Built with 💓 for a safer, cleaner internet. It always looks impossible until someone just goes ahead and does it.
Privacy isn't a crime, so go protect yours. It's what lets you decide who you are and who you want to be
Like this project? If it's helped you out, drop a ⭐ (top right) and join the stargazers club! Every star genuinely helps.
What this is: a set of DNS blocklists that block ads, trackers, telemetry, phishing, malware, scams, and other unwanted domains network-wide. They work for any region and with every common DNS server, ad blocker, and content blocker.
New here? Start with Multi PRO plus the Threat Intelligence Feeds list, pick the format that matches your tool, and follow the quick setup guide. Unsure which version fits you? See which list version should I use.
- Overview: Which format do I need?
- Multi LIGHT, hand brush: basic protection
- Multi NORMAL, broom: all-round protection
- Multi PRO, big broom: extended protection (recommended): Full - Mini
- Multi PRO++, sweeper: maximum protection (more aggressive): Full - Mini
- Multi ULTIMATE, ultimate sweeper: aggressive protection: Full - Mini
- Fake, block scams, traps, and fake sites!
- Pop-Up Ads, stop annoying and malicious pop-ups!
- Threat Intelligence Feeds, a serious security boost (recommended): Full - Medium - Mini - IPs
- Newly Registered Domains (NRD/DGA), a favorite tool of threat actors for launching attacks!
- DoH/VPN/TOR/Proxy Bypass, stop people from sneaking around your DNS: Full - DoH only - DoH IPs
- Safesearch not supported, block search engines that skip Safesearch!
- Dynamic DNS (DynDNS), guard against dynamic DNS abuse!
- Badware Hoster, guard against malicious hosting services!
- URL Shortener, block link shorteners!
- Most Abused TLDs, block known shady top-level domains!
- DNS Rebind Protection, stop attackers from pointing domains at your local network!
- Anti Piracy, block piracy sites!
- Gambling, block gambling content: Full - Medium - Mini
- Social Networks, block access to social networks!
- NSFW, block adult content!
- Native Tracker, block built-in trackers from devices, apps, and OSes!
- Blocklists Cheat Sheet, quick reference table for every list at a glance
- Recommendation: Which list version should I actually use?
- Online DNS Services: HaGeZi DNS - DNS Bunker
- About: Repository - Referral Domains - Support
- FAQ, frequently asked questions, including the quick setup guide and the glossary
- Discussions
- Update Interval/Official Mirrors
- Sources
- Disclaimer
- Contact
This is an all-in-one DNS blocklist that comes in several versions (light, normal, pro, pro++, and ultimate). You can run it standalone, and it works for any region. It blocks ads, affiliate links, trackers, metrics, telemetry, fake sites, phishing, malware, scams, cryptojacking, and other junk. It's built on various source blocklists, but that doesn't mean it's just a pile of lists glued together. Everything here has been optimized and extended so it actually cleans up the internet across the board.
Curious about the sources? Check out: Which sources are used for the lists and how are they compiled?
| Version | Entries | Light | Normal | Pro | Pro++ | Fake | TIF | Nat ive |
PopUp Ads |
Error Tracker |
|---|---|---|---|---|---|---|---|---|---|---|
| 📗Light | 41865 | 🟢 | 🟨 | 🟨 | ||||||
| 📘Normal | 190873 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 🟨 | |||
| 📒Pro | 226870 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 🟢 | 🟢 | |
| 📙Pro++ | 251363 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟨 | 🟢 | 🟢 |
| 📕Ultimate | 271045 | 🟢 | 🟢 | 🟢 | 🟢 | 🟢 | 🟨 | 🟢 | 🟢 | 🟢 |
- 🟢 fully includes the list named in the column header
- 🟨 partially includes the list named in the column header
- (empty cell) does not include the list named in the column header
Ultimate has no column of its own, since it's the top tier and no other version contains it.
