Index of/

HaGeZi DNS Blocklist Mirror

Let's make the internet a nicer place!

$pwd /

$ grep
NameLast modifiedSize
adblock/2026-09-23 23:51 UTC-
adguard/2026-08-13 20:04 UTC-
assets/2026-09-16 20:15 UTC-
controld/2026-09-23 23:52 UTC-
dnsmasq/2026-09-23 23:51 UTC-
domains/2026-09-23 23:51 UTC-
hosts/2026-09-23 23:51 UTC-
ips/2026-09-23 23:51 UTC-
rpz/2026-09-23 23:52 UTC-
share/2026-09-23 23:32 UTC-
wildcard/2026-09-23 23:52 UTC-

License: GPL-3.0

📖 Description

HaGeZi DNS Blocklists are lists of domains that block ads, trackers, telemetry, phishing, malware, scams, and other unwanted content across your whole network, before any of it reaches your devices. They work with every common DNS server, ad blocker, and content blocker.

This is the official, always-on mirror. Same lists as the main source, with every published format gathered in one place, so you're never left hanging if the main source hiccups.

The mirror runs on infrastructure operated by DNSBUNKER.org with HaGeZi's authorization. The lists and this README are pushed and maintained by HaGeZi.

This page is the short version. For the full per-list documentation, formats, FAQ, and glossary, see the detailed documentation.

Note

This mirror is connected directly to the HaGeZi build system and publishes every build as soon as it finishes, which works out to a new version roughly every 4 to 8 hours. The GitHub, GitLab, and Codeberg repositories publish one build per day, so this mirror is always the fresher option. Think of it as your backup generator: reliable, redundant, and always plugged in.

Licensed under the GNU General Public License v3.0 (GPL-3.0). See the Disclaimer section below for the full redistribution and liability terms.

📑 Table of Contents


🚀 Quick Setup

Already have a working setup from a different source and just want to switch the download URL? Skip ahead to Migrating from Another Mirror instead, the steps in this section are for a brand new setup.

Tip

In a hurry? If your tool reads the Adblock, DNSMasq, Wildcard, or RPZ format, the Direct Link Generator does all three steps below for you: pick your tool, tick your lists, copy every link at once. The steps here still explain what you're actually picking, so they're worth a skim either way.

Quick Setup overview: pick a format, pick a tier, add extras, with Pro + TIF marked as the recommended combo

Note

Above this README, you'll find a file browser. It starts at the root, showing one folder per format (adblock/, adguard/, wildcard/, and so on). Open the folder matching your format first, and only then will you see the individual list files inside it. Use the small copy icon next to a file name to grab that file's direct link. No need to type out URLs by hand. The browser is the right tool when you're after one specific file; if you're putting a whole set together, the Direct Link Generator is quicker.

Before you start: these three steps assume you already run something that can subscribe to blocklists, a DNS server like Pi-hole, AdGuard Home, or TechnitiumDNS, or a content blocker like uBlock Origin or the AdGuard app. If you don't have one and don't want to set one up, skip straight to DNS Resolver Services, where these lists are already running for you.

Three steps, in this order:

  1. Pick your format first. Check Supported Formats to see which one your DNS filter or firewall actually understands (Adblock, AdGuard, RPZ, and so on), and note its Extension pattern from that table. This decides both the top level folder you'll open in the file browser above and how the file names look inside it. Not sure which one your tool speaks? The table has a tip for that.
  2. Pick your lists. Browse the Blocklists Cheat Sheet and note the file names of whatever you want, starting with a tier from Main Tiers, then adding Threat Intelligence Feeds from Security Add-ons, see the tip there for why this pairing matters at every tier. Layer on anything else you need from there. File names shown in the cheat sheet are for the Adblock format; adjust them to match your format's extension pattern from step 1.
  3. Grab each link and subscribe to it, one list at a time. In the file browser, open the folder matching the format you picked in step 1. For each file from step 2 (renamed to match that format's pattern): click its copy icon, switch to your DNS filter or firewall, and add that single link as a new blocklist subscription. Then go back to the file browser and repeat for the next file. Each list needs its own separate subscription entry. Most tools won't accept several links pasted into a single field, so add them one by one unless yours explicitly supports bulk input. Quicker route for the copying part: the Direct Link Generator hands you every link at once, already named correctly for your format.

Note

One exception to step 3: the Referral Allowlist from Referral Lists is not a blocklist. It has to go into your tool's allowlist or whitelist field instead, otherwise you'd be blocking exactly the domains it's meant to keep working.

Worked example: the ⭐ Recommended default, Pro plus Threat Intelligence Feeds (Full), on a blocker using the Adblock format. Open the adblock/ folder, copy the link next to pro.txt, add it as a subscription, then do the same for tif.txt as a second, separate subscription. Adblock uses a plain *.txt pattern, so both file names match the cheat sheet unchanged. If your blocker can't handle TIF's full size, use tif.medium.txt or tif.mini.txt instead.

Important

File names are not identical across formats. Each format in Supported Formats has its own Extension pattern, and you have to apply it yourself. For example, switching to Wildcard, Domains doesn't just move pro.txt into the wildcard/ folder, that format only ships as *-onlydomains.txt, so the actual file is pro-onlydomains.txt. Always check the Extension column for your chosen format before assuming a file name carries over unchanged.

Tip

Your query log answers both questions after setup. Browse for a bit, then open it. Blocked entries piling up means the subscription is live; an empty log usually means your device isn't using that DNS server yet.

