:zap: DNS Blocklists, let's make the internet a nicer place!
Built with :heartbeat: for a safer, cleaner internet. It always looks impossible until someone just goes ahead and does it.
What this is: a set of DNS blocklists that block ads, trackers, telemetry, phishing, malware, scams, and other unwanted domains network-wide. They work for any region and with every common DNS server, ad blocker, and content blocker.
Like this project? If it's helped you out, drop a :star: (top right) and join the stargazers club! Every star genuinely helps.
New here? Start with Multi PRO plus the Threat Intelligence Feeds list, pick the format that matches your tool, and follow the quick setup guide. Unsure which version fits you? See which list version should I use.
[!NOTE] About the cleaning tools below. The five Multi versions are named after cleaning tools, and you'll see that wording throughout this page: Light is the hand brush, Normal the broom, Pro the big broom, Pro++ the sweeper, and Ultimate the ultimate sweeper. The bigger the tool, the more thoroughly it cleans, and the more likely it is to sweep up something you wanted to keep.
:bookmark_tabs: Table of Contents
- Overview: Which format do I need?
- Multi LIGHT, hand brush: basic protection
- Multi NORMAL, broom: all-round protection
- Multi PRO, big broom: extended protection (recommended): Full - Mini
- Multi PRO++, sweeper: advanced protection (more aggressive): Full - Mini
- Multi ULTIMATE, ultimate sweeper: maximum protection (most aggressive): Full - Mini
- Fake, block scams, traps, and fake sites!
- Pop-Up Ads, stop annoying and malicious pop-ups!
- Threat Intelligence Feeds, a serious security boost (recommended): Full - Medium - Mini - IPs
- Newly Registered Domains (NRD/DGA), a favorite tool of threat actors for launching attacks!
- Dynamic DNS (DynDNS), guard against dynamic DNS abuse!
- Badware Hoster, guard against malicious hosting services!
- Most Abused TLDs, block known shady top-level domains!
- DNS Rebind Protection, stop attackers from pointing domains at your local network!
- DoH/VPN/TOR/Proxy Bypass, stop people from sneaking around your DNS: Full - DoH only - DoH IPs
- Safesearch not supported, block search engines that skip Safesearch!
- URL Shortener, block link shorteners!
- Anti Piracy, block piracy sites!
- Gambling, block gambling content: Full - Medium - Mini
- Social Networks, block access to social networks!
- NSFW, block adult content!
- Native Tracker, block built-in trackers from devices, apps, and OSes!
- Blocklist Lookup, check any domain or IP against every list!
- Blocklists Cheat Sheet, quick reference table for every list at a glance
- Recommendation: Which list version should I actually use?
- Online DNS Services: AdGuard DNS - ControlD - HaGeZi DNS - DNS Bunker - Public RDNS - RobinGroppe.de - RethinkDNS - DNSwarden - OpenBLD.net
- About: Repository - Referral Domains - Support
- FAQ, frequently asked questions, including the quick setup guide and the glossary
- Discussions
- Update Interval/Official Mirrors
- Sources
- Disclaimer
- Contact
:books: Multi, cleans up the internet and protects your privacy!
This is an all-in-one DNS blocklist that comes in several versions (light, normal, pro, pro++, and ultimate). You can run it standalone, and it works for any region. It blocks ads, trackers, metrics, telemetry, fake sites, phishing, malware, scams, cryptojacking, and other junk. It's built on various source blocklists, but that doesn't mean it's just a pile of lists glued together. Everything here has been optimized and extended so it actually cleans up the internet across the board.
Curious about the sources? Check out: Which sources are used for the lists and how are they compiled?
Blocklist versions at a glance:
For a full inclusion matrix that also covers the standalone lists, see the Cheat Sheet.
Main lists at a glance:
| List | Blocking type | Risk of breakage | Entries | Size-optimized version |
|---|---|---|---|---|
| :green_book:Light | Relaxed | Minimal | 37181 | - |
| :blue_book:Normal | Relaxed/Balanced | Low | 192712 | Light: 37181 |
| :ledger:Pro | Balanced | Low to moderate | 224797 | Mini: 49522 |
| :orange_book:Pro++ | Balanced/Aggressive | Moderate | 248778 | Mini: 59797 |
| :closed_book:Ultimate | Aggressive | High | 274506 | Mini: 74193 |
| :closed_lock_with_key:TIF | Threats only | Low | 2121596 | Medium: 352966 Mini: 178909 |
The first five build on each other, so pick exactly one of them. TIF works differently: it's an add-on covering malware, phishing, and other live threats, and it's worth running alongside any tier. The size-optimized versions are alternatives to their full list, never something you add on top. Entry counts change with every build.
[!TIP] :information_desk_person: Not sure which version fits you? Check this out.
Which format do I need?