For a full inclusion matrix that also covers the standalone lists, see the Cheat Sheet.
| Version | Blocking type | Risk of breakage |
|---|---|---|
| 📗Light | Relaxed | Minimal |
| 📘Normal | Relaxed/Balanced | Low |
| 📒Pro | Balanced | Low to moderate |
| 📙Pro++ | Balanced/Aggressive | Moderate |
| 📕Ultimate | Aggressive | High |
Each version is named after a cleaning tool, which is where the "hand brush", "broom", and "sweeper" wording in the sections below comes from: Light is the hand brush, Normal the broom, Pro the big broom, Pro++ the sweeper, and Ultimate the ultimate sweeper. The bigger the tool, the more thoroughly it cleans, and the more likely it is to sweep up something you wanted to keep.
Every list below is published in the same five formats. Pick the row that matches your tool, the content is identical, only the structure differs.
| Format | Use it with |
|---|---|
| Adblock | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini (smaller lists only) |
| DNSMasq | DNSMasq (v2.86+), Diversion (v5+) |
| Wildcard Asterisk | Blocky (v0.23+), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS >= v8.40), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Response Policy Zone, Bind, Knot, PowerDNS, Unbound |
The legacy Subdomains and Hosts formats live in a separate repository. For the complete format-to-tool breakdown, see the FAQ.
Hand brush edition. Cleans up the internet and protects your privacy without going overboard. Blocks ads, trackers, metrics, and some badware. Basically a size-optimized version of Multi NORMAL, built only from domains that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop). That's also why the Fake list isn't part of Light: fake shops and fake streaming sites generally don't rank on those lists in the first place.
Note
This version shouldn't cause any real restrictions. Great if there's no admin around to unblock stuff for you, or if your ad blocker chokes on big lists.
Important
Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
Entries: 41865
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
This one mostly won't cause restrictions either. Good pick if you don't have an admin handy to unblock anything.
Important
Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
Entries: 190873
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Big broom edition. Cleans up the internet and protects your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
Restrictions here are rare. Works best if you've got an admin nearby who can unblock something if needed. This is my personal go-to recommendation for solid ad blocking with good privacy without much hassle.
Warning
Referral domains (affiliate and tracking links): Most referral domains are still allowed here, but a handful get blocked anyway, mainly ones that double as regular trackers or are commonly tied to scam and spam links. Details: Referral domains
Entries: 226870
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. This only contains domains from the full Pro list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 56926
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Sweeper edition. This one cleans up the internet aggressively and protects your privacy hard. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
This is the more aggressive sibling of Multi PRO. It might block a few legit domains by mistake, so it's best for experienced users. Ideally have an admin ready to unblock things that break.
Warning
Referral domains (affiliate and tracking links): More referral domains get blocked than in Pro, specifically the ones that aren't used exclusively for link tracking. The bulk of the category still stays allowed. Details: Referral domains
Entries: 251363
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Built the same way as Pro mini, but from the full Pro++ list: only its domains that appear on the Top 1M/10M lists make the cut. For DNS or browser blockers on limited hardware.
Entries: 68533
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Ultimate sweeper edition. Strictly cleans up the internet and locks down your privacy. Blocks ads, affiliate links, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
Note
This is a stricter version of Multi PRO++. It contains domains that can limit app or website functionality, including some popular trackers that will cause hiccups. Only use this if you know what you're doing, and make sure someone can unblock things when needed.
Warning
Referral domains (affiliate and tracking links): Same as Pro++: referral domains that aren't used exclusively for link tracking are blocked, the rest of the category stays allowed. Details: Referral domains
Facebook: Ultimate blocks some META trackers, which limits Facebook and Facebook Messenger app functionality. It also blocks WhatsApp's graph trackers, which can mess with avatar creation, the in-app help center, and video effects. Other than that, WhatsApp works fine. If you use META apps alongside Ultimate, unblock these domains as needed: META Tracker
Windows/Xbox: Some Microsoft trackers are blocked too, which can affect things like Windows Spotlight and Xbox Live Achievements Activity History. Check here for details on which domains to unblock for which feature: Microsoft Tracker.