If a site stops working, the same log tells you whether a block is the cause. Sometimes the page won't come up at all, which shows as a name-resolution error ("server not found" or similar) rather than a normal error page from the site. More often the page loads but doesn't behave right: blank images or videos, embedded maps or comments that never appear, a button that does nothing. In that second case the blocked domain is usually not the site you're on, so check the log for whatever got blocked while the page was loading. Confirm it was blocked, then add it to your tool's allowlist. To find out which list is behind the block, drop the domain into the Blocklist Lookup. If you think it shouldn't be blocked at all, report it, see Support.

Note

What DNS blocking can't do. It works by refusing to resolve a domain, which only helps when the unwanted content has a domain of its own. YouTube, Spotify, Twitch, Facebook, and many mobile apps serve their ads from the same domains as the content itself, so there's nothing separate to block, and blocking it would take the whole service down. That's a limit of DNS filtering in general, not of these lists.

To cover that gap, pair your setup with a browser content blocker like uBlock Origin, AdGuard, or Ghostery, which filters individual elements inside the page. On mobile, a client-side blocker app does the same for app traffic. Think of DNS blocking as the network-wide baseline and a content blocker as the fine-tuned layer on top.

Keep them current. These lists change constantly. Most tools refresh subscribed lists on their own, but check that the option is enabled, and if yours doesn't support it, re-download the files from time to time. This mirror always serves the latest build.


🔄 Migrating from Another Mirror

Already using a different source for these blocklists? Switching over to this mirror is quick. Just replace the base part of your existing URL with the new base below, and keep the rest (the format folder and file name) exactly as it is.

Note

New to this mirror entirely, not migrating from somewhere else? Head back up to Quick Setup instead, this section only covers swapping an existing URL's base.

Source Old Base URL
jsDelivr (dns-blocklists) https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/
jsDelivr (dns-blocklists-legacy) https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists-legacy@latest/
jsDelivr (nrd) https://cdn.jsdelivr.net/gh/hagezi/nrd@latest/
GitHub (dns-blocklists) https://raw.githubusercontent.com/hagezi/dns-blocklists/main/
GitHub (nrd) https://raw.githubusercontent.com/hagezi/nrd/main/
GitHub (dns-blocklists-legacy) https://raw.githubusercontent.com/hagezi/dns-blocklists-legacy/main/
GitLab https://gitlab.com/hagezi/mirror/-/raw/main/dns-blocklists/
Codeberg https://codeberg.org/hagezi/mirror2/raw/branch/main/dns-blocklists/

New base URL for all of the above: https://hagezi-mirror.dnsbunker.org/

Here's a full example, so you can see it in action:

https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/pro.txt becomes https://hagezi-mirror.dnsbunker.org/adblock/pro.txt

Everything after the base URL, the adblock/pro.txt part in this case, stays the same. Just update your DNS filter or firewall config with the new base and you're good to go.

Tip

The Direct Link Generator can do this for you too. Tick the lists you already use, leave the source on DNSBunker, and copy the finished links. No URL surgery by hand, and no typos.


📇 Supported Formats

Pick whichever format actually talks to your DNS filter or firewall. The Example column shows what an entry for example.com actually looks like in each format, so you can tell them apart at a glance.

For the domain-based formats, the Syntax column also tells you how subdomains are handled. Wildcard formats match every subdomain of a listed domain automatically, so a single entry is usually enough. Explicit formats have no wildcard mechanism, so every subdomain that should be caught has to be spelled out as its own entry, which is why those files are much larger and still can't cover everything, see the note below the table.

Format Extension Syntax Example Compatible Software
Adblock *.txt Adblock, wildcard (covers subdomains) ||example.com^ Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave (aggressive mode), AdBlock-Fast, AdNauseam, Little Snitch Mini (smaller lists only)
AdGuard *.txt AdGuard filter syntax ||_dns.resolver.arpa^$dnsrewrite=NXDOMAIN
/^10\.(?:\d{1,3})\.(?:\d{1,3})\.(?:\d{1,3})$/
|*faceb00k*^
AdGuard, AdGuard Home
ControlD *.json JSON ControlD-specific JSON structure, no plain domain example applies ControlD folders
DNSMasq *.txt DNSMasq, wildcard (covers subdomains) local=/example.com/ DNSMasq v2.86 or later, Diversion v5 or later
Subdomains *.txt Domains, explicit subdomain entries example.com
a.example.com
Blocky (before v0.23), Diversion (before v5), PersonalBlocklist, pfBlockerNG, other
Hosts *.txt Hosts, explicit subdomain entries 0.0.0.0 example.com
0.0.0.0 a.example.com
AdAway, uMatrix, OpenSnitch, DNS66, NetGuard, other
Hosts, Compressed *-compressed.txt Hosts, explicit subdomain entries, 9 per line 0.0.0.0 example.com a.example.com b.example.com
(up to 9 domains per line)
Hostfile, Linux
IPs *.txt IPv4 1.2.3.4 Firewalls
RPZ *.txt Response Policy Zone, wildcard (covers subdomains) example.com CNAME .
*.example.com CNAME .
BIND, Knot, PowerDNS, Unbound
Wildcard, Asterisk *.txt Domains with asterisk, wildcard (covers subdomains) *.example.com Blocky v0.23 or later, Nebulo, NetDuma, OPNsense, YogaDNS
Wildcard, Domains *-onlydomains.txt Plain domains, treated as wildcard by the software below example.com DNSCloak, DNSCrypt, FRITZ!Box FRITZ!OS 8.40 or later, TechnitiumDNS, adblock-lean, PersonalDNSfilter, InviZible Pro

Tip

Not sure which row is yours? The Direct Link Generator picks the format for you: select the app or device you use, tick your lists, copy the links. It covers five of the formats in this table: Adblock, DNSMasq, both Wildcard variants, and RPZ. For the rest, use the file browser.