Most lists below are published in the same five standard formats. Pick the row that matches your tool. Within these five, the blocked domains are the same, only the way they're written down changes.
| Format | Use it with |
|---|---|
| Adblock | Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode only), AdBlock-Fast, AdNauseam, Little Snitch Mini (smaller lists only) |
| DNSMasq | DNSMasq (v2.86 or newer), Diversion (v5 or newer) |
| Wildcard Asterisk | Blocky (v0.23 or newer), Nebulo, NetDuma, OPNsense, YogaDNS |
| Wildcard Domains | DNSCloak, DNSCrypt, FRITZ!Box (FRITZ!OS v8.40 or newer), TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro |
| RPZ | Bind, Knot, PowerDNS, Unbound, and other software supporting Response Policy Zones |
A handful of lists don't follow this pattern, because their content or their exclusion rules can't be expressed the same way in every format. Those are Most Abused TLDs (its own set of format variants), DNS Rebind Protection (AdGuard only), NRD/DGA (Adblock and plain domains only), and the IP lists for TIF and DoH. Each of those sections spells out what's available.
[!NOTE] The legacy Subdomains and Hosts formats live in a separate repository. For the complete format-to-tool breakdown, see the FAQ.
:green_book: Multi LIGHT, basic protection
Hand brush edition. Cleans up the internet and protects your privacy without going overboard. Blocks ads, trackers, metrics, telemetry, and some badware. Basically a size-optimized version of Multi NORMAL, built only from domains that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
[!NOTE] This version shouldn't cause any real restrictions. Great if your ad blocker chokes on big lists, or anywhere even Normal's low risk is too much.
[!IMPORTANT] Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 37181 | Link | Link | Link | Link | Link |
:blue_book: Multi NORMAL, all-round protection
Broom edition. Cleans up the internet and protects your privacy. Blocks ads, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
[!NOTE] This one mostly won't cause restrictions either. Good pick if you don't have an admin handy to unblock anything.
[!IMPORTANT] Doesn't block error trackers like Bugsnag, Crashlytics, Firebase, Instabug, Sentry, and similar app crash reporters. Those only get blocked starting with the Pro version.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 192712 | Link | Link | Link | Link | Link |
:ledger: Multi PRO, extended protection (recommended)
Big broom edition. Cleans up the internet and protects your privacy. Blocks ads, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
[!NOTE] Restrictions here are rare. Works best if you've got an admin nearby who can unblock something if needed. This is my personal go-to recommendation for solid ad blocking with good privacy without much hassle.
[!WARNING] Referral domains (affiliate and tracking links): Most referral domains are still allowed here, but a handful get blocked anyway, mainly ones that double as regular trackers or are commonly tied to scam and spam links. Details: Referral domains
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 224797 | Link | Link | Link | Link | Link |
:ledger: Multi PRO mini (best for browser/mobile ad blockers)
A size-optimized version made for DNS or browser blockers, like devices with limited RAM. This only contains domains from the full Pro list that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 49522 | Link | Link | Link | Link | Link |
:orange_book: Multi PRO++, advanced protection (more aggressive)
Sweeper edition. This one cleans up the internet aggressively and protects your privacy hard. Blocks ads, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
[!WARNING] This is the more aggressive sibling of Multi PRO. It might block a few legit domains by mistake, so it's best for experienced users. Ideally have an admin ready to unblock things that break.
[!WARNING] Referral domains (affiliate and tracking links): More referral domains get blocked than in Pro, specifically the ones that aren't used exclusively for link tracking. The bulk of the category still stays allowed. Details: Referral domains
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 248778 | Link | Link | Link | Link | Link |
:orange_book: Multi PRO++ mini
Built the same way as Pro mini, but from the full Pro++ list: only its domains that appear on the Top 1M/10M lists make the cut. For DNS or browser blockers on limited hardware.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 59797 | Link | Link | Link | Link | Link |
:closed_book: Multi ULTIMATE, maximum protection (most aggressive)
Ultimate sweeper edition. Strictly cleans up the internet and locks down your privacy. Blocks ads, trackers, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other junk.
[!CAUTION] This is a stricter version of Multi PRO++. It contains domains that can limit app or website functionality, including some popular trackers that will cause hiccups. Only use this if you know what you're doing, and make sure someone can unblock things when needed.
[!WARNING] Referral domains (affiliate and tracking links): Same as Pro++: referral domains that aren't used exclusively for link tracking are blocked, the rest of the category stays allowed. Details: Referral domains
Facebook: Ultimate blocks some META trackers, which limits Facebook and Facebook Messenger app functionality. It also blocks WhatsApp's graph trackers, which can mess with avatar creation, the in-app help center, and video effects. Other than that, WhatsApp works fine. If you use META apps alongside Ultimate, unblock these domains as needed: META Tracker
Windows/Xbox: Some Microsoft trackers are blocked too, which can affect things like Windows Spotlight and Xbox Live Achievements Activity History. Check here for details on which domains to unblock for which feature: Microsoft Tracker.
Location and IP trackers: Certain trackers that websites use to pin down your IP or location get blocked. Great for privacy, but it might trigger wrong regional settings, extra CAPTCHAs, or reduced site functionality here and there. These trackers are usually used for hidden analytics and ad targeting.