Location and IP trackers: Certain trackers that websites use to pin down your IP or location get blocked. Great for privacy, but it might trigger wrong regional settings, extra CAPTCHAs, or reduced site functionality here and there. These trackers are usually used for hidden analytics and ad targeting.
Anything else: More known quirks are listed here.
Entries: 271045
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Built the same way as Pro mini, but from the full Ultimate list: only its domains that appear on the Top 1M/10M lists make the cut. For DNS or browser blockers on limited hardware.
Entries: 79658
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
This blocklist targets fake stores, fake streaming sites, rip-offs, subscription traps, and similar scams.
Entries: 17284
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Targets pop-up ads that range from annoying to outright malicious.
Entries: 54178
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
This blocklist targets malware, cryptojacking, scams, spam, and phishing. It blocks domains known for spreading malware, running phishing attacks, and hosting command-and-control servers.
Warning
This list is huge and can eat up a lot of memory depending on your ad blocker. If that's an issue, grab the medium or mini version instead. It's too big for the iOS AdGuard mobile app, and AdGuard Home needs at least 2 GB RAM. The RPZ version had to be split into two files because of its size, you need both.
Entries: 2167242
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ (split) |
|---|---|---|---|---|
| Link | Link | Link | Link | 1️⃣ Link 2️⃣ Link |
A medium-sized version of the TIF list, built for ad blockers that struggle with the full-size version. Includes only the most important feeds.
Warning
Too big for the iOS AdGuard mobile app. AdGuard Home needs at least 1 GB RAM.
Entries: 331321
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
A size-optimized version of the TIF Medium list, for ad blockers that even struggle with that one.
Entries: 176834
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
There's also an IPv4 version of this list, in plain IP format for firewalls and AdGuard Home format, which extends the regular TIF list.
Tip
If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
Newly registered domains (NRDs) are a favorite tool for threat actors running phishing, malware, and command-and-control operations, since these domains are easy to throw away and help dodge detection.
There are two variants:
- NRDs: every newly registered domain, no filtering.
- Entropy NRDs/DGAs: only newly registered domains with high entropy, meaning they were likely generated by a Domain Generation Algorithm (DGA). These have a random-looking structure and are commonly used by malware for resilient command-and-control channels.
Warning
These lists are big and resource-heavy. They can spike memory usage and include false positives, since some legit domains are new too. Use with care and whitelist important services if needed.
Caution
Use these at your own risk. NRD lists come as-is, with no guarantees, no support, and no formal process for fixing false positives.
Important
The base data comes from Stamus Labs. Stamus Labs doesn't promise daily updates, so the data can sometimes lag by a few days.
Current status of the data:
- Stamus Labs: 🟢 - Sat, 29 Aug 2026 04:25:59 UTC / 10888781 domains
| Time period |
Entries | Format Adblock |
Format Domains |
|---|---|---|---|
| 7 days ago to yesterday | 2708008 | Link | Link |
| 14 days ago to 8 days ago | 2930214 | Link | Link |
| 21 days ago to 15 days ago | 2703429 | Link | Link |
| 28 days ago to 22 days ago | 2864733 | Link | Link |
| 35 days ago to 29 days ago | 2370684 | Link | Link |
Note
The five files are non-overlapping bands, so stack them for wider coverage: nrd7 plus nrd14-8 covers the last 14 days, add nrd21-15 for 21 days, and so on.
Tip
Besides the formats here, NRDs are also available elsewhere:
- Wildcard (Asterisk): Cebeerre/dnsblocklists
Note
These domains are already part of the full NRD list, just filtered down.
| Time period |
Entries | Format Adblock |
Format Domains |
|---|---|---|---|
| Past 7 days | 517158 | Link | Link |
| Past 14 days | 1088259 | Link | Link |
| Past 30 days | 2455768 | Link | Link |
Blocks common ways to bypass your DNS setup.
Note
To make sure your DNS server is actually the one being used, you'll need to redirect or block standard DNS traffic (TCP/UDP 53) and also block DNS over TLS/QUIC (TCP/UDP 853) outbound.