Note

The explicit formats (Subdomains, Hosts, Hosts Compressed) always have gaps. Every relevant subdomain has to be spelled out by hand, so they can't catch generic, dynamic, or previously unknown ones. The files look complete but aren't, which is the dangerous part: you're likely missing subdomains that don't exist yet.

That's also why not every list is built in these formats. If you can't find one, it doesn't exist there, and there's no hidden version elsewhere.


📑 Blocklists Cheat Sheet

The lazy scroller's cheat sheet for every list in the collection: what it does, what to watch out for, who should grab it, and the actual file name.

Blocklists Cheat Sheet overview: six categories, with Main Tiers as the required starting point, then Security Add-ons, Bypass and Rebind Protection, Content Filtering, and Referral Lists as opt-in layers on top, plus Native Trackers, which every tier already covers to some degree

The matrix below shows which commonly overlapping lists are already included in each Main Tier and in TIF. A half-filled circle means partial inclusion; its color shows the relative coverage within that row: orange = less, yellow = more, green = most. The same matrix is available as a text table in the detailed documentation.

Inclusion Matrix showing coverage of Fake, Pop-Up Ads, Threat Intelligence Feeds, Native Trackers, Crash/Error Trackers, and Referral Domains across Light, Normal, Pro, Pro++, Ultimate, and TIF

Start with a tier from Main Tiers below to set your baseline, then layer on whatever you need from Security Add-ons, Bypass and Rebind Protection, Content Filtering, Native Trackers, or Referral Lists. Most lists across those five categories are separate, opt-in additions that no Main Tier includes. Three things work differently: Fake and Pop-Up Ads are already bundled into most tiers, and Native Tracker coverage is baked into every tier at a different strength, so the per-vendor files there fine-tune what you already have rather than adding it from scratch. The Already in Main Tiers column in those tables spells out the exact overlap. Grab whichever combo fits your setup and go make the internet a nicer place.

Tip

New here? Pro + Threat Intelligence Feeds (Full) is the recommended balanced default for most setups, marked ⭐ Recommended below. See Quick Setup above for exact steps, and the tip in Security Add-ons for why TIF is worth pairing with any tier, not just Pro.

Want the full scoop on any individual list? Check out the detailed per-list documentation for all the details.

Main Tiers

These are the baseline lists. Pick exactly one as your foundation, then optionally layer other categories on top.

List Name What It Does Blocking Level Best For File Name (Adblock)
Light Light cleanup of ads, trackers, metrics, telemetry, and some badware. It's built only from domains that appear on the Top 1M/10M lists, which is why the Fake list isn't in it at all: fake shops and fake streaming sites generally don't rank there. Also doesn't block crash/error trackers (Bugsnag, Crashlytics, Firebase, Sentry, and similar) or any referral/affiliate links. Relaxed (minimal breakage risk) Anywhere Normal doesn't fit: blockers that can't handle its size, or environments where even Normal's low breakage risk is unacceptable light.txt
Normal All round protection: ads, trackers, telemetry, phishing, malware, scams, fakes, cryptojacking. Doesn't block crash/error trackers or any referral/affiliate links either, both start with Pro. Relaxed to Balanced (low breakage risk) The default baseline for unattended setups with no admin around to unblock things, step down to Light only if size or breakage becomes a problem multi.txt
ProRecommended Extended protection, same categories as Normal but wider net. First tier to block crash/error trackers. Also the first tier to block a handful of referral/affiliate domains, only ones that double as regular trackers or are tied to scam/spam links, most referral links still work. Balanced (low to moderate breakage risk, recommended default) Setups with an admin nearby who can unblock domains if needed pro.txt
Pro (Mini) Same blocking scope as Pro, just size-optimized for low RAM DNS or browser blockers. Balanced Same audience as Pro, but on limited hardware pro.mini.txt
Pro++ More aggressive sibling of Pro, same junk blocked harder. May nab a few legit domains. Blocks a few more referral domains than Pro (still not all of them), including some like ad.doubleclick.net and adservice.google.*. Balanced to Aggressive (moderate breakage risk) Experienced users with an admin available pro.plus.txt
Pro++ (Mini) Same blocking scope as Pro++, just size-optimized for low RAM devices. Balanced to Aggressive Same audience as Pro++, but on limited hardware pro.plus.mini.txt
Ultimate Strict, no-mercy cleanup, deliberately blocks some popular trackers. Blocks the same handful of referral/affiliate domains as Pro++, still not all of them. Has known side effects, see the note below the table. Aggressive (high breakage risk) Very experienced users with an admin available ultimate.txt
Ultimate (Mini) Same blocking scope as Ultimate, just size-optimized for low RAM devices. Aggressive Same audience as Ultimate, but on limited hardware ultimate.mini.txt

Warning

Ultimate's known side effects. Meta tracker blocking limits Facebook and Facebook Messenger and affects some WhatsApp features (avatar creation, help center, video effects). Microsoft tracker blocking affects Windows Spotlight and Xbox Live Achievements. Location and IP tracker blocking may trigger extra CAPTCHAs or wrong regional settings. Ready-made unblock lists are available for Meta and Microsoft, plus a general known issues list.

Security Add-ons

Optional lists that add specific security protections on top of whatever Main Tier you picked. Fake and Pop-Up Ads are already bundled into most Main Tiers by default (see the Already in Main Tiers column below). Everything else here, including every TIF variant, is a separate, opt-in addition that no Main Tier ships as a list.