Anything else: More known quirks are listed here.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 274506 | Link | Link | Link | Link | Link |
:closed_book: Multi ULTIMATE mini
Built the same way as Pro mini, but from the full Ultimate list: only its domains that appear on the Top 1M/10M lists make the cut. For DNS or browser blockers on limited hardware.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 74193 | Link | Link | Link | Link | Link |
:trollface: Fake, blocks scams, traps, and fake sites!
This blocklist targets fake stores, fake streaming sites, rip-offs, subscription traps, and similar scams.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 16870 | Link | Link | Link | Link | Link |
:tada: Pop-Up Ads, stops annoying and malicious pop-ups!
Targets pop-up ads that range from annoying to outright malicious.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 50282 | Link | Link | Link | Link | Link |
:closed_lock_with_key: Threat Intelligence Feeds, a serious security boost (recommended)
This blocklist targets malware, cryptojacking, scams, spam, and phishing. It blocks domains known for spreading malware, running phishing attacks, and hosting command-and-control servers.
[!WARNING] This list is huge and can eat up a lot of memory depending on your ad blocker. If that's an issue, grab the medium or mini version instead. It's too big for the iOS AdGuard mobile app, and AdGuard Home needs at least 2 GB RAM. The RPZ version had to be split into two files because of its size, you need both.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ (split) |
|---|---|---|---|---|---|
| 2121596 | Link | Link | Link | Link | :one: Link :two: Link |
:closed_lock_with_key: Threat Intelligence Feeds, medium version (best for browser/mobile ad blockers)
A medium-sized version of the TIF list, built for ad blockers that struggle with the full-size version. Includes only the most important feeds.
[!WARNING] Too big for the iOS AdGuard mobile app. AdGuard Home needs at least 1 GB RAM.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 352966 | Link | Link | Link | Link | Link |
:closed_lock_with_key: Threat Intelligence Feeds, mini version
A size-optimized version of the TIF Medium list, for ad blockers that even struggle with that one.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 178909 | Link | Link | Link | Link | Link |
:closed_lock_with_key: Threat Intelligence Feeds, IPs
There's also an IPv4 version of this list, in plain IP format for firewalls and AdGuard Home format, which extends the regular TIF list.
[!TIP] If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
:new: Newly Registered Domains (NRD/DGA)
Newly registered domains (NRDs) are a favorite tool for threat actors running phishing, malware, and command-and-control operations, since these domains are easy to throw away and help dodge detection.
There are two variants:
- NRDs: every newly registered domain, no filtering.
- Entropy NRDs/DGAs: only newly registered domains with high entropy, meaning they were likely generated by a Domain Generation Algorithm (DGA). These have a random-looking structure and are commonly used by malware for resilient command-and-control channels.
[!WARNING] These lists are big and resource-heavy. They can spike memory usage and include false positives, since some legit domains are new too. Use with care and whitelist important services if needed.
[!CAUTION] Use these at your own risk. NRD lists come as-is, with no guarantees, no support, and no formal process for fixing false positives.
[!IMPORTANT] The base data comes from Stamus Labs. Stamus Labs doesn't promise daily updates, so the data can sometimes lag by a few days.
Current status of the data:
- Stamus Labs: :green_circle: - Sun, 06 Sep 2026 04:23:15 UTC / 10999757 domains
:new: NRDs: all newly registered domains, unfiltered
| Time period | Entries | Format Adblock | Format Domains |
|---|---|---|---|
| 7 days ago to yesterday | 3117466 | Link | Link |
| 14 days ago to 8 days ago | 2309542 | Link | Link |
| 21 days ago to 15 days ago | 3001474 | Link | Link |
| 28 days ago to 22 days ago | 2666049 | Link | Link |
| 35 days ago to 29 days ago | 2891059 | Link | Link |
[!NOTE] The five files are non-overlapping bands, so stack them for wider coverage:
nrd7plusnrd14-8covers the last 14 days, addnrd21-15for 21 days, and so on.
[!TIP] Besides the formats here, NRDs are also available elsewhere:
- Wildcard (Asterisk): Cebeerre/dnsblocklists
:capital_abcd: Entropy NRDs/DGAs: only newly registered, high-entropy domains generated by DGAs
[!NOTE] These domains are already part of the full NRD list, just filtered down.
| Time period | Entries | Format Adblock | Format Domains |
|---|---|---|---|
| Past 7 days | 582919 | Link | Link |
| Past 14 days | 1123658 | Link | Link |
| Past 30 days | 2449988 | Link | Link |
:lock_with_ink_pen: Dynamic DNS (DynDNS), guards against dynamic DNS abuse!
Blocks dynamic DNS services that get abused for phishing campaigns and other shady activity.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 1534 | Link | Link | Link | Link | Link |
:computer: Badware Hoster, guards against malicious hosting services!
Blocks known hosting providers that repeatedly host badware through user-uploaded content.
[!IMPORTANT] This list blocks the root domains of hosting providers that keep showing up in threat feeds because of malicious subdomains. That means legit sites hosted there will get blocked too, so think it through before using this one.
If you use this list, you're on your own for unblocking any subdomains you actually need.
[!CAUTION] Blocking whole hosting providers is overkill for most setups and can break legit services. In high-security environments though, that trade-off might make sense.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ | ControlD |
|---|---|---|---|---|---|---|
| 1237 | Link | Link | Link | Link | Link | Link |
:crystal_ball: Most Abused TLDs, blocks known shady top-level domains!
