← Downloads

Pi-hole 6.4

Package v6.4 x86_64, ARM64 TAR.GZ November 27, 2025

Network-wide DNS filtering that blocks advertising and tracking domains for every device on your network, including the ones that cannot run a browser extension.

Download TAR.GZ Project website ↗

Download Mirrors

Mirror Region Download
Pi-hole (Official) Primary Global Download
GitHub Releases Global Download
Docker Image Global Download

Pi-hole is a DNS server that consults a blocklist. When a device asks for a blocked domain it answers with nothing, so the connection is never made. Point every device at it and the filtering applies everywhere with nothing installed on the clients.

Installing

curl -sSL https://install.pi-hole.net | bash

Or as a container, which is tidier. Expect one conflict on modern distributions: systemd-resolved already listens on port 53.

sudo systemctl disable --now systemd-resolved
# or set DNSStubListener=no in /etc/systemd/resolved.conf

Pointing devices at it

Best: on the router, via DHCP, so every device including guests picks it up automatically.

Do not set a public DNS server as a secondary. Devices query whichever answers first, so filtering becomes intermittent and confusing to debug. For redundancy, run a second Pi-hole.

Blocklists, with restraint

The default list is reasonable. Very aggressive lists break things constantly and the resulting whitelist maintenance is worse than the ads.

pihole -g                       # update lists
pihole -q doubleclick.net       # is this blocked, and by which list
pihole allow required.example.com
pihole disable 5m               # temporarily, to confirm it is the cause

The query log is how you diagnose a page that half loads: look at what was blocked at the moment it failed.

What it cannot do

Same-domain advertising. YouTube serves ads from the same domains as video, and DNS cannot distinguish them.

First-party tracking, which is indistinguishable from the site working.

Devices with hardcoded DNS, which ignore your DHCP settings entirely. Blocking outbound port 53 except to the Pi-hole forces them back, and DNS-over-HTTPS bypasses even that.

The single point of failure

Plan this before deploying. If Pi-hole is down, DNS fails network-wide, and to everyone else in the house that is “the internet is broken.”

Run a second instance, or know how to change the router’s DNS back quickly, and make sure someone else knows too. Our Pi-hole guide covers the whole picture.

Encrypt the upstream

By default Pi-hole forwards queries in plaintext. Pair it with unbound as a recursive resolver, or cloudflared for DNS-over-HTTPS, so it handles filtering and something else handles privacy on the way out.

Verify Your Download

Release archives on GitHub are published with checksums.