Pi-hole 6.4
Network-wide DNS filtering that blocks advertising and tracking domains for every device on your network, including the ones that cannot run a browser extension.
Download TAR.GZ Project website ↗Download Mirrors
Pi-hole is a DNS server that consults a blocklist. When a device asks for a blocked domain it answers with nothing, so the connection is never made. Point every device at it and the filtering applies everywhere with nothing installed on the clients.
Installing
curl -sSL https://install.pi-hole.net | bash
Or as a container, which is tidier. Expect one conflict on modern distributions: systemd-resolved already listens on port 53.
sudo systemctl disable --now systemd-resolved
# or set DNSStubListener=no in /etc/systemd/resolved.conf
Pointing devices at it
Best: on the router, via DHCP, so every device including guests picks it up automatically.
Do not set a public DNS server as a secondary. Devices query whichever answers first, so filtering becomes intermittent and confusing to debug. For redundancy, run a second Pi-hole.
Blocklists, with restraint
The default list is reasonable. Very aggressive lists break things constantly and the resulting whitelist maintenance is worse than the ads.
pihole -g # update lists
pihole -q doubleclick.net # is this blocked, and by which list
pihole allow required.example.com
pihole disable 5m # temporarily, to confirm it is the cause
The query log is how you diagnose a page that half loads: look at what was blocked at the moment it failed.
What it cannot do
Same-domain advertising. YouTube serves ads from the same domains as video, and DNS cannot distinguish them.
First-party tracking, which is indistinguishable from the site working.
Devices with hardcoded DNS, which ignore your DHCP settings entirely. Blocking outbound port 53 except to the Pi-hole forces them back, and DNS-over-HTTPS bypasses even that.
The single point of failure
Plan this before deploying. If Pi-hole is down, DNS fails network-wide, and to everyone else in the house that is “the internet is broken.”
Run a second instance, or know how to change the router’s DNS back quickly, and make sure someone else knows too. Our Pi-hole guide covers the whole picture.
Encrypt the upstream
By default Pi-hole forwards queries in plaintext. Pair it with unbound as a recursive resolver, or cloudflared for DNS-over-HTTPS, so it handles filtering and something else handles privacy on the way out.
Verify Your Download
Release archives on GitHub are published with checksums.