Blocks the most abused top-level domains, combining data from Cloudflare Radar, Netcraft, and SpamHaus.
[!WARNING] This list blocks entire top-level domains (like *.top, *.shop, *.gdn) that have a bad reputation overall. Yes, that means some legit sites get caught in the crossfire too, but it's really effective against spam, scams, phishing, malware, and other garbage. Know what you're signing up for.
Only well-known, reputable domains that show up on the supported top lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop) or are essential for popular apps get considered for exclusion. Illegal domains, including piracy sites, stay blocked no matter what. Anything that doesn't clearly qualify gets reviewed case by case, and if there's no good reason to unblock it, it stays blocked. If you need access to something specific, add it to your personal allowlist.
This selective approach exists because AdGuard and uBlock Origin have technical limits on rule length when using denyallow/domain modifiers. Trying to exclude every legit domain would eventually break important rules, so exclusions have to stay limited and carefully picked.
This list doesn't follow the usual five-format pattern, since the exclusion rules work differently from tool to tool.
| Format | Link | Notes |
|---|---|---|
| AdGuard | Link | For AdGuard and AdGuard Home |
| uBlock Origin | Link | For uBlock Origin and Adblock Plus |
| Adblock | Link | For Pi-hole and TechnitiumDNS. Spam TLDs with no exclusions |
| Adblock (Aggressive) + Allowlist | Link Link | For Pi-hole and TechnitiumDNS. Use both together |
| Wildcard Domains + Allowlist | Link Link | For DNSCrypt. Use both together |
| RPZ | Link | Spam TLDs with no exclusions |
| RPZ (Aggressive) | Link | All spam TLDs, matching the AdGuard and uBlock Origin versions |
| ControlD | Link | Importable ControlD folder |
:shield: DNS Rebind Protection, stops attackers from pointing domains at your local network!
DNS Rebind Protection stops attackers from messing with DNS responses to make a domain point to a private or local IP address. This blocks malicious scripts from using DNS rebinding attacks to reach your internal network.
[!IMPORTANT] This only works with AdGuard/AdGuard Home, and it's also selectable in AdGuard DNS. Other DNS blockers may already have their own rebind protection built in.
Since rebind protection blocks anything resolving to a local IP, your internal hostnames might get caught too. In AdGuard, whitelist your local domains, something like:
@@||fritz.box^
| Format | Link |
|---|---|
| AdGuard | Link |
:outbox_tray: DoH/VPN/TOR/Proxy Bypass, stop people from sneaking around your DNS!
Blocks common ways to bypass your DNS setup.
[!NOTE] To make sure your DNS server is actually the one being used, you'll need to redirect or block standard DNS traffic (TCP/UDP 53) and also block DNS over TLS/QUIC (TCP/UDP 853) outbound.
This comes as three lists. The first two are alternatives, pick one; the third is an IP-level companion to the DoH-only list, not to the complete edition:
:outbox_tray: Complete edition: encrypted DNS servers, VPN, TOR, proxies
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 16469 | Link | Link | Link | Link | Link |
:outbox_tray: Encrypted DNS servers only
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 3334 | Link | Link | Link | Link | Link |
:outbox_tray: Encrypted DNS server IPs
There's also an IPv4 version in plain IP format for firewalls, and an AdGuard Home format.
[!TIP] If you use the IP list in AdGuard Home, it'll block any domain that resolves to a blocked IP. To stop domains from slipping through via IPv6, turn off IPv6 resolution in AdGuard Home:
Settings > DNS settings > DNS server configuration > Disable resolving of IPv6 addresses
:mag: Safesearch not supported, blocks search engines that skip Safesearch!
Blocks search engines that don't support Safesearch.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 204 | Link | Link | Link | Link | Link |
:link: URL Shortener, blocks link shorteners!
Blocks every known URL/link shortener out there.
[!WARNING] Not really meant for everyday setups. Blocking all URL shorteners makes the most sense in high-security environments, since shorteners can hide where a link actually leads and help enable attacks. In lower-risk settings, keeping an eye on things or just being careful usually does the job.
If you use this list, you're on your own for unblocking any domains you actually need.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 9907 | Link | Link | Link | Link | Link |
:skull: Anti Piracy, blocks piracy sites!
Blocks sites and services mainly used for illegally distributing copyrighted content.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 48957 | Link | Link | Link | Link | Link |
:slot_machine: Gambling, blocks gambling content!
Blocks gambling-related sites.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 469516 | Link | Link | Link | Link | Link |
:slot_machine: Gambling, medium version
A medium-sized version for ad blockers that have trouble with the full gambling list.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 146036 | Link | Link | Link | Link | Link |
:slot_machine: Gambling, mini version
A size-optimized version of the Gambling Medium list. Only contains domains that appear on Top 1M/10M lists (Umbrella, Cloudflare, Tranco, Chrome, BuiltWith, Majestic, DomCop).
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 89010 | Link | Link | Link | Link | Link |
:speech_balloon: Social Networks, blocks access to social networks!
