, and if there's no good reason to unblock it, it stays blocked. If you need access to something specific, add it to your personal allowlist.

This selective approach exists because AdGuard and uBlock Origin have technical limits on rule length when using denyallow/domain modifiers. Trying to exclude every legit domain would eventually break important rules, so exclusions have to stay limited and carefully picked.

This list doesn't follow the usual five-format pattern, since the exclusion rules work differently from tool to tool.

Format Link Notes
AdGuard Link For AdGuard and AdGuard Home
uBlock Origin Link For uBlock Origin and Adblock Plus
Adblock Link For Pi-hole and TechnitiumDNS. Spam TLDs with no exclusions
Adblock
(Aggressive)
+ Allowlist
Link
Link
For Pi-hole and TechnitiumDNS. Use both together
Wildcard
Domains
+ Allowlist
Link
Link
For DNSCrypt. Use both together
RPZ Link Spam TLDs with no exclusions
RPZ
(Aggressive)
Link All spam TLDs, matching the AdGuard and uBlock Origin versions
ControlD Link Importable ControlD folder

🛡️ DNS Rebind Protection, stops attackers from pointing domains at your local network!

DNS Rebind Protection stops attackers from messing with DNS responses to make a domain point to a private or local IP address. This blocks malicious scripts from using DNS rebinding attacks to reach your internal network.

Important

This only works with AdGuard/AdGuard Home, and it's also selectable in AdGuard DNS. Other DNS blockers may already have their own rebind protection built in.

Since rebind protection blocks anything resolving to a local IP, your internal hostnames might get caught too. In AdGuard, whitelist your local domains, something like: @@||fritz.box^

Format Link
AdGuard Link

💀 Anti Piracy, blocks piracy sites!

Blocks sites and services mainly used for illegally distributing copyrighted content.

Entries: 45775

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🎰 Gambling, blocks gambling content!

Blocks gambling-related sites.

Entries: 472115

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🎰 Gambling, medium version

A medium-sized version for ad blockers that have trouble with the full gambling list.

Entries: 152312

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🎰 Gambling, mini version

A size-optimized version of the Gambling Medium list. Only contains domains that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).

Entries: 99165

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

💬 Social Networks, blocks access to social networks!

Blocks social networks like Facebook, Instagram, TikTok, X (formerly Twitter), Snapchat, and others.

Note

This list won't block messaging apps like WhatsApp or streaming platforms like Twitch. It's strictly aimed at classic social networking sites.

Entries: 902

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

🔞 NSFW, blocks adult content!

Blocks adult content.

Entries: 114339

Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Link Link Link Link Link

📲 Native Tracker, blocks built-in trackers from devices, apps, and OSes!

Blocks the native trackers baked into devices, services, and operating systems that quietly track what you do.

Important

Native tracker lists cover everything used to monitor user activity, which can occasionally limit functionality too. They're integrated across all the standard tiers (Light, Normal, Pro, Pro++, Ultimate), each at a different blocking level:

  • Light through Pro: only block native trackers that won't break functionality, for a smooth experience.
  • Pro++ (aggressive): blocks extra native trackers that might cause some restrictions or limit certain features.
  • Ultimate: the most thorough option, blocking all native trackers for max privacy.

Pick whichever tier matches how aggressive you want to be about native tracker blocking.

When combining native tracker lists with the standard lists, you might need to manually unblock a specific tracker here or there.

Device/Service Adblock DNSMasq Wildcard
Asterisk
Wildcard
Domains
RPZ
Amazon (Devices, Shopping, Video) Link Link Link Link Link
Apple (iOS, macOS, tvOS) Link Link Link Link Link
Huawei (Devices) Link Link Link Link Link
Microsoft (Windows, Office, MSN) Link Link Link Link Link
Samsung Link Link Link Link Link
TikTok (Fingerprinting) Link Link Link Link Link
TikTok (Fingerprinting) Aggressive Link Link Link Link Link
LG webOS Link Link Link Link Link
Roku Link Link Link Link Link
Vivo Link Link Link Link Link
OPPO/Realme Link Link Link Link Link
Xiaomi Link Link Link Link Link

💡 Recommendation

For network-wide DNS blocking, I'd recommend AdGuard Home, Pi-hole, TechnitiumDNS, Blocky (if you're comfortable with advanced setups), adblock-lean (for OpenWrt), or eBlocker.

DNS blockers do a great job protecting your privacy by cutting off trackers, metrics, and telemetry. They can also block most ads, malware, scams, and fake sites, but they can't catch everything since some of that stuff doesn't work through DNS.