This list comes in two flavors:
Entries: 16718
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Entries: 3367
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
There's also an IPv4 version in plain IP format for firewalls, and an AdGuard Home format.
Tip
If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
Blocks search engines that don't support Safesearch.
Entries: 205
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks dynamic DNS services that get abused for phishing campaigns and other shady activity.
Entries: 1540
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks known hosting providers that repeatedly host badware through user-uploaded content.
Important
This list blocks the root domains of hosting providers that keep showing up in threat feeds because of malicious subdomains. That means legit sites hosted there will get blocked too, so think it through before using this one.
If you use this list, you're on your own for unblocking any subdomains you actually need.
Caution
Blocking whole hosting providers is overkill for most setups and can break legit services. In high-security environments though, that trade-off might make sense.
Entries: 1238
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ | ControlD |
|---|---|---|---|---|---|
| Link | Link | Link | Link | Link | Link |
Blocks every known URL/link shortener out there.
Warning
Not really meant for everyday setups. Blocking all URL shorteners makes the most sense in high-security environments, since shorteners can hide where a link actually leads and help enable attacks. In lower-risk settings, keeping an eye on things or just being careful usually does the job.
If you use this list, you're on your own for unblocking any domains you actually need.
Entries: 9922
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks the most abused top-level domains, combining data from Cloudflare Radar, Netcraft, and SpamHaus.
Warning
This list blocks entire top-level domains (like *.top, *.shop, *.gdn) that have a bad reputation overall. Yes, that means some legit sites get caught in the crossfire too, but it's really effective against spam, scams, phishing, malware, and other garbage. Know what you're signing up for.
Only well-known, reputable domains that show up on major top lists (Umbrella, Cloudflare, Tranco, Chrome, DomCop, etc.) or are essential for popular apps get considered for exclusion. Illegal domains, including piracy sites, stay blocked no matter what. Anything that doesn't clearly qualify gets reviewed case by case, and if there's no good reason to unblock it, it stays blocked. If you need access to something specific, add it to your personal allowlist.
This selective approach exists because AdGuard and uBlock Origin have technical limits on rule length when using denyallow/domain modifiers. Trying to exclude every legit domain would eventually break important rules, so exclusions have to stay limited and carefully picked.
This list doesn't follow the usual five-format pattern, since the exclusion rules work differently from tool to tool.
| Format | Link | Notes |
|---|---|---|
| AdGuard | Link | For AdGuard and AdGuard Home |
| uBlock Origin | Link | For uBlock Origin and Adblock Plus |
| Adblock | Link | For Pi-hole and TechnitiumDNS. Spam TLDs with no exclusions |
| Adblock (Aggressive) + Allowlist |
Link Link |
For Pi-hole and TechnitiumDNS. Use both together |
| Wildcard Domains + Allowlist |
Link Link |
For DNSCrypt. Use both together |
| RPZ | Link | Spam TLDs with no exclusions |
| RPZ (Aggressive) |
Link | All spam TLDs, matching the AdGuard and uBlock Origin versions |
| ControlD | Link | Importable ControlD folder |
DNS Rebind Protection stops attackers from messing with DNS responses to make a domain point to a private or local IP address. This blocks malicious scripts from using DNS rebinding attacks to reach your internal network.
Important
This only works with AdGuard/AdGuard Home, and it's also selectable in AdGuard DNS. Other DNS blockers may already have their own rebind protection built in.
Since rebind protection blocks anything resolving to a local IP, your internal hostnames might get caught too.
In AdGuard, whitelist your local domains, something like: @@||fritz.box^
| Format | Link |
|---|---|
| AdGuard | Link |
Blocks sites and services mainly used for illegally distributing copyrighted content.
Entries: 45775
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks gambling-related sites.
Entries: 472115
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
A medium-sized version for ad blockers that have trouble with the full gambling list.
Entries: 152312
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
A size-optimized version of the Gambling Medium list. Only contains domains that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
Entries: 99165
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks social networks like Facebook, Instagram, TikTok, X (formerly Twitter), Snapchat, and others.