Tip

Out of everything here, Threat Intelligence Feeds (TIF) is the one add-on worth combining with your Main Tier no matter which tier you picked, Light through Ultimate. No Main Tier ships TIF as a list. Some individual TIF domains do end up in the Main Tiers during the build, but that overlap is negligible on Light and only ever partial on Normal, Pro, Pro++, and Ultimate, so TIF still closes real coverage gaps even on Pro++ or Ultimate. If your DNS filter or firewall can handle large lists, use TIF (Full). If it struggles, drop down to TIF (Medium), and if even that's too much, use TIF (Mini). Either way, pick one TIF variant, don't skip it.

List Name What It Does Already in Main Tiers Notes Best For File Name (Adblock)
Fake Targets fake stores, fake streaming sites, rip-offs, subscription traps, and similar scams. Normal, Pro, Pro++, Ultimate (fully); not in Light at all. Also fully included in TIF Bundled in at those tiers, standalone add-on otherwise Anyone who doesn't want to get scammed by a fake shop, streaming site, or subscription trap fake.txt
Pop-Up Ads Stops annoying and malicious pop ups. Heads up: it's a chunky list on its own. Pro, Pro++, Ultimate (fully); Light, Normal (partially). Also partially included in TIF Bundled in at those tiers, standalone add-on otherwise Anyone drowning in pop up garbage popupads.txt
Threat Intelligence Feeds (Full) ⭐ Recommended Serious security upgrade pulling in threat feeds against malware, cryptojacking, scams, spam, and phishing, including C2 domains. Too big for the iOS AdGuard mobile app. Not as a list. Normal, Pro, Pro++, and Ultimate do carry some individual TIF domains, Light almost none, see tip above Standalone, recommended with every tier; needs 2GB RAM in AdGuard Home, RPZ version split into 2 files (you need both) Security focused users with enough RAM tif.txt
Threat Intelligence Feeds (Medium) Trimmed TIF version with only the most important feeds. Also too big for the iOS AdGuard mobile app. Not as a list, same partial domain overlap as TIF (Full), see tip above Standalone, recommended with every tier; needs 1GB RAM in AdGuard Home Blockers that struggle with the full TIF list tif.medium.txt
Threat Intelligence Feeds (Mini) Further size-optimized version of TIF Medium only, not a direct cut of the full TIF list. Not as a list, same partial domain overlap as TIF (Full), see tip above Standalone, recommended with every tier Blockers that even struggle with the Medium version tif.mini.txt
Threat Intelligence Feeds (IPs) IPv4 companion list, extends the regular TIF list. If you also run AdGuard Home, disable IPv6 resolution there, otherwise devices can dodge the block by resolving over IPv6 instead. None Standalone Firewalls or AdGuard Home setups wanting IP level TIF coverage tif-ips.txt
Newly Registered Domains (NRD) Blocks freshly registered domains. Ships as five non-overlapping bands meant to be stacked, see the note below the table. None Aggressive, higher false positive risk since some legit domains are new too Security minded users comfortable maintaining an allowlist, used at your own risk nrd7.txt, nrd14-8.txt, nrd21-15.txt, nrd28-22.txt, nrd35-29.txt
Newly Registered Domains (DGA) Only high entropy NRDs, likely generated by malware Domain Generation Algorithms. A filtered subset of NRD, so use one or the other, never both, see the note below the table. None Aggressive, narrower than full NRD Same audience as NRD, focused on C2 style domains, want less noise dga7.txt, dga14.txt, dga30.txt
Dynamic DNS Blocks dynamic DNS providers commonly abused in phishing. None Standalone Security focused admins, pairs well with TIF, Badware Hoster, and Most Abused TLDs dyndns.txt
Badware Hoster Blocks root domains of hosting providers whose infrastructure is frequently abused for malware. Also ships as a ControlD folder. None Standalone (blunt, legit sites hosted there get blocked too) Admins okay with some collateral damage in exchange for stronger protection hoster.txt
URL Shortener Blocks all known link/URL shorteners. Recommended mainly for high security environments since it can break legitimate short links. None Standalone (niche, add only if you need it) High security environments where hidden redirect destinations are a risk urlshortener.txt
Most Abused TLDs Blocks entire top level domains (like .top, .shop, .gdn) with poor reputations. None Aggressive (some legit sites caught) Users fine with trading a few false positives for strong anti spam and anti scam coverage spam-tlds.txt (AdGuard), spam-tlds-ublock.txt, spam-tlds-adblock.txt (no exclusions), spam-tlds-adblock-aggressive.txt + spam-tlds-adblock-allow.txt (aggressive pair)

Note

NRD and DGA are alternatives, not a pair. DGA is the high-entropy subset of NRD, so pick one rather than running both.

Bypass and Rebind Protection

Optional lists that close specific loopholes: services people use to dodge DNS filtering, and attacks that abuse DNS to reach your local network. None of these are bundled into any Main Tier, all four are separate, opt-in additions. If you're building a kid-safe network, the DoH/VPN/Tor/Proxy Bypass (Full) list below is part of the recommended combination described in Content Filtering.