Blocks social networks like Facebook, Instagram, TikTok, X (formerly Twitter), Snapchat, and others.
[!NOTE] This list won't block messaging apps like WhatsApp or streaming platforms like Twitch. It's strictly aimed at classic social networking sites.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 902 | Link | Link | Link | Link | Link |
:underage: NSFW, blocks adult content!
Blocks adult content.
| Entries | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| 127091 | Link | Link | Link | Link | Link |
:calling: Native Tracker, blocks built-in trackers from devices, apps, and OSes!
Blocks the native trackers baked into devices, services, and operating systems that quietly track what you do.
[!IMPORTANT] Native tracker lists cover everything used to monitor user activity, which can occasionally limit functionality too. They're integrated across all the standard tiers (Light, Normal, Pro, Pro++, Ultimate) at four increasing blocking levels:
- Light and Normal: the baseline. Only native trackers that won't break functionality, for a smooth experience.
- Pro: blocks more than the baseline, while still staying out of your way.
- Pro++ (aggressive): blocks nearly all of them, which might cause some restrictions or limit certain features.
- Ultimate: the most thorough option, blocking all native trackers for max privacy.
Pick whichever tier matches how aggressive you want to be about native tracker blocking.
When combining native tracker lists with the standard lists, you might need to manually unblock a specific tracker here or there.
| Device/Service | Adblock | DNSMasq | Wildcard Asterisk | Wildcard Domains | RPZ |
|---|---|---|---|---|---|
| Amazon (Devices, Shopping, Video) | Link | Link | Link | Link | Link |
| Apple (iOS, macOS, tvOS) | Link | Link | Link | Link | Link |
| Huawei (Devices) | Link | Link | Link | Link | Link |
| Microsoft (Windows, Office, MSN) | Link | Link | Link | Link | Link |
| Samsung | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) | Link | Link | Link | Link | Link |
| TikTok (Fingerprinting) Aggressive | Link | Link | Link | Link | Link |
| LG webOS | Link | Link | Link | Link | Link |
| Roku | Link | Link | Link | Link | Link |
| Vivo | Link | Link | Link | Link | Link |
| OPPO/Realme | Link | Link | Link | Link | Link |
| Xiaomi | Link | Link | Link | Link | Link |
:mag_right: Blocklist Lookup, check any domain or IP against every list!
Not sure whether a domain is blocked, or which list is responsible for it? The Blocklist Lookup answers both: hagezi-mirror.dnsbunker.org/listseek.php
Paste in one entry or a whole batch, one per line and up to 50 per query, hit Search, and you get a card per entry listing every list that blocks it along with the exact rule. Domains and IPv4 addresses both work, so you can check something like ads.tracker.net and 1.1.1.1 in the same run. Wildcard patterns like *.example.com work too, listing every matching rule, and you can paste a full URL or bracketed notation (example[.]com) straight in. It reads the published lists straight from the build mirror, so the results always reflect the newest build.
It's subdomain-aware too: look up region1.app-measurement.com and you'll see the match comes from ||app-measurement.com^, a wildcard on the parent domain, not an entry for that exact hostname. It also follows CNAME chains, up to 8 hops, so a domain that isn't on any list itself still gets flagged if it points at something that is, and the result shows you the full chain.
Handy for hunting down a false positive, comparing what happens to a domain across tiers before you switch, or checking whether something is covered at all before you report it. The NRD and DGA lists aren't searched by default, they're very large and slow the search down noticeably, so switch them on only when you need them.
[!NOTE] The Lookup reads the published lists, not your own setup, and it doesn't judge whether a domain is harmful. Your local allowlist, extra lists from other projects, or a copy that hasn't refreshed yet can all make your network behave differently. More detail in the FAQ.
:bulb: Recommendation
For network-wide DNS blocking, I'd recommend AdGuard Home, Pi-hole, TechnitiumDNS, Blocky (if you're comfortable with advanced setups), adblock-lean (for OpenWrt), or eBlocker.
DNS blockers do a great job protecting your privacy by cutting off trackers, metrics, and telemetry. They can also block most ads, malware, scams, and fake sites, but they can't catch everything since some of that stuff doesn't work through DNS.
That's why I also recommend pairing this with a browser content blocker like AdGuard, uBlock Origin, or Ghostery.
Check out Yokoffing's Recommended Filters for uBlock Origin for good content blocker filter lists.
[!TIP] :information_desk_person: Still not sure which version to pick?
:department_store: Online DNS Services
Don't run your own DNS server at home, or want extra protection for your phone when it's off your home network? These DNS services have you covered.