Note
This list won't block messaging apps like WhatsApp or streaming platforms like Twitch. It's strictly aimed at classic social networking sites.
Entries: 902
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks adult content.
Entries: 114339
| Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|
| Link | Link | Link | Link | Link |
Blocks the native trackers baked into devices, services, and operating systems that quietly track what you do.
Important
Native tracker lists cover everything used to monitor user activity, which can occasionally limit functionality too. They're integrated across all the standard tiers (Light, Normal, Pro, Pro++, Ultimate), each at a different blocking level:
- Light through Pro: only block native trackers that won't break functionality, for a smooth experience.
- Pro++ (aggressive): blocks extra native trackers that might cause some restrictions or limit certain features.
- Ultimate: the most thorough option, blocking all native trackers for max privacy.
Pick whichever tier matches how aggressive you want to be about native tracker blocking.
When combining native tracker lists with the standard lists, you might need to manually unblock a specific tracker here or there.
| Device/Service | Adblock | DNSMasq | Wildcard Asterisk |
Wildcard Domains |
RPZ |
|---|---|---|---|---|---|
| Amazon (Devices, Shopping, Video) | Link | Link | Link | Link | Link |
| Apple (iOS, macOS, tvOS) | Link | Link | Link | Link | Link |
| Huawei (Devices) | Link | Link | Link | Link | Link |
| Microsoft (Windows, Office, MSN) | Link | Link | Link | Link | Link |
| Samsung | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) Aggressive | Link | Link | Link | Link | Link |
| LG webOS | Link | Link | Link | Link | Link |
| Roku | Link | Link | Link | Link | Link |
| Vivo | Link | Link | Link | Link | Link |
| OPPO/Realme | Link | Link | Link | Link | Link |
| Xiaomi | Link | Link | Link | Link | Link |
For network-wide DNS blocking, I'd recommend AdGuard Home, Pi-hole, TechnitiumDNS, Blocky (if you're comfortable with advanced setups), adblock-lean (for OpenWrt), or eBlocker.
DNS blockers do a great job protecting your privacy by cutting off trackers, metrics, and telemetry. They can also block most ads, malware, scams, and fake sites, but they can't catch everything since some of that stuff doesn't work through DNS.
That's why I also recommend pairing this with a browser content blocker like AdGuard, uBlock Origin, or Ghostery.
Check out Yokoffing's Recommended Filters for uBlock Origin for good content blocker filter lists.
Don't run your own DNS server at home, or want extra protection for your phone when it's off your home network? These DNS services have you covered.
Which lists are available where:
The services in this matrix let you pick individual lists. The ones further down (HaGeZi DNS, DNSBUNKER.org, Public RDNS, RobinGroppe.de, OpenBLD.net) run fixed list combinations instead, so they aren't part of it.
| List | AdGuard DNS | ControlD | RethinkDNS | DNSwarden |
|---|---|---|---|---|
| Light | ❌ | 🟢 | 🟢 | 🟢 |
| Normal | 🟢 | 🟢 | 🟢 | 🟢 |
| Pro | 🟢 | 🟢 | 🟢 | 🟢 |
| Pro++ | 🟢 | 🟢 | 🟢 | 🟢 |
| Ultimate | 🟢 | 🟢 | 🟢 | 🟢 |
| TIF | 🟢 | 🟢 | 🟢 | 🟢 |
| Bypass | 🟢 | 🟨 | 🟢 | ❌ |
| Dynamic DNS | 🟢 | 🟨 | 🟢 | ❌ |
| Badware Hoster | 🟢 | 📓 | 🟢 | ❌ |
| Most Abused TLDs | 🟢 | 📓 | ❌ | ❌ |
| Anti Piracy | 🟢 | 🟨 | ❌ | ❌ |
| Gambling | 🟢 | 🟨 | ❌ | ❌ |
| All other lists | 🟢 | ❌ | ❌ | ❌ |
- 🟢 Fully available as a native list on that service.
- ❌ Not available.
