AdGuard Home and Pi-hole hosting for private, ad-free DNS
Block ads, trackers and malicious domains on every device with a DNS server of your own. AdGuard Home serves encrypted DNS that phones use anywhere; Pi-hole filters the devices that reach it through your VPN. Run either on a HyperDC VPS, preinstalled as an app option or installed with our guide, and locked to your own devices.
- Blocks ads, trackers and malware for every device
- Encrypted DNS over HTTPS, TLS and QUIC
- Per-device rules and query logs
- Locked to your devices, never an open resolver
- Install
- Official install script or Docker image
- Stack
- Go (AdGuard Home) · C and dnsmasq-based FTL (Pi-hole)
- Default portsDNS on 53, DNS-over-HTTPS on 443, DNS-over-TLS and DNS-over-QUIC on 853, and AdGuard Home’s first-run setup on 3000. Open only what your devices use.
- 53 · 443 · 853 · 3000
- MinimumPi-hole asks for 512 MB of RAM and 2 GB of free disk, 4 GB recommended. AdGuard Home publishes no minimum and is just as light.
- Pi-hole: 512 MB RAM and 2 GB disk
- Current release
- AdGuard Home v0.107 · Pi-hole v6
- Official docs
- adguard-dns.io/kb · docs.pi-hole.net
Tools and protocols
- AdGuard Home
- Pi-hole
- DNS-over-HTTPS
- DNS-over-TLS
- DNS-over-QUIC
- DNSCrypt
- Blocklists
- Parental control
- Safe search
- ClientID
Facts from the project’s official website, documentation and repository, checked in October 2026.
AdGuard Home plans are being prepared
Tell us how many devices will use your DNS, and our team will reply with the right server. Or start today on a Linux VPS and install AdGuard Home with our guide.
How big a server does a DNS filter need?
DNS filtering is light. Query logs and a VPN on the same server are what add to the size.
| Feature |
Personal
You and your devices
|
Recommended Family
Every device in a household
|
Team
A team, together with a WireGuard VPN
|
|---|---|---|---|
| vCPUVirtual processor cores of the server. | 1 | 1 | 2 |
| MemoryMemory for the app, its database and the operating system. | 1 GB | 1 GB | 2 GB |
| DiskNVMe or SSD storage for the app, its data and local backups. | 10 GB | 10 GB | 20 GB |
| Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need. | A few days | A week | Up to a month |
-
Personal
You and your devices
- vCPUVirtual processor cores of the server.
- 1
- MemoryMemory for the app, its database and the operating system.
- 1 GB
- DiskNVMe or SSD storage for the app, its data and local backups.
- 10 GB
- Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need.
- A few days
-
Recommended
Family
Every device in a household
- vCPUVirtual processor cores of the server.
- 1
- MemoryMemory for the app, its database and the operating system.
- 1 GB
- DiskNVMe or SSD storage for the app, its data and local backups.
- 10 GB
- Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need.
- A week
-
Team
A team, together with a WireGuard VPN
- vCPUVirtual processor cores of the server.
- 2
- MemoryMemory for the app, its database and the operating system.
- 2 GB
- DiskNVMe or SSD storage for the app, its data and local backups.
- 20 GB
- Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need.
- Up to a month
Pi-hole asks for 512 MB of RAM and 2 GB of free disk; AdGuard Home publishes no minimum. These sizes leave room for the operating system, query logs and a VPN on the same server.
Cleaner, more private DNS for every device
A DNS filter answers every lookup your devices make and drops the ones that lead to ads, trackers and malware.
Blocklists you choose
Add well-known blocklists for ads, trackers and malicious domains, plus your own allow and block rules.
Encrypted DNS anywhere
AdGuard Home answers DNS-over-HTTPS, TLS and QUIC with a Let’s Encrypt certificate, so phones stay filtered on mobile data.
Rules per device
Give each device a ClientID, then apply parental control, safe search or its own blocklists per device.