:department_store: AdGuardDNS, limited free / unlimited trial / paid
On AdGuardDNS you can use:
- Normal, Pro, Pro++, Ultimate
- Threat Intelligence Feeds (TIF), Most Abused TLDs, Badware Hoster, DynDNS, DNS Rebind Protection, URL Shortener
- DoH/VPN/TOR/Proxy Bypass
- Gambling
- Anti Piracy
- Native Tracker (Apple, OPPO & Realme, Samsung, Vivo, Windows/Office, Xiaomi)
- NSFW (Parental Control > Block adult websites)
- Allowlist Referral
:department_store: ControlD, free / paid
On ControlD you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
Free:
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC | Legacy DNS | Apple |
|---|---|---|---|---|
| Light | https://freedns.controld.com/x-hagezi-light | x-hagezi-light.freedns.controld.com | 76.76.2.37 76.76.10.37 2606:1a40::37 2606:1a40:1::37 | Link |
| Normal | https://freedns.controld.com/x-hagezi-normal | x-hagezi-normal.freedns.controld.com | 76.76.2.40 76.76.10.40 2606:1a40::40 2606:1a40:1::40 | Link |
| Pro | https://freedns.controld.com/x-hagezi-pro | x-hagezi-pro.freedns.controld.com | 76.76.2.41 76.76.10.41 2606:1a40::41 2606:1a40:1::41 | Link |
| Pro Plus | https://freedns.controld.com/x-hagezi-proplus | x-hagezi-proplus.freedns.controld.com | 76.76.2.42 76.76.10.42 2606:1a40::42 2606:1a40:1::42 | Link |
| Ultimate | https://freedns.controld.com/x-hagezi-ultimate | x-hagezi-ultimate.freedns.controld.com | 76.76.2.45 76.76.10.45 2606:1a40::45 2606:1a40:1::45 | Link |
| TIF | https://freedns.controld.com/x-hagezi-tif | x-hagezi-tif.freedns.controld.com | 76.76.2.46 76.76.10.46 2606:1a40::46 2606:1a40:1::46 | Link |
Paid:
Check out Yokoffing's ControlD Config Guide for good ControlD settings.
Automation:
controld-hagezi-sync: automatically syncs HaGeZi folder blocklists to ControlD profiles via API. Supports TOML config, dry-run mode, multi-profile mappings, and daily GitHub Actions syncs.
:department_store: HaGeZi DNS (EU: Germany/Finland, balanced blocking), free
HaGeZi DNS runs free, non-commercial public resolvers for Europe, mixing privacy and security with minimal restrictions using the Multi Pro and Threat Intelligence Feed lists.
More details in the project repository.
Blocks ads, trackers, analytics, metrics, telemetry, phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Falkenstein | DoH/DoH3 | https://root.hagezi.org/dns-query | Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, FR, GB, HU, IE, IT, LU, NL, PL, RO, SI, SK |
| DoT/QUIC | root.hagezi.org | |||
| Do53 | 188.34.161.2102a01:4f8:c17:1c66::1 | |||
| Germany, Nuremberg | DoH/DoH3 | https://wurzn.hagezi.org/dns-query | Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | wurzn.hagezi.org | |||
| Do53 | 159.69.155.942a01:4f8:1c1c:d363::1 | |||
| Finland, Helsinki | DoH/DoH3 | https://juuri.hagezi.org/dns-query | Link QR | DK, EE, FI, LT, LV, NO, SE |
| DoT/QUIC | juuri.hagezi.org | |||
| Do53 | 95.217.163.172a01:4f9:c013:dc4e::1 |
Blocks ONLY phishing, malware, scams, fakes, cryptojacking, and other harmful domains:
| Location | Protocols | Endpoint/URL | Apple Config | Recommended for |
|---|---|---|---|---|
| Germany, Nuremberg | DoH/DoH3 | https://ctif.hagezi.org/dns-query | Link QR | AT, BA, BE, BG, CH, CZ, DE, DK, ES, FR, GB, GR, HR, HU, IE, IT, LU, MD, MK, MT, NL, PL, PT, RO, RS, SI, SK, TR, UA |
| DoT/QUIC | ctif.hagezi.org | |||
| Do53 | 162.55.58.402a01:4f8:1c19:6c19::1 |
:department_store: DNSBUNKER.org (EU: Germany, balanced blocking), free
DNSBUNKER.org is a hardened, privacy-first DNS resolver based in Germany.
| Blocklists | DNS-over-HTTPS/3 | DNS-over-TLS/QUIC | Apple |
|---|---|---|---|
| Pro + TIF | https://dnsbunker.org/dns-query | dnsbunker.org | Link |
:department_store: Public RDNS (EU: Finland, family-safe, aggressive blocking), free
Public RDNS is a free, no-log recursive resolver for families that uses HaGeZi lists to aggressively block ads, trackers, malware, NSFW content, piracy, gambling, and other unwanted domains.
More info on the project page.
:department_store: RobinGroppe.de (EU: Germany, threat blocking), free
RobinGroppe.de DNS is a free, privacy-focused DNS service. It doesn't log your queries and protects your connection by blocking malware, phishing, and other online threats using the HaGeZi Threat Intelligence Feeds.
:department_store: RethinkDNS, free
On RethinkDNS you can use Light, Normal, Pro, Pro++, Ultimate, TIF, Bypass, DynDNS, and Badware Hoster.