That's why I also recommend pairing this with a browser content blocker like AdGuard, uBlock Origin, or Ghostery.

Check out Yokoffing's Recommended Filters for uBlock Origin for good content blocker filter lists.


🏬 Online DNS Services

Don't run your own DNS server at home, or want extra protection for your phone when it's off your home network? These DNS services have you covered.

Which lists are available where:

The services in this matrix let you pick individual lists. The ones further down (HaGeZi DNS, DNSBUNKER.org, Public RDNS, RobinGroppe.de, OpenBLD.net) run fixed list combinations instead, so they aren't part of it.

List AdGuard DNS ControlD RethinkDNS DNSwarden
Light 🟢 🟢 🟢
Normal 🟢 🟢 🟢 🟢
Pro 🟢 🟢 🟢 🟢
Pro++ 🟢 🟢 🟢 🟢
Ultimate 🟢 🟢 🟢 🟢
TIF 🟢 🟢 🟢 🟢
Bypass 🟢 🟨 🟢
Dynamic DNS 🟢 🟨 🟢
Badware Hoster 🟢 📓 🟢
Most Abused TLDs 🟢 📓
Anti Piracy 🟢 🟨
Gambling 🟢 🟨
All other lists 🟢
  • 🟢 Fully available as a native list on that service.
  • ❌ Not available.
  • 🟨 Included as part of ControlD's native category lists, no separate list needed.
  • 📓 Available as a separate ControlD folder.

🏬 AdGuardDNS, limited free / unlimited trial / paid

On AdGuardDNS you can use:

  • Normal, Pro, Pro++, Ultimate
  • Threat Intelligence Feeds (TIF), Most Abused TLDs, Badware Hoster, DynDNS, DNS Rebind Protection, URL Shortener
  • DoH/VPN/TOR/Proxy Bypass
  • Gambling
  • Anti Piracy
  • Native Tracker (Apple, OPPO & Realme, Samsung, Vivo, Windows/Office, Xiaomi)
  • Allowlist Referral

🏬 ControlD, free / paid

On ControlD you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.

Free:

Blocklists DNS-over-HTTPS DNS-over-TLS/QUIC Legacy DNS Apple
Light https://freedns.controld.com/x-hagezi-light x-hagezi-light.freedns.controld.com 76.76.2.37
76.76.10.37
2606:1a40::37
2606:1a40:1::37
Link
Normal https://freedns.controld.com/x-hagezi-normal x-hagezi-normal.freedns.controld.com 76.76.2.40
76.76.10.40
2606:1a40::40
2606:1a40:1::40
Link
Pro https://freedns.controld.com/x-hagezi-pro x-hagezi-pro.freedns.controld.com 76.76.2.41
76.76.10.41
2606:1a40::41
2606:1a40:1::41
Link
Pro Plus https://freedns.controld.com/x-hagezi-proplus x-hagezi-proplus.freedns.controld.com 76.76.2.42
76.76.10.42
2606:1a40::42
2606:1a40:1::42
Link
Ultimate https://freedns.controld.com/x-hagezi-ultimate x-hagezi-ultimate.freedns.controld.com 76.76.2.45
76.76.10.45
2606:1a40::45
2606:1a40:1::45
Link
TIF https://freedns.controld.com/x-hagezi-tif x-hagezi-tif.freedns.controld.com 76.76.2.46
76.76.10.46
2606:1a40::46
2606:1a40:1::46
Link

Paid:

Check out Yokoffing's ControlD Config Guide for good ControlD settings.

Automation:

controld-hagezi-sync: automatically syncs HaGeZi folder blocklists to ControlD profiles via API. Supports TOML config, dry-run mode, multi-profile mappings, and daily GitHub Actions syncs.

🏬 HaGeZi DNS (EU: Germany/Finland, balanced blocking), free

HaGeZi DNS runs free, non-commercial public resolvers for Europe, mixing privacy and security with minimal restrictions using the Multi Pro and Threat Intelligence Feed lists.

More details in the project repository.