List Name What It Does Best For File Name (Adblock)
DoH/VPN/Tor/Proxy Bypass (Full) Blocks encrypted DNS, VPN, Tor, and proxy services so people can't dodge your DNS filtering. The broadest of the three bypass lists, includes the DoH-only list's domains plus VPN/Tor/proxy services. Works best paired with a firewall rule blocking outbound ports 53 and 853, otherwise devices can still reach DNS servers directly. Admins locking down networks, useful for parental control or corporate setups doh-vpn-proxy-bypass.txt
DoH/VPN/Tor/Proxy Bypass (DoH only) Blocks only encrypted DNS servers, not VPN, Tor, or proxy services. Same port-blocking recommendation as Full applies. Same goal as Full, but narrower scope doh.txt
DoH/VPN/Tor/Proxy Bypass (DoH IPs) IPv4 companion list, but specifically for the DoH-only list above, not for Full, since VPN/Tor/proxy services don't resolve to a fixed IP set. If you also run AdGuard Home, disable IPv6 resolution there for the same reason as the TIF IPs list above. Firewalls or AdGuard Home setups wanting IP level bypass coverage doh-ips.txt
DNS Rebind Protection Stops attackers from pointing external domains at your internal/local network's private IP addresses. Works with AdGuard, AdGuard Home, and AdGuard DNS. Check your own tool's documentation first, plenty of other DNS blockers already have their own built-in rebind protection. Whitelist your local hostnames (for example @@||fritz.box^ in AdGuard) since anything resolving to a local IP gets caught too. Add it only if your environment calls for it. Anyone running AdGuard products who wants rebind attack protection dns-rebind-protection.txt

Content Filtering

Optional lists for blocking specific categories of content, commonly used for parental controls or workplace filtering rather than general security. None of these are bundled into any Main Tier. There are five lists here, shipped as seven files since Gambling comes in three sizes. Those three are alternatives, not building blocks, so pick one Gambling variant rather than combining them. Every list here is a separate, opt-in addition. The recommended combination for a kid-safe network is Gambling, Anti Piracy, Safesearch, Social Networks, and NSFW, together with DoH/VPN/Tor/Proxy Bypass (Full) from Bypass and Rebind Protection above, which stops a device from simply switching to its own encrypted DNS and walking around all of them.

List Name What It Does Best For File Name (Adblock)
Safesearch Not Supported Blocks search engines that don't support or force Safesearch. Kid-safe networks nosafesearch.txt
Anti Piracy Blocks piracy and illegal streaming/download sites. Kid-safe networks, or anyone who wants piracy sites off the network anti.piracy.txt
Gambling (Full) Blocks gambling sites and content. Kid-safe networks, self-exclusion setups, or workplace filtering gambling.txt
Gambling (Medium) Same blocking scope as Gambling (Full), just trimmed for blockers that struggle with the full version. Same audience as Full, lighter setups gambling.medium.txt
Gambling (Mini) Further size-optimized version of Gambling Medium only, not a direct cut of the full list. Same audience as Medium, even lighter setups gambling.mini.txt
Social Networks Blocks Facebook, Instagram, TikTok, X, and Snapchat. Doesn't touch messaging apps like WhatsApp or streaming platforms like Twitch. Kid-safe networks, digital detox setups, or workplace focus filtering social.txt
NSFW Blocks adult content. Kid-safe networks, workplace and school networks nsfw.txt

Native Trackers

Native tracker lists cover everything used to monitor user activity built directly into devices, apps, and operating systems, which can occasionally limit functionality too. Unlike the other categories on this page, native tracker blocking isn't something you opt into separately, it's already baked into every Main Tier at a different strength, see the Already in Main Tiers column below for the exact breakdown.

The per-device files in the table are for fine-tuning that default coverage, not for adding tracker blocking from scratch. Use them to block (or, by leaving one out, effectively allow) tracking from one specific vendor rather than all of them at once, useful if you want stronger native-tracker coverage without moving all the way up to Ultimate. When combining these with your Main Tier, you might occasionally need to manually unblock a specific tracker if something breaks.

List Name What It Does Already in Main Tiers Best For File Name (Adblock)
Native Tracker Per-vendor lists blocking built-in trackers baked into devices, apps, and operating systems (Amazon, Apple, Huawei, Microsoft, Samsung, TikTok, LG webOS, Roku, Vivo, OPPO/Realme, Xiaomi). All tiers, at four increasing strengths: Light and Normal share the baseline; Pro blocks more than that; Pro++ blocks nearly all of them; Ultimate is the only tier with full coverage Privacy nerds who want fine-grained control over which vendor's trackers get blocked native.amazon.txt, native.apple.txt, native.huawei.txt, native.winoffice.txt, native.samsung.txt, native.tiktok.txt, native.tiktok.extended.txt, native.lgwebos.txt, native.roku.txt, native.vivo.txt, native.oppo-realme.txt, native.xiaomi.txt

Referral Lists

Two opposite, optional lists for handling affiliate and referral tracking links, on top of whatever your Main Tier already does (see Main Tiers above: Light and Normal block none, Pro blocks a few, Pro++ and Ultimate block a few more). Neither list is bundled into any Main Tier. Use at most one of these two lists, they solve the same problem in opposite directions.

List Name What It Does Notes Best For File Name (Adblock)
Referral Allowlist Keeps known affiliate and tracking links unblocked on purpose, since they're normally only triggered by a manual click, not loaded automatically. Also prevents you getting trapped by broken newsletter unsubscribe links. The only referral list that ships with a ControlD folder. Not a blocklist, this is a deliberate carve-out Anyone running Pro++ or Ultimate who wants the referral domains those tiers already partially block to keep working whitelist-referral.txt (AdGuard style), whitelist-referral-native.txt (Pi-hole v6+/TechnitiumDNS style)
Referral Blocklist Opt-in list to actually block referral and affiliate tracking domains. Not recommended for network-wide DNS use since it can break search results and newsletter unsubscribe links. No ControlD folder for this one. Aggressive, opt-in only Advanced users who specifically want referral tracking gone, best applied in a browser content blocker like uBlock Origin instead of at the DNS level blocklist-referral-native.txt

Don't feel like clicking through folders and renaming files by hand? The Direct Link Generator puts your download links together for you.