[!NOTE] RethinkDNS only updates its lists once a week.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://sky.rethinkdns.com/1:AAkACAQA | 1-aaeqacaeaa.max.rethinkdns.com |
| Normal + TIF | https://sky.rethinkdns.com/1:AAkACAgA | 1-aaeqacaiaa.max.rethinkdns.com |
| Pro + TIF | https://sky.rethinkdns.com/1:AAoACBAA | 1-aafaacaqaa.max.rethinkdns.com |
| Pro plus + TIF | https://sky.rethinkdns.com/1:AAoACAgA | 1-aafaacaiaa.max.rethinkdns.com |
| Ultimate + TIF | https://sky.rethinkdns.com/1:gAgACABA | 1-qaeaacaaia.max.rethinkdns.com |
:department_store: DNSwarden, free
On DNSwarden you can use Light, Normal, Pro, Pro++, Ultimate, and TIF.
| Blocklists | DNS-over-HTTPS | DNS-over-TLS/QUIC |
|---|---|---|
| Light + TIF | https://dns.dnswarden.com/00000000000000000000048 | 00000000000000000000048.dns.dnswarden.com |
| Normal + TIF | https://dns.dnswarden.com/00000000000000000000028 | 00000000000000000000028.dns.dnswarden.com |
| Pro + TIF | https://dns.dnswarden.com/00000000000000000000018 | 00000000000000000000018.dns.dnswarden.com |
| Pro plus + TIF | https://dns.dnswarden.com/0000000000000000000000o | 0000000000000000000000o.dns.dnswarden.com |
| Ultimate + TIF | https://dns.dnswarden.com/0000000000000000000000804 | 0000000000000000000000804.dns.dnswarden.com |
:department_store: OpenBLD.net, free
OpenBLD.net combines the Pro list with the TIF blocklist.
| Blocklists | DNS-over-HTTPS |
|---|---|
| Pro + TIF | https://ric.openbld.net/dns-query/hagezi |
:loudspeaker: About
"If the plan doesn't work, change the plan, not the goal."
There's no place like 127.0.0.1!
These blocklists are built on various sources plus my own denylists and extensions. The goal has always been to avoid false positives as much as possible without giving up effectiveness. Dead entries get pruned regularly to keep the lists lean. Built with :heartbeat: for a safer, cleaner internet.
While the lists were being developed, each version was tested against 10,000 websites from the Cisco Umbrella Top 1 million list. I checked whether pages loaded properly, content displayed correctly, navigation worked, images loaded, videos played, and so on. That was a one-off benchmark run rather than something that repeats with every build.
So no, these aren't just random lists stitched together from other sources. They've been optimized and extended to genuinely clean up the internet across every category. Curious how? Check out: Which sources are used and how are the lists compiled?
Here's how each version performed in that run against the same 10,000-page set, which is also cross-referenced through whotracks.me. All pages were opened and fully loaded in batch via Edge with privacy features turned off, and cookies accepted. The numbers are a snapshot from that benchmark, not live figures from the current build.
| List | Total queries | Blocked queries | % blocked | % gap to light |
|---|---|---|---|---|
| Ultimate | 299646 | 131093 | 43.75 | 12.85 |
| Pro++ | 299646 | 119681 | 39.94 | 9.05 |
| Pro | 299646 | 97508 | 32.54 | 1.65 |
| Normal | 299646 | 93258 | 31.12 | 0.23 |
| Light | 299646 | 92576 | 30.90 | |
| ---- | 299646 | 67888 | 22.66 | -8.24 |
Give it a try, share your feedback, and report anything that should (or shouldn't) be blocked. Want to check a specific domain first? Use the Blocklist Lookup.
:octocat: Repository
The repository gets compressed (reinitialized) every now and then to keep its size in check. Heads up, this invalidates forks and wipes the commit history.
:cyclone: Referral Domains
Wondering how referral domains (affiliate and tracking links) are handled? Here's the answer: FAQ on referral domains
:dizzy: Support
This project only exists because of a genuinely supportive community. It's free for everyone and stays up to date thanks to ongoing care, updates, and contributions from people who actually want to make things better.
Feedback, ideas, domain reports, false-positive reports, whatever you've got, it's all appreciated. Every bit of help, big or small, makes the internet a little safer and cleaner for everyone.
Before you report a domain, run it through the Blocklist Lookup. A report that names the exact list and rule is a lot quicker to act on.
See: Getting help and reporting issues
Thanks for being part of this!
:floppy_disk: Update Interval/Official Mirrors
The lists are rebuilt several times a day, but not every source publishes every build. There are two kinds of sources here, and the difference is only how often a finished build shows up:
- Repository sources. GitHub is the reference repository, and GitLab and Codeberg are its full repository mirrors. All three publish one build per day, in sync with each other.
- Build mirror. hagezi-mirror.dnsbunker.org is connected directly to the build system and publishes every build as soon as it finishes, which works out to a new version roughly every 4 to 8 hours.
| Source | What it is | Publishes |
|---|---|---|
| GitHub/jsDelivr | Reference repository | Once a day |
| gitlab.com/hagezi/mirror | Repository mirror | Once a day, in sync with GitHub |
| codeberg.org/hagezi/mirror2 | Repository mirror | Once a day, in sync with GitHub |
| hagezi-mirror.dnsbunker.org | Build mirror | Every build, roughly every 4 to 8 hours |
[!TIP] All four sources serve the same lists, so pick by how fresh you need the data. Once a day is plenty for most setups. If you want every build the moment it exists, use the build mirror at hagezi-mirror.dnsbunker.org.
