Pi-hole basics: block ads and trackers on every device at home
Pi-hole is free, open-source software that blocks ad and tracking domains for your whole network: phones, smart TVs, tablets, even devices where you can’t install an ad blocker. It’s a great weekend project, and this guide covers the parts most tutorials skip, like what to do when it goes down.
What Pi-hole does (and doesn’t)
Every time a device loads a web page or an app, it looks up names like example.com using DNS, the internet’s phone book. Pi-hole becomes your home’s DNS server. When a device asks for a known ad or tracking domain, Pi-hole answers “nothing here”, and the ad never loads.
It’s good at: banner and pop-up ads served from separate ad domains, tracking and telemetry domains in apps and smart TVs, and showing you exactly what your devices are contacting.
It can’t block:
- ads served from the same domain as the content. Video ads on major streaming and video sites are the classic example.
- sponsored posts inside social media feeds;
- devices or browsers that use their own encrypted DNS (DNS-over-HTTPS) and bypass your network’s DNS. More on this below.
Think of it as a strong first layer, not a complete replacement for an in-browser blocker.
What you need
- An always-on device. A Raspberry Pi is the classic choice; even a Zero 2 W handles a household. Any small Linux computer works, and so does a container on a NAS or home server.
- A reliable power supply and storage. For a Pi, use the official power supply and a good-quality microSD card (16 GB or more), or a USB SSD.
- A wired connection if possible. Ethernet is more reliable than Wi-Fi for something the whole house depends on.
- Access to your router’s settings, to give the Pi-hole a fixed address and change the DNS your router hands out. Some ISP-supplied routers don’t allow changing DNS. If yours doesn’t, see option B below.
Install it
- Prepare the Pi. Use Raspberry Pi Imager to write Raspberry Pi OS Lite to the card. In the Imager’s settings, set a username and password, enable SSH and set your Wi-Fi if you won’t use Ethernet.
- Give it a fixed address. Boot the Pi, find it in your router’s device list, and create a DHCP reservation so it always gets the same IP address (for example
192.168.1.53). Write that address down; you’ll need it. - Connect and update. From a computer, run
ssh yourname@192.168.1.53, then:sudo apt update && sudo apt full-upgrade -y - Run the official installer. The Pi-hole project’s one-step install is:
If you prefer to read a script before running it (a good habit), download it first, read it, then run it withcurl -sSL https://install.pi-hole.net | bashsudo bash basic-install.sh. The official docs at docs.pi-hole.net cover both methods and Docker. - Answer the prompts. Choose an upstream DNS provider, the service Pi-hole asks for everything it doesn’t block. Privacy-focused public resolvers such as Quad9 or Cloudflare are common choices. Keep the default blocklist to start.
- Set the admin password:
sudo pihole setpassword - Open the dashboard at
http://192.168.1.53/admin, using your Pi’s address.
Point your network at it
Pi-hole only works for devices that use it for DNS. Pick one approach:
Option A: change the DNS your router hands out (recommended)
In your router’s DHCP or LAN settings, set the DNS server to your Pi-hole’s address. Then restart devices, or wait for them to renew, so they pick up the change.
Option B: let Pi-hole be the DHCP server
If your router won’t let you change DNS, turn off the router’s DHCP server and turn on Pi-hole’s (Settings → DHCP). Only one DHCP server should run on a network. Do the switch-over when nobody is mid-video-call.
Option C: set it per device
Set DNS manually on individual devices. This is handy for testing before you switch the whole house.
Check it’s working
- The dashboard should show queries climbing as devices browse.
- From a computer, look up a known ad domain against your Pi-hole:
A blocked domain returnsnslookup doubleclick.net 192.168.1.530.0.0.0(or::for IPv6). - Open a news site you know is ad-heavy and compare.
Living with Pi-hole
- Something broke? Occasionally a shopping link, a smart-TV app or a sign-in page needs a blocked domain. Open Query Log, find the blocked domain from the moment it broke, and allow it. From the command line, use
pihole allow example.com. - Pause blocking from the dashboard for 5 minutes when you need to test whether Pi-hole is the cause, or run
pihole disable 5m. - Keep it updated:
pihole -upupdates Pi-hole. Blocklists refresh weekly on their own, or runpihole -g. Update the operating system too (sudo apt update && sudo apt full-upgrade). - Encrypted DNS in browsers: if a browser’s “secure DNS” setting points to an outside provider, that browser skips Pi-hole. Set it to use your system/network DNS. By default, Pi-hole also tells Firefox to disable its automatic DNS-over-HTTPS.
- Don’t go overboard with blocklists. Huge lists mostly add breakage. Start with the default and add a list only when you have a reason.
Plan for when it’s down
Once your whole network uses Pi-hole, a dead Pi means “the internet is broken” for everyone at home, even though your connection is fine. Decide now what you’ll do:
- Write down how to undo it: “Router settings → LAN → DNS: set back to automatic.” Keep the note where another family member can find it.
- Back up your settings using the dashboard’s backup/export feature (Settings → Teleporter) after you change anything.
- Consider a second Pi-hole on another device and give both addresses to your router. Small tools exist to keep the two in sync.
- Use a decent power supply and storage. Cheap power supplies and worn-out SD cards cause most Pi failures.
What to buy
- A Raspberry Pi with the official power supply and a case. A Pi 4 or Pi 5 also leaves room for other projects. Example: Raspberry Pi starter kit with power supply
- A high-endurance microSD card or small USB SSD. Example: high-endurance 32 GB microSD card
- A short Ethernet cable to connect it to your router. Example: 3 ft Cat6 patch cable
Already have a NAS or an old laptop that stays on? Pi-hole runs happily in Docker or on most Linux systems, so you may not need to buy anything.