Pick a source and a format, or just tell it which app or device you use and it sets the format for you. Then pick one Main Tier, tick whatever add-ons you want, and every matching link shows up at the bottom. There's a copy button per link and a Copy all links button for the whole set.

The useful part is that it knows what overlaps. Pick Pro and the Fake list greys out, because Pro already carries it. Tick an NRD band and DGA locks, because you want one or the other, never both. The two referral lists behave the same way, since which one makes sense depends on your tier. And the full TIF list in RPZ format comes as both of its files automatically, so you can't end up subscribed to half of it. Lists that are unusually large, or powerful enough to cause trouble if you enable them blindly, carry a small badge as well. You get a set that fits together, not just a pile of links.

The source starts on DNSBunker, this mirror, which is the freshest option. You can switch it to jsDelivr, GitHub, GitLab, or Codeberg if you'd rather pull from one of those, and the links change with it.

Note

What it doesn't cover. It handles the five most common formats: Adblock, DNSMasq, Wildcard (Asterisk), Wildcard (Domains), and RPZ. If your tool needs AdGuard, ControlD, Subdomains, Hosts, Hosts Compressed, or IPs, use the file browser above instead. NRD, DGA, and the referral lists only appear when the format is Adblock or Wildcard (Domains). A few lists follow their own naming scheme and aren't in the generator at all: Most Abused TLDs, DNS Rebind Protection, the IP variants of TIF and DoH, and the ControlD folders.


🔎 Blocklist Lookup

Wondering whether a specific domain or IP is blocked, and which list is doing it? Check it here: Blocklist Lookup

Paste in one entry or a whole batch, one per line and up to 50 per query, hit Search, and you get a card per entry listing every list that blocks it along with the exact rule. Domains and IPv4 addresses both work, so you can check something like ads.tracker.net and 1.1.1.1 in the same run. Wildcard patterns like *.example.com work too, listing every matching rule, and you can paste a full URL or bracketed notation (example[.]com) straight in. It reads the lists straight from this mirror, so the results always reflect the newest build.

It's subdomain-aware too. Look up region1.app-measurement.com and you'll see the match comes from ||app-measurement.com^, a wildcard on the parent domain, not an entry for that exact hostname.

It also follows CNAME chains, up to 8 hops. A domain that isn't on any list itself still gets flagged if it points at something that is, which is exactly how CNAME cloaking hides trackers behind a harmless looking first-party name. The result then shows the full chain, so you can see where the block actually comes from.

Three things it's especially good for:

The NRD and DGA lists aren't searched by default. They're very large and including them slows the search down noticeably, so tick Include NRD and DGA lists only when you specifically want to know whether a domain is caught as a newly registered or algorithm-generated domain.

Note

The Lookup reads the published lists, not your own setup, and it doesn't judge whether a domain is harmful. Your own allowlist, extra lists from other projects, or a local copy that hasn't refreshed yet can all make your network behave differently.


🏬 DNS Resolver Services

Don't want to run your own DNS server or config at all? Use one of these managed resolvers instead, free, non-commercial public resolvers for Europe that mix privacy and security with minimal restrictions. The full protection endpoints run the Pro and Threat Intelligence Feeds blocklists; the security-only endpoint further down runs Threat Intelligence Feeds alone, so ads and trackers stay untouched there. Handy for protecting your phone even when you're off your home Wi-Fi.

Which protocol? Use DoH (or DoH3, the faster variant) if your device or router supports encrypted DNS, that's most modern systems. DoT and QUIC are alternatives some tools prefer. Do53 is classic unencrypted DNS, use it only if nothing else works. On iPhone, iPad, or Mac, skip the manual setup entirely: the Apple Config column links a configuration profile that sets up the encrypted server with one tap.

DNS Resolver Services overview comparing DNSBUNKER.org and HaGeZi DNS Full Protection and Security-only resolvers, including privacy features, supported protocols, locations, filtering profiles, and Apple profile availability

🏬 DNSBUNKER.org

Full details: project page.

Full protection (ads, tracking, analytics, telemetry, phishing, malware, scam, cryptojacking, and other harmful domains)

Location Protocols Endpoint Apple Config
Germany, Frankfurt DoH / DoH3 https://dnsbunker.org/dns-query Download
DoT / QUIC dnsbunker.org
Do53 Not supported

Blocklist(s) in use: Pro and TIF

🏬 HaGeZi DNS

Full details: project page.

Full protection (ads, tracking, analytics, telemetry, phishing, malware, scam, cryptojacking, and other harmful domains)

Location Protocols Endpoint Apple Config
Germany, Falkenstein DoH/DoH3 https://root.hagezi.org/dns-query Download · QR
DoT/QUIC root.hagezi.org
Do53 188.34.161.210 · 2a01:4f8:c17:1c66::1
Germany, Nuremberg DoH/DoH3 https://wurzn.hagezi.org/dns-query Download · QR
DoT/QUIC wurzn.hagezi.org
Do53 159.69.155.94 · 2a01:4f8:1c1c:d363::1
Finland, Helsinki DoH/DoH3 https://juuri.hagezi.org/dns-query Download · QR
DoT/QUIC juuri.hagezi.org
Do53 95.217.163.17 · 2a01:4f9:c013:dc4e::1

Blocklist(s) in use: Pro and TIF

Security-only (phishing, malware, scam, cryptojacking, and other harmful domains)

Location Protocols Endpoint Apple Config
Germany, Nuremberg DoH/DoH3 https://ctif.hagezi.org/dns-query Download · QR
DoT/QUIC ctif.hagezi.org
Do53 162.55.58.40 · 2a01:4f8:1c19:6c19::1

Blocklist(s) in use: TIF


💫 Support

Important

Spot a domain that got blocked by mistake, or one that should be on the naughty list but isn't? Drop a report on the blocklist repo's issue tracker or shoot an email to support@hagezi.org. Prefer chatting? Swing by the official Matrix support chat.