Never an open resolver
Allow only your devices by ClientID or IP, or answer only inside your VPN, so nobody can use your server for DNS amplification attacks.
Root access, your rules
Every Linux VPS, VDS and dedicated server comes with full root access: you choose the versions, the add-ons and the security settings.
Locations on three continents
Run your server in the United States, Europe or Asia, close to the people who use it. The order form estimates the latency from where you are to each location.
Preinstalled or with our guide
Choose the app as an option when you order and it is installed for you, or set it up yourself with our step-by-step guide.
Dedicated IPv4 address
Linux and Windows VPS plans include a dedicated IPv4 address for your domain, your TLS certificate and your firewall rules.
Set up your DNS filter in four steps
Order the app preinstalled on your server, or install it yourself with our guide.
-
Choose your server
Pick a VPS, VDS or dedicated server in the size from the table above and the location closest to your users.
-
Install AdGuard Home or Pi-hole
Choose it as an app option, or use the official install script or Docker image of either project as described in our guide.
-
Add your domain and lock it down
Point a subdomain such as dns.example.com at the server, add a Let’s Encrypt certificate for encrypted DNS and allow only your devices.
-
Point your devices at it
Set Private DNS on Android to your hostname, install a DNS profile on Apple devices, or set the DNS server in your WireGuard config.
Step-by-step setup guides
Install, secure and update the app with our guides, written for current Ubuntu and Debian releases.
-
How to set up a WireGuard VPN server on Ubuntu or Debian
Build your own WireGuard VPN on a Linux server: generate keys safely, write wg0.conf, enable forwarding and NAT with ufw, run wg-quick under systemd and hand out client configs as QR codes.
35 min Intermediate -
How to install Docker Engine on Ubuntu 24.04 and 26.04
Install Docker Engine, Buildx and Compose from Docker's official apt repository on Ubuntu LTS, run it without sudo, rotate logs and keep published ports private.
15 min Beginner -
How to install AdGuard Home on a server without an open resolver
Run AdGuard Home on an internet-facing Linux server safely: official install script, a private admin UI, plain DNS only over WireGuard, optional DNS-over-HTTPS behind Caddy with ClientIDs, backups and updates.
40 min Intermediate
Related solutions
Self-Hosted App Hosting
Nextcloud, Immich, Jellyfin, Vaultwarden and more on your server.
Learn moreFrequently asked questions
AdGuard Home or Pi-hole: which should I choose?
On a server, AdGuard Home is usually the better fit: it serves DNS-over-HTTPS, TLS and QUIC itself and identifies devices by ClientID, so phones can use it from anywhere. Pi-hole is built for local networks; on a server, use it through your WireGuard VPN.
Why should port 53 not be open to everyone?
An open DNS resolver answers anyone, and attackers abuse such servers to amplify floods against others. AdGuard’s guide recommends allowlist mode for public instances, and Pi-hole listens only to local devices by default. Allow your own devices only, or answer inside your VPN.
How do my phones use it away from home?
On Android, set Private DNS to your DNS-over-TLS hostname. On iPhone, iPad and Mac, install a DNS profile for DNS-over-HTTPS, which AdGuard Home can generate. Both work on mobile data and on any Wi-Fi.
Do I need a domain name?
For encrypted DNS, yes: DNS-over-HTTPS, TLS and QUIC need a certificate for a hostname such as dns.example.com. Plain DNS through a VPN works without one.
Does DNS filtering block every ad?
No. It blocks ads and trackers served from their own domains. Ads delivered from the same domain as the content, as on some video platforms and in some apps, pass through; a browser extension handles those.
Will a DNS server far away slow my browsing?
Each new lookup travels to the server and back, so choose the location closest to you. Both tools cache answers, so repeated lookups are answered right away.
Can I use it together with my VPN?
Yes. Run WireGuard on the same server and set its DNS to the server’s tunnel address. Every device on the VPN is filtered, and the DNS server never has to answer the public internet.
Ready for ad-free DNS on every device?
Tell us what you want to run and for how many people, and we will help you pick the right server.