- 🟨 Included as part of ControlD's native category lists, no separate list needed.
- 📓 Available as a separate ControlD folder.
On AdGuardDNS you can use:
- Normal, Pro, Pro++, Ultimate
- Threat Intelligence Feeds (TIF), Most Abused TLDs, Badware Hoster, DynDNS, DNS Rebind Protection, URL Shortener
- DoH/VPN/TOR/Proxy Bypass
- Gambling
- Anti Piracy
- Native Tracker (Apple, OPPO & Realme, Samsung, Vivo, Windows/Office, Xiaomi)
- Allowlist Referral
On ControlD you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
Free:
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC | Legacy DNS | Apple |
|---|---|---|---|---|
| Light | https://freedns.controld.com/x-hagezi-light |
x-hagezi-light.freedns.controld.com |
76.76.2.37 76.76.10.37 2606:1a40::37 2606:1a40:1::37 |
Link |
| Normal | https://freedns.controld.com/x-hagezi-normal |
x-hagezi-normal.freedns.controld.com |
76.76.2.40 76.76.10.40 2606:1a40::40 2606:1a40:1::40 |
Link |
| Pro | https://freedns.controld.com/x-hagezi-pro |
x-hagezi-pro.freedns.controld.com |
76.76.2.41 76.76.10.41 2606:1a40::41 2606:1a40:1::41 |
Link |
| Pro Plus | https://freedns.controld.com/x-hagezi-proplus |
x-hagezi-proplus.freedns.controld.com |
76.76.2.42 76.76.10.42 2606:1a40::42 2606:1a40:1::42 |
Link |
| Ultimate | https://freedns.controld.com/x-hagezi-ultimate |
x-hagezi-ultimate.freedns.controld.com |
76.76.2.45 76.76.10.45 2606:1a40::45 2606:1a40:1::45 |
Link |
| TIF | https://freedns.controld.com/x-hagezi-tif |
x-hagezi-tif.freedns.controld.com |
76.76.2.46 76.76.10.46 2606:1a40::46 2606:1a40:1::46 |
Link |
Paid:
Check out Yokoffing's ControlD Config Guide for good ControlD settings.
Automation:
controld-hagezi-sync: automatically syncs HaGeZi folder blocklists to ControlD profiles via API. Supports TOML config, dry-run mode, multi-profile mappings, and daily GitHub Actions syncs.
HaGeZi DNS runs free, non-commercial public resolvers for Europe, mixing privacy and security with minimal restrictions using the Multi Pro and Threat Intelligence Feed lists.
More details in the project repository.
Blocks ads, trackers, analytics, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config |
Recommended for |
|---|---|---|---|---|
| Germany, Falkenstein | DoH/DoH3 | https://root.hagezi.org/dns-query |
Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK |
| DoT/QUIC | root.hagezi.org |
|||
| Do53 | 188.34.161.2102a01:4f8:c17:1c66::1 |
|||
| Germany, Nuremberg | DoH/DoH3 | https://wurzn.hagezi.org/dns-query |
Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | wurzn.hagezi.org |
|||
| Do53 | 159.69.155.942a01:4f8:1c1c:d363::1 |
|||
| Finland, Helsinki | DoH/DoH3 | https://juuri.hagezi.org/dns-query |
Link QR | DK, EE, FI, LT, LV, NO, SE |
| DoT/QUIC | juuri.hagezi.org |
|||
| Do53 | 95.217.163.172a01:4f9:c013:dc4e::1 |
Blocks ONLY phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config |
Recommended for |
|---|---|---|---|---|
| Germany, Nuremberg | DoH/DoH3 | https://ctif.hagezi.org/dns-query |
Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | ctif.hagezi.org |
|||
| Do53 | 162.55.58.402a01:4f8:1c19:6c19::1 |
DNSBUNKER.org is a hardened, privacy-first DNS resolver based in Germany.
| Blocklists | DNS-over-HTTPS/3 | DNS-over-TLS/QUIC | Apple |
|---|---|---|---|
| Pro + TIF | https://dnsbunker.org/dns-query |
dnsbunker.org |
Link |
Public RDNS is a free, no-log recursive resolver for families that uses HaGeZi lists to aggressively block ads, trackers, malware, NSFW content, piracy, gambling, and other unwanted domains.