:warning: Disclaimer
[!IMPORTANT] Scope. This disclaimer applies to these DNS blocklists and to the related lists published by the project, including the NRD/DGA lists and the legacy format lists (together, "the Lists"). The Lists are created and maintained by HaGeZi ("the Provider"). This disclaimer does not extend to any other service the Provider may separately operate (e.g., public DNS resolvers or the Blocklist Lookup), which may be subject to its own terms.
No warranty. The Lists are provided free of charge, "as is" and "as available," with no warranty of any kind, express, implied, or statutory. The Provider makes no promises about accuracy, completeness, timeliness, reliability, or fitness for any particular purpose. There's no guarantee that every malicious or unwanted domain is covered, and no guarantee that legitimate domains won't get blocked by mistake. The Lists are compiled in part from third-party sources; the Provider does not control and is not responsible for errors originating in those sources.
No accusation, no endorsement. A domain showing up on a list is a technical filtering decision, not a legal finding and not a claim that whoever operates it did anything wrong. Categorization is based on third-party threat data, public rankings, and observed behavior, and any of that can be outdated or simply wrong. Brand names, domain names, and trademarks mentioned in the Lists or in this documentation belong to their respective owners and are used for identification only. If you operate a domain and think it's listed by mistake, ask for a review through the issue tracker or by mail at support@hagezi.org. Review and removal requests are handled on a best-effort basis, with no guaranteed response time.
Assumption of risk. Using the Lists is entirely at your own risk. The Provider disclaims any and all direct, indirect, incidental, or consequential liability for damages arising from using, misusing, or being unable to use the Lists, except where such damages result from willful misconduct or gross negligence on the Provider's part, or from death or personal injury caused by the Provider's negligence. Mandatory statutory liability that can't be excluded by agreement stays unaffected, whatever the wording above says.
A supplement, not a substitute. The Lists are meant to be one part of a broader defense-in-depth strategy, not the whole thing. They don't replace your own responsibility to do due diligence, run your own risk assessments, or use additional protections (firewalls, antivirus/EDR, IDS/IPS, etc.). There's no guarantee of compatibility with any specific system, platform, or setup. Nothing in the Lists or in the surrounding documentation is legal advice or professional security advice.
Your setup, your responsibility. You're responsible for making sure the way you deploy the Lists is legal where you are. That matters most when you filter a network other people use (family, guests, employees, students, customers) and when you use lists that restrict access rather than block threats, such as NSFW, Social Networks, Gambling, Anti Piracy, or the DoH/VPN/TOR/Proxy Bypass list. Employment, telecommunications, and data-protection rules can all come into play. The Provider offers no guidance on this and takes no responsibility for how the Lists are deployed.
Third-party services and software. DNS services, software, mirrors, and other projects linked or listed here are run by their respective operators, not by the Provider. Being mentioned is not an endorsement, and how those parties host, configure, delay, or modify the Lists is outside the Provider's control. Their own terms and privacy policies apply, including those of the platforms you download from (GitHub/jsDelivr, GitLab, Codeberg, and the build mirror).
No guarantee of availability, fair use. The Lists are a free, personal/community project, made available internationally, and no one is automatically entitled to their continued availability. The Provider may modify, suspend, restrict, or discontinue the Lists (in whole or in part) at any time and for any reason, including excessive query volume or abusive or disproportionate use, without notice and without liability, and is under no obligation to maintain, update, or continue providing them. The Provider makes reasonable efforts to fix faults once discovered, but does not guarantee any particular response or resolution time.
Redistribution and licensing. The Lists are published under the GNU General Public License v3.0 (GPL-3.0). A copy of the license is included in this repository and has to accompany any redistribution. You may redistribute, modify, and adapt the Lists only under the terms of that license. This disclaimer applies in addition to, and does not replace, the warranty and liability terms already contained in the GPL-3.0 (Sections 15 to 17). Some inputs come from third-party sources with their own licenses or terms of use. GPL-3.0 covers the Lists as published here; it doesn't hand you any rights in the upstream data itself, so if you build on that data directly, checking those terms is on you. It's on you to read, understand, and follow the license terms before using or redistributing anything.
Governing law. The Provider is based in Germany, and the Lists are made available for international use. This disclaimer is governed by the laws of Germany, without regard to conflict-of-law principles, to the extent permitted by applicable law. Nothing in this disclaimer limits any mandatory consumer-protection rights you may have under the law of your country of residence.
Severability. If any provision of this disclaimer is found invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision will be replaced by a valid one that most closely reflects its intended effect.
Changes to this disclaimer. The Provider may update this disclaimer from time to time. The version published alongside the Lists at the time of your access or use applies. Continued use of the Lists after an update constitutes acceptance of the updated disclaimer.
Accepting these terms. By accessing, downloading, or using these DNS blocklists, you agree to be bound by everything laid out in this disclaimer. If you do not agree, do not access, download, or use the Lists.