Blocks ads, trackers, analytics, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other harmful domains:

Location Protocols Endpoint/URL Apple
Config
Recommended for
Germany, Falkenstein DoH/DoH3 https://root.hagezi.org/dns-query Link QR AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK
DoT/QUIC root.hagezi.org
Do53 188.34.161.210
2a01:4f8:c17:1c66::1
Germany, Nuremberg DoH/DoH3 https://wurzn.hagezi.org/dns-query Link QR AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA
DoT/QUIC wurzn.hagezi.org
Do53 159.69.155.94
2a01:4f8:1c1c:d363::1
Finland, Helsinki DoH/DoH3 https://juuri.hagezi.org/dns-query Link QR DK, EE, FI, LT, LV, NO, SE
DoT/QUIC juuri.hagezi.org
Do53 95.217.163.17
2a01:4f9:c013:dc4e::1

Blocks ONLY phishing, malware, scams, fakes, cryptojacking, and other harmful domains:

Location Protocols Endpoint/URL Apple
Config
Recommended for
Germany, Nuremberg DoH/DoH3 https://ctif.hagezi.org/dns-query Link QR AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA
DoT/QUIC ctif.hagezi.org
Do53 162.55.58.40
2a01:4f8:1c19:6c19::1

🏬 DNSBUNKER.org (EU: Germany, balanced blocking), free

DNSBUNKER.org is a hardened, privacy-first DNS resolver based in Germany.

Blocklists DNS-over-HTTPS/3 DNS-over-TLS/QUIC Apple
Pro + TIF https://dnsbunker.org/dns-query dnsbunker.org Link

🏬 Public RDNS (EU: Finland, family-safe, aggressive blocking), free

Public RDNS is a free, no-log recursive resolver for families that uses HaGeZi lists to aggressively block ads, trackers, malware, NSFW content, piracy, gambling, and other unwanted domains.

More info on the project page.

🏬 RobinGroppe.de (EU: Germany, threat blocking), free

RobinGroppe.de DNS is a free, privacy-focused DNS service. It doesn't log your queries and protects your connection by blocking malware, phishing, and other online threats using the HaGeZi Threat Intelligence Feeds.

🏬 RethinkDNS, free

On RethinkDNS you can use Light, Normal, Pro, Pro++, Ultimate, TIF, Bypass, DynDNS, and Badware Hoster.

Note

RethinkDNS only updates its lists once a week.

Blocklists DNS-over-HTTPS DNS-over-TLS/QUIC
Light + TIF https://sky.rethinkdns.com/1:AAkACAQA 1-aaeqacaeaa.max.rethinkdns.com
Normal + TIF https://sky.rethinkdns.com/1:AAkACAgA 1-aaeqacaiaa.max.rethinkdns.com
Pro + TIF https://sky.rethinkdns.com/1:AAoACBAA 1-aafaacaqaa.max.rethinkdns.com
Pro plus + TIF https://sky.rethinkdns.com/1:AAoACAgA 1-aafaacaiaa.max.rethinkdns.com
Ultimate + TIF https://sky.rethinkdns.com/1:gAgACABA 1-qaeaacaaia.max.rethinkdns.com

🏬 DNSwarden, free

On DNSwarden you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.

Blocklists DNS-over-HTTPS DNS-over-TLS/QUIC
Light + TIF https://dns.dnswarden.com/00000000000000000000048 00000000000000000000048.dns.dnswarden.com
Normal + TIF https://dns.dnswarden.com/00000000000000000000028 00000000000000000000028.dns.dnswarden.com
Pro + TIF https://dns.dnswarden.com/00000000000000000000018 00000000000000000000018.dns.dnswarden.com
Pro plus + TIF https://dns.dnswarden.com/0000000000000000000000o 0000000000000000000000o.dns.dnswarden.com
Ultimate + TIF https://dns.dnswarden.com/0000000000000000000000804 0000000000000000000000804.dns.dnswarden.com

🏬 OpenBLD.net, free

OpenBLD.net combines the Pro list with the TIF blocklist.

Blocklists DNS-over-HTTPS
Pro + TIF https://ric.openbld.net/dns-query/hagezi

📢 About

"If the plan doesn't work, change the plan, not the goal."
There's no place like 127.0.0.1!

These blocklists are built on various sources plus my own denylists and extensions. The goal has always been to avoid false positives as much as possible without giving up effectiveness. Dead entries get pruned regularly to keep the lists lean. Built with 💓 for a safer, cleaner internet.

Every list gets tested against 10,000 websites from the Cisco Umbrella Top 1 million list. I check whether pages load properly, content displays correctly, navigation works, images load, videos play, and so on.

So no, these aren't just random lists stitched together from other sources. They've been optimized and extended to genuinely clean up the internet across every category. Curious how? Check out: Which sources are used and how are the lists compiled?

Here's how each version performed against that same 10,000-page set, which is also cross-referenced through whotracks.me. All pages were opened and fully loaded in batch via Edge with privacy features turned off, and cookies accepted.

List Total queries Blocked queries % blocked % gap to light
Ultimate 299646 131093 43.75 12.85
Pro++ 299646 119681 39.94 9.05
Pro 299646 97508 32.54 1.65
Normal 299646 93258 31.12 0.23
Light 299646 92576 30.90
---- 299646 67888 22.66 -8.24

Give it a try, share your feedback, and report anything that should (or shouldn't) be blocked.