More info on the project page.
RobinGroppe.de DNS is a free, privacy-focused DNS service. It doesn't log your queries and protects your connection by blocking malware, phishing, and other online threats using the HaGeZi Threat Intelligence Feeds.
On RethinkDNS you can use Light, Normal, Pro, Pro++, Ultimate, TIF, Bypass, DynDNS, and Badware Hoster.
Note
RethinkDNS only updates its lists once a week.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://sky.rethinkdns.com/1:AAkACAQA |
1-aaeqacaeaa.max.rethinkdns.com |
| Normal + TIF | https://sky.rethinkdns.com/1:AAkACAgA |
1-aaeqacaiaa.max.rethinkdns.com |
| Pro + TIF | https://sky.rethinkdns.com/1:AAoACBAA |
1-aafaacaqaa.max.rethinkdns.com |
| Pro plus + TIF | https://sky.rethinkdns.com/1:AAoACAgA |
1-aafaacaiaa.max.rethinkdns.com |
| Ultimate + TIF | https://sky.rethinkdns.com/1:gAgACABA |
1-qaeaacaaia.max.rethinkdns.com |
On DNSwarden you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://dns.dnswarden.com/00000000000000000000048 |
00000000000000000000048.dns.dnswarden.com |
| Normal + TIF | https://dns.dnswarden.com/00000000000000000000028 |
00000000000000000000028.dns.dnswarden.com |
| Pro + TIF | https://dns.dnswarden.com/00000000000000000000018 |
00000000000000000000018.dns.dnswarden.com |
| Pro plus + TIF | https://dns.dnswarden.com/0000000000000000000000o |
0000000000000000000000o.dns.dnswarden.com |
| Ultimate + TIF | https://dns.dnswarden.com/0000000000000000000000804 |
0000000000000000000000804.dns.dnswarden.com |
OpenBLD.net combines the Pro list with the TIF blocklist.
| Blocklists | DNS-over-HTTPS |
|---|---|
| Pro + TIF | https://ric.openbld.net/dns-query/hagezi |
"If the plan doesn't work, change the plan, not the goal."
There's no place like 127.0.0.1!
These blocklists are built on various sources plus my own denylists and extensions. The goal has always been to avoid false positives as much as possible without giving up effectiveness. Dead entries get pruned regularly to keep the lists lean. Built with 💓 for a safer, cleaner internet.
Every list gets tested against 10,000 websites from the Cisco Umbrella Top 1 million list. I check whether pages load properly, content displays correctly, navigation works, images load, videos play, and so on.
So no, these aren't just random lists stitched together from other sources. They've been optimized and extended to genuinely clean up the internet across every category. Curious how? Check out: Which sources are used and how are the lists compiled?
Here's how each version performed against that same 10,000-page set, which is also cross-referenced through whotracks.me. All pages were opened and fully loaded in batch via Edge with privacy features turned off, and cookies accepted.
| List | Total queries | Blocked queries | % blocked | % gap to light |
|---|---|---|---|---|
| Ultimate | 299646 | 131093 | 43.75 | 12.85 |
| Pro++ | 299646 | 119681 | 39.94 | 9.05 |
| Pro | 299646 | 97508 | 32.54 | 1.65 |
| Normal | 299646 | 93258 | 31.12 | 0.23 |
| Light | 299646 | 92576 | 30.90 | |
| ---- | 299646 | 67888 | 22.66 | -8.24 |
Give it a try, share your feedback, and report anything that should (or shouldn't) be blocked.
The repository gets compressed (reinitialized) every now and then to keep its size in check. Heads up, this invalidates forks and wipes the commit history.
Wondering how referral domains (affiliate and tracking links) are handled? Here's the answer: FAQ on referral domains
This project only exists because of a genuinely supportive community. It's free for everyone and stays up to date thanks to ongoing care, updates, and contributions from people who actually want to make things better.