To get your report resolved quickly, include the exact domain, which list and tier you're using (for example Pro or Ultimate), and, for a false positive, what actually broke (a specific site, app, or feature) so it can be reproduced. If your tool keeps a query log, a quick look there confirms the exact domain responsible, and the Blocklist Lookup tells you which lists block it and with which rule.


🔤 Glossary

Short explanations of terms used on this page. For the full glossary with around 90 entries, see the detailed documentation.

Basics

Term What it means
DNS The system that translates website names like example.com into the numeric IP addresses computers use to find each other. Every blocklist here works by intercepting those translations for unwanted domains.
DNS filter / DNS server Software that performs those translations for your network and can refuse them for listed domains. Pi-hole, AdGuard Home, and TechnitiumDNS are common examples.
Blocklist A list of domains that get blocked so they can't load.
Wildcard A single entry that automatically covers a domain and all of its subdomains, so example.com also catches ads.example.com. Formats without it have to spell out every subdomain by hand.
Allowlist (whitelist) The opposite. Domains here always get through, even if a blocklist would otherwise catch them. Adding a domain here is what "unblocking" means.
False positive A domain that gets blocked by mistake even though it isn't harmful, usually breaking a website or app feature.
Query log A record most DNS tools keep of every domain lookup, showing which ones were allowed and which were blocked. The fastest way to find out which domain broke a site.
Blocklist Lookup The web tool on this mirror that checks one or more domains or IPv4 addresses against every published list and shows which lists block them, and with which rule. Follows CNAME chains and understands wildcard rules on parent domains, see Blocklist Lookup.
Direct Link Generator The web tool on this mirror that puts download links together for you: pick a format, tick the lists you want, copy them all at once. It also greys out anything your chosen tier already covers, see Direct Link Generator.
Mirror An exact copy of a project hosted elsewhere, so the lists stay reachable if the main source is down. This page is one.
Base URL The first part of a download link, everything before the format folder. Swapping it is all it takes to move from one mirror to another.

Connection protocols

Term What it means
Do53 Classic, unencrypted DNS over port 53. The name literally means "DNS over port 53".
DoH / DoT DNS-over-HTTPS and DNS-over-TLS, two ways of encrypting DNS traffic so it can't be read or tampered with in transit.
DoH3 / QUIC Newer variants that run over QUIC, a faster, UDP-based connection, instead of classic TCP.
Apple Config (mobileconfig) A settings file for iPhone, iPad, and Mac that installs an encrypted DNS server with one tap, instead of typing the settings in by hand.
Brave aggressive mode The Brave browser only applies these lists when its shielding is set to aggressive blocking. On the default setting it ignores most of them, which is why the format table says "aggressive mode".

Formats

Listed in the same order as the Supported Formats table above.

Term What it means
Adblock The classic filter-rule format used by ad blockers and most DNS filters. The most widely supported option, and the format all file names on this page refer to.
AdGuard AdGuard's own extended syntax, with rules that go beyond plain domain blocking, such as DNS rewrites and regular expressions. Only AdGuard and AdGuard Home understand it.
ControlD Not a list of domains but a JSON file, imported into a ControlD profile as a reusable folder of rules.
DNSMasq A lightweight DNS and DHCP program, often running on routers or small home servers, with its own config-line format.
Subdomains A plain list of domains with every subdomain spelled out individually. One of the two legacy formats, see the note under the format table.
Hosts The classic hosts-file format: one domain per line, prefixed with 0.0.0.0. Also a legacy format.
Hosts, Compressed The same as Hosts, but with up to nine domains per line, which keeps the file smaller for tools that can read it.
IPs A plain list of IPv4 addresses instead of domains, for firewalls and IP-level blocking.
RPZ Response Policy Zone, a DNS server feature (Bind, Knot, PowerDNS, Unbound) that applies blocklists directly at the server level.
Wildcard, Asterisk Domains written with a leading asterisk, like *.example.com, for tools that expect that notation.
Wildcard, Domains Plain domain names that the listed software treats as wildcards on its own. Ships as *-onlydomains.txt rather than *.txt.

Threats and list terms

Term What it means
Phishing Fake websites or messages that try to trick you into handing over passwords, banking details, or other sensitive info.
Malware Malicious software of all kinds: viruses, trojans, spyware. Infects a device, steals data, or lets someone control it remotely.
Badware Umbrella term for domains involved in anything harmful, from malware and scams to abusive hosting, without naming one specific category.
Metrics / telemetry Usage data a site or app collects about itself, such as page views, load times, or click paths. Blocked from the Light tier upwards.
Cryptojacking A website or app secretly using your device's processing power to mine cryptocurrency in the background.
C2 (command and control) A server attackers use to remotely control malware already running on infected devices. Threat Intelligence Feeds specifically target their domains.
NRD Newly Registered Domain. Threat actors like fresh domains because security tools haven't flagged them yet.
DGA / high entropy Domain Generation Algorithm, a technique malware uses to generate large numbers of random-looking domains. "High entropy" describes exactly that randomness: xj4k9qz2.com versus news-site.com.
TLD Top-Level Domain, the last part of a domain name like .com or .de. Some, like .top or .gdn, get abused for spam and scams far more often than others.
Referral / affiliate domain A domain used in tracking or commission links, common on deal sites, in emails, and in search results. These usually only fire when you click a link, unlike ads, which load automatically.
Crash/error tracker Tools like Sentry, Crashlytics, or Firebase that apps use to report crashes back to developers. A form of telemetry, so blocking them is a privacy gain but can hide real bugs from the developer.