:octocat: Repository

The repository gets compressed (reinitialized) every now and then to keep its size in check. Heads up, this invalidates forks and wipes the commit history.

🌀 Referral Domains

Wondering how referral domains (affiliate and tracking links) are handled? Here's the answer: FAQ on referral domains

💫 Support

This project only exists because of a genuinely supportive community. It's free for everyone and stays up to date thanks to ongoing care, updates, and contributions from people who actually want to make things better.

Feedback, ideas, domain reports, false-positive reports, whatever you've got, it's all appreciated. Every bit of help, big or small, makes the internet a little safer and cleaner for everyone.

See: Getting help and reporting issues

Thanks for being part of this!


💾 Update Interval/Official Mirrors

The primary source for all lists is the GitHub repository. The GitHub repository and its two full mirrors, GitLab and Codeberg, are updated in sync, once a day:

Source Update frequency
GitHub/jsDelivr (primary) Once a day
gitlab.com/hagezi/mirror Once a day, in sync with GitHub
codeberg.org/hagezi/mirror2 Once a day, in sync with GitHub
hagezi-mirror.dnsbunker.org Every 4 to 8 hours

Tip

If you need the freshest possible data, use hagezi-mirror.dnsbunker.org. It's connected directly to the build system and receives each new list version as soon as it's built, ahead of the daily GitHub, GitLab, and Codeberg update.


⚠️ Disclaimer

Important

Scope. This disclaimer applies only to these DNS blocklists ("the Lists"). It does not extend to any other services the Provider may separately operate (e.g., public DNS resolvers), which may be subject to their own terms.

No warranty. The Lists are provided free of charge, "as is" and "as available," with no warranty of any kind, express, implied, or statutory. The creator/operator of the Lists ("the Provider") makes no promises about accuracy, completeness, timeliness, reliability, or fitness for any particular purpose. There's no guarantee that every malicious or unwanted domain is covered, and no guarantee that legitimate domains won't get blocked by mistake. The Lists are compiled in part from third-party sources; the Provider does not control and is not responsible for errors originating in those sources.

Assumption of risk. Using the Lists is entirely at your own risk. The Provider disclaims any and all direct, indirect, incidental, or consequential liability for damages arising from using, misusing, or being unable to use the Lists, except where such damages result from willful misconduct or gross negligence on the Provider's part, or from death or personal injury caused by the Provider's negligence.

A supplement, not a substitute. The Lists are meant to be one part of a broader defense-in-depth strategy, not the whole thing. They don't replace your own responsibility to do due diligence, run your own risk assessments, or use additional protections (firewalls, antivirus/EDR, IDS/IPS, etc.). There's no guarantee of compatibility with any specific system, platform, or setup.

No guarantee of availability, fair use. The Lists are a free, personal/community project, made available internationally, and no one is automatically entitled to their continued availability. The Provider may modify, suspend, restrict, or discontinue the Lists (in whole or in part) at any time and for any reason, including excessive query volume or abusive or disproportionate use, without notice and without liability, and is under no obligation to maintain, update, or continue providing them. The Provider makes reasonable efforts to fix faults once discovered, but does not guarantee any particular response or resolution time.

Redistribution and licensing. The Lists are published under the GNU General Public License v3.0 (GPL-3.0). A copy of the license is also included in each repository or mirror distributing the Lists. You may redistribute, modify, and adapt the Lists only under the terms of that license. This disclaimer applies in addition to, and does not replace, the warranty and liability terms already contained in the GPL-3.0 (Sections 15 to 16). It's on you to read, understand, and follow the license terms before using or redistributing anything.

Governing law. The Provider is based in Germany, and the Lists are made available for international use. This disclaimer is governed by the laws of Germany, without regard to conflict-of-law principles, to the extent permitted by applicable law. Nothing in this disclaimer limits any mandatory consumer-protection rights you may have under the law of your country of residence.

Severability. If any provision of this disclaimer is found invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision will be replaced by a valid one that most closely reflects its intended effect.

Changes to this disclaimer. The Provider may update this disclaimer from time to time. The version published alongside the Lists at the time of your access or use applies. Continued use of the Lists after an update constitutes acceptance of the updated disclaimer.

Accepting these terms. By accessing, downloading, or using these DNS blocklists, you agree to be bound by everything laid out in this disclaimer. If you do not agree, do not access, download, or use the Lists.


Keep the internet clean!


https://gafam.info


Mail Matrix Signal


Releases

Used by

Contributors

Languages