Feedback, ideas, domain reports, false-positive reports, whatever you've got, it's all appreciated. Every bit of help, big or small, makes the internet a little safer and cleaner for everyone.
See: Getting help and reporting issues
Thanks for being part of this!
The primary source for all lists is the GitHub repository. The GitHub repository and its two full mirrors, GitLab and Codeberg, are updated in sync, once a day:
| Source | Update frequency |
|---|---|
| GitHub/jsDelivr (primary) | Once a day |
| gitlab.com/hagezi/mirror | Once a day, in sync with GitHub |
| codeberg.org/hagezi/mirror2 | Once a day, in sync with GitHub |
| hagezi-mirror.dnsbunker.org | Every 4 to 8 hours |
Tip
If you need the freshest possible data, use hagezi-mirror.dnsbunker.org. It's connected directly to the build system and receives each new list version as soon as it's built, ahead of the daily GitHub, GitLab, and Codeberg update.
Important
Scope. This disclaimer applies only to these DNS blocklists ("the Lists"). It does not extend to any other services the Provider may separately operate (e.g., public DNS resolvers), which may be subject to their own terms.
No warranty. The Lists are provided free of charge, "as is" and "as available," with no warranty of any kind, express, implied, or statutory. The creator/operator of the Lists ("the Provider") makes no promises about accuracy, completeness, timeliness, reliability, or fitness for any particular purpose. There's no guarantee that every malicious or unwanted domain is covered, and no guarantee that legitimate domains won't get blocked by mistake. The Lists are compiled in part from third-party sources; the Provider does not control and is not responsible for errors originating in those sources.
Assumption of risk. Using the Lists is entirely at your own risk. The Provider disclaims any and all direct, indirect, incidental, or consequential liability for damages arising from using, misusing, or being unable to use the Lists, except where such damages result from willful misconduct or gross negligence on the Provider's part, or from death or personal injury caused by the Provider's negligence.
A supplement, not a substitute. The Lists are meant to be one part of a broader defense-in-depth strategy, not the whole thing. They don't replace your own responsibility to do due diligence, run your own risk assessments, or use additional protections (firewalls, antivirus/EDR, IDS/IPS, etc.). There's no guarantee of compatibility with any specific system, platform, or setup.
No guarantee of availability, fair use. The Lists are a free, personal/community project, made available internationally, and no one is automatically entitled to their continued availability. The Provider may modify, suspend, restrict, or discontinue the Lists (in whole or in part) at any time and for any reason, including excessive query volume or abusive or disproportionate use, without notice and without liability, and is under no obligation to maintain, update, or continue providing them. The Provider makes reasonable efforts to fix faults once discovered, but does not guarantee any particular response or resolution time.
Redistribution and licensing. The Lists are published under the GNU General Public License v3.0 (GPL-3.0). A copy of the license is also included in each repository or mirror distributing the Lists. You may redistribute, modify, and adapt the Lists only under the terms of that license. This disclaimer applies in addition to, and does not replace, the warranty and liability terms already contained in the GPL-3.0 (Sections 15 to 16). It's on you to read, understand, and follow the license terms before using or redistributing anything.
Governing law. The Provider is based in Germany, and the Lists are made available for international use. This disclaimer is governed by the laws of Germany, without regard to conflict-of-law principles, to the extent permitted by applicable law. Nothing in this disclaimer limits any mandatory consumer-protection rights you may have under the law of your country of residence.
Severability. If any provision of this disclaimer is found invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision will be replaced by a valid one that most closely reflects its intended effect.
Changes to this disclaimer. The Provider may update this disclaimer from time to time. The version published alongside the Lists at the time of your access or use applies. Continued use of the Lists after an update constitutes acceptance of the updated disclaimer.
Accepting these terms. By accessing, downloading, or using these DNS blocklists, you agree to be bound by everything laid out in this disclaimer. If you do not agree, do not access, download, or use the Lists.
