Skip to content

AdGuard Home and Pi-hole hosting for private, ad-free DNS

Block ads, trackers and malicious domains on every device with a DNS server of your own. AdGuard Home serves encrypted DNS that phones use anywhere; Pi-hole filters the devices that reach it through your VPN. Run either on a HyperDC VPS, preinstalled as an app option or installed with our guide, and locked to your own devices.

  • Blocks ads, trackers and malware for every device
  • Encrypted DNS over HTTPS, TLS and QUIC
  • Per-device rules and query logs
  • Locked to your devices, never an open resolver
Install
Official install script or Docker image
Stack
Go (AdGuard Home) · C and dnsmasq-based FTL (Pi-hole)
Default portsDNS on 53, DNS-over-HTTPS on 443, DNS-over-TLS and DNS-over-QUIC on 853, and AdGuard Home’s first-run setup on 3000. Open only what your devices use.
53 · 443 · 853 · 3000
MinimumPi-hole asks for 512 MB of RAM and 2 GB of free disk, 4 GB recommended. AdGuard Home publishes no minimum and is just as light.
Pi-hole: 512 MB RAM and 2 GB disk
Current release
AdGuard Home v0.107 · Pi-hole v6
Official docs
adguard-dns.io/kb · docs.pi-hole.net

Tools and protocols

  • AdGuard Home
  • Pi-hole
  • DNS-over-HTTPS
  • DNS-over-TLS
  • DNS-over-QUIC
  • DNSCrypt
  • Blocklists
  • Parental control
  • Safe search
  • ClientID

Facts from the project’s official website, documentation and repository, checked in October 2026.

AdGuard Home plans are being prepared

Tell us how many devices will use your DNS, and our team will reply with the right server. Or start today on a Linux VPS and install AdGuard Home with our guide.

How big a server does a DNS filter need?

DNS filtering is light. Query logs and a VPN on the same server are what add to the size.

How big a server does a DNS filter need?
Feature
Personal You and your devices
Recommended Family Every device in a household
Team A team, together with a WireGuard VPN
vCPUVirtual processor cores of the server. 1 1 2
MemoryMemory for the app, its database and the operating system. 1 GB 1 GB 2 GB
DiskNVMe or SSD storage for the app, its data and local backups. 10 GB 10 GB 20 GB
Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need. A few days A week Up to a month
  • Personal

    You and your devices

    vCPUVirtual processor cores of the server.
    1
    MemoryMemory for the app, its database and the operating system.
    1 GB
    DiskNVMe or SSD storage for the app, its data and local backups.
    10 GB
    Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need.
    A few days
  • Recommended

    Family

    Every device in a household

    vCPUVirtual processor cores of the server.
    1
    MemoryMemory for the app, its database and the operating system.
    1 GB
    DiskNVMe or SSD storage for the app, its data and local backups.
    10 GB
    Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need.
    A week
  • Team

    A team, together with a WireGuard VPN

    vCPUVirtual processor cores of the server.
    2
    MemoryMemory for the app, its database and the operating system.
    2 GB
    DiskNVMe or SSD storage for the app, its data and local backups.
    20 GB
    Query logLogs and statistics take disk space and can reveal browsing habits; keep them only as long as you need.
    Up to a month

Pi-hole asks for 512 MB of RAM and 2 GB of free disk; AdGuard Home publishes no minimum. These sizes leave room for the operating system, query logs and a VPN on the same server.

Cleaner, more private DNS for every device

A DNS filter answers every lookup your devices make and drops the ones that lead to ads, trackers and malware.

Blocklists you choose

Add well-known blocklists for ads, trackers and malicious domains, plus your own allow and block rules.

Encrypted DNS anywhere

AdGuard Home answers DNS-over-HTTPS, TLS and QUIC with a Let’s Encrypt certificate, so phones stay filtered on mobile data.

Rules per device

Give each device a ClientID, then apply parental control, safe search or its own blocklists per device.

Never an open resolver

Allow only your devices by ClientID or IP, or answer only inside your VPN, so nobody can use your server for DNS amplification attacks.

Root access, your rules

Every Linux VPS, VDS and dedicated server comes with full root access: you choose the versions, the add-ons and the security settings.

Locations on three continents

Run your server in the United States, Europe or Asia, close to the people who use it. The order form estimates the latency from where you are to each location.

Preinstalled or with our guide

Choose the app as an option when you order and it is installed for you, or set it up yourself with our step-by-step guide.

Dedicated IPv4 address

Linux and Windows VPS plans include a dedicated IPv4 address for your domain, your TLS certificate and your firewall rules.

Set up your DNS filter in four steps

Order the app preinstalled on your server, or install it yourself with our guide.

  1. Choose your server

    Pick a VPS, VDS or dedicated server in the size from the table above and the location closest to your users.

  2. Install AdGuard Home or Pi-hole

    Choose it as an app option, or use the official install script or Docker image of either project as described in our guide.

  3. Add your domain and lock it down

    Point a subdomain such as dns.example.com at the server, add a Let’s Encrypt certificate for encrypted DNS and allow only your devices.

  4. Point your devices at it

    Set Private DNS on Android to your hostname, install a DNS profile on Apple devices, or set the DNS server in your WireGuard config.

Step-by-step setup guides

Install, secure and update the app with our guides, written for current Ubuntu and Debian releases.

More guides

Related solutions

Self-Hosted App Hosting

Nextcloud, Immich, Jellyfin, Vaultwarden and more on your server.

Learn more

VPN server

Your own WireGuard or OpenVPN server with a fixed IP.

Learn more

Vaultwarden

Bitwarden-compatible password server for families and teams.

Learn more

Home Assistant

Always-on smart home hub with MQTT and remote access.

Learn more

Linux VPS Hosting

KVM servers with full root access for any app stack.

Learn more

Secure a new Linux server

Users, SSH keys, firewall and updates before you install apps.

Learn more

Frequently asked questions

Still have a question? Send us a message and our team will reply by email.
AdGuard Home or Pi-hole: which should I choose?

On a server, AdGuard Home is usually the better fit: it serves DNS-over-HTTPS, TLS and QUIC itself and identifies devices by ClientID, so phones can use it from anywhere. Pi-hole is built for local networks; on a server, use it through your WireGuard VPN.

Why should port 53 not be open to everyone?

An open DNS resolver answers anyone, and attackers abuse such servers to amplify floods against others. AdGuard’s guide recommends allowlist mode for public instances, and Pi-hole listens only to local devices by default. Allow your own devices only, or answer inside your VPN.

How do my phones use it away from home?

On Android, set Private DNS to your DNS-over-TLS hostname. On iPhone, iPad and Mac, install a DNS profile for DNS-over-HTTPS, which AdGuard Home can generate. Both work on mobile data and on any Wi-Fi.

Do I need a domain name?

For encrypted DNS, yes: DNS-over-HTTPS, TLS and QUIC need a certificate for a hostname such as dns.example.com. Plain DNS through a VPN works without one.

Does DNS filtering block every ad?

No. It blocks ads and trackers served from their own domains. Ads delivered from the same domain as the content, as on some video platforms and in some apps, pass through; a browser extension handles those.

Will a DNS server far away slow my browsing?

Each new lookup travels to the server and back, so choose the location closest to you. Both tools cache answers, so repeated lookups are answered right away.

Can I use it together with my VPN?

Yes. Run WireGuard on the same server and set its DNS to the server’s tunnel address. Every device on the VPN is filtered, and the DNS server never has to answer the public internet.

Ready for ad-free DNS on every device?

Tell us what you want to run and for how many people, and we will help you pick the right server.

Генерирај лозинка

Please confirm