⚠️ Disclaimer

Important

Scope. This disclaimer applies to these DNS blocklists and to the related lists published by the project, including the NRD/DGA lists and the legacy format lists (together, "the Lists"). The Lists are created and maintained by HaGeZi ("the Provider"), who also publishes them to this mirror; the mirror infrastructure itself is operated by DNSBUNKER.org under HaGeZi's authorization and only hosts the files. This disclaimer does not extend to any other service either party may separately operate (e.g., public DNS resolvers, or the domain lookup tool and the link generator on this mirror), which may be subject to its own terms.

No warranty. The Lists are provided free of charge, "as is" and "as available," with no warranty of any kind, express, implied, or statutory. The Provider makes no promises about accuracy, completeness, timeliness, reliability, or fitness for any particular purpose. There's no guarantee that every malicious or unwanted domain is covered, and no guarantee that legitimate domains won't get blocked by mistake. The Lists are compiled in part from third-party sources; the Provider does not control and is not responsible for errors originating in those sources.

No accusation, no endorsement. A domain showing up on a list is a technical filtering decision, not a legal finding and not a claim that whoever operates it did anything wrong. Categorization is based on third-party threat data, public rankings, and observed behavior, and any of that can be outdated or simply wrong. Brand names, domain names, and trademarks mentioned in the Lists or in this documentation belong to their respective owners and are used for identification only. If you operate a domain and think it's listed by mistake, ask for a review through the issue tracker or by mail at support@hagezi.org. Review and removal requests are handled on a best-effort basis, with no guaranteed response time.

Assumption of risk. Using the Lists is entirely at your own risk. The Provider disclaims any and all direct, indirect, incidental, or consequential liability for damages arising from using, misusing, or being unable to use the Lists, except where such damages result from willful misconduct or gross negligence on the Provider's part, or from death or personal injury caused by the Provider's negligence. Mandatory statutory liability that can't be excluded by agreement stays unaffected, whatever the wording above says.

A supplement, not a substitute. The Lists are meant to be one part of a broader defense-in-depth strategy, not the whole thing. They don't replace your own responsibility to do due diligence, run your own risk assessments, or use additional protections (firewalls, antivirus/EDR, IDS/IPS, etc.). There's no guarantee of compatibility with any specific system, platform, or setup. Nothing in the Lists or in the surrounding documentation is legal advice or professional security advice.

Your setup, your responsibility. You're responsible for making sure the way you deploy the Lists is legal where you are. That matters most when you filter a network other people use (family, guests, employees, students, customers) and when you use lists that restrict access rather than block threats, such as NSFW, Social Networks, Gambling, Anti Piracy, or the DoH/VPN/Tor/Proxy Bypass list. Employment, telecommunications, and data-protection rules can all come into play. The Provider offers no guidance on this and takes no responsibility for how the Lists are deployed.

Third-party services and software. DNS services, software, mirrors, and other projects linked or listed here are run by their respective operators, not by the Provider. Being mentioned is not an endorsement, and how those parties host, configure, delay, or modify the Lists is outside the Provider's control. Their own terms and privacy policies apply, including those of the platforms you download from.

No guarantee of availability, fair use. The Lists are a free, personal/community project, made available internationally, and no one is automatically entitled to their continued availability. The Provider may modify, suspend, restrict, or discontinue the Lists (in whole or in part) at any time and for any reason, including excessive query volume or abusive or disproportionate use, without notice and without liability, and is under no obligation to maintain, update, or continue providing them. The Provider makes reasonable efforts to fix faults once discovered, but does not guarantee any particular response or resolution time.

Redistribution and licensing. The Lists are published under the GNU General Public License v3.0 (GPL-3.0). A copy of the license is included alongside the Lists and has to accompany any redistribution. You may redistribute, modify, and adapt the Lists only under the terms of that license. This disclaimer applies in addition to, and does not replace, the warranty and liability terms already contained in the GPL-3.0 (Sections 15 to 17). Some inputs come from third-party sources with their own licenses or terms of use. GPL-3.0 covers the Lists as published here; it doesn't hand you any rights in the upstream data itself, so if you build on that data directly, checking those terms is on you. It's on you to read, understand, and follow the license terms before using or redistributing anything.

Governing law. The Provider is based in Germany, and the Lists are made available for international use. This disclaimer is governed by the laws of Germany, without regard to conflict-of-law principles, to the extent permitted by applicable law. Nothing in this disclaimer limits any mandatory consumer-protection rights you may have under the law of your country of residence.

Severability. If any provision of this disclaimer is found invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision will be replaced by a valid one that most closely reflects its intended effect.

Changes to this disclaimer. The Provider may update this disclaimer from time to time. The version published alongside the Lists at the time of your access or use applies. Continued use of the Lists after an update constitutes acceptance of the updated disclaimer.

Accepting these terms. By accessing, downloading, or using these DNS blocklists, you agree to be bound by everything laid out in this disclaimer. If you do not agree, do not access, download, or use the Lists.


Privacy Information (Cloudflare Analytics)

We use Cloudflare Web Analytics, provided by Cloudflare, Inc., to monitor page performance and optimize server caching.

This service operates without cookies or local storage access, and does not track users across websites or create personal profiles. Only aggregated, privacy-friendly performance metrics (such as load times and cache efficiency) are processed.

Legal basis: The processing is based on our legitimate interest in providing a fast, secure, and technically optimized blocklist mirror (Art. 6(1)(f) GDPR).