π― What Pi-hole Actually Does
Pi-hole is a DNS sinkhole. When any device on your network tries to load ads.facebook.com or analytics.google.com, Pi-hole says "that doesn't exist." The tracking request dies before it leaves your network. No ads load. No trackers phone home. Your smart TV can't snitch. Your kids' tablets stay clean.
One Raspberry Pi protects everything: phones, computers, smart TVs, IoT devices, guests' devices. Everything.
The Truth About Pi-hole
What It Blocks
- Traditional display ads on websites
- Tracking pixels and analytics
- Malware and phishing domains
- Smart TV telemetry (Samsung, Roku, etc.)
- Windows telemetry (partially)
- Mobile app ads (many, not all)
- IoT device phone-home attempts
What It Can't Block
- YouTube ads (they come from same domain as videos)
- Facebook/Instagram sponsored posts
- Amazon product recommendations
- Any same-domain advertising
- VPN or encrypted DNS traffic
- Hard-coded IP addresses (some smart devices)
β οΈ Pi-hole Is Not Anonymous Browsing
Pi-hole blocks ads, not anonymity. Your ISP still sees what sites you visit. Websites still see your IP. You're just loading fewer trackers. For anonymity, you need Tor or VPN. Pi-hole is about blocking annoyances and reducing tracking, not hiding.
Streaming Services and Smart TVs: What Pi-hole Actually Does
A recurring question about Pi-hole is whether it removes ads from Netflix, Hulu, Disney+, Spotify or a smart TV's built-in apps. The answer turns on a distinction that is rarely drawn, and drawing it changes what anyone should expect from the box on their network.
There are two very different kinds of traffic involved:
- In-stream ads, which the service presents as part of playback and, in at least one documented case, serves from the same domain as the content. Where that is so, a DNS sinkhole cannot separate them from the thing being watched.
- Telemetry, analytics and viewing-data reporting, which travel to separate destinations from the content. That is the exact shape of traffic DNS filtering was built for.
Pi-hole describes itself in its own README as "a DNS sinkhole that protects your devices from unwanted content without installing any client-side software". It decides which domain names resolve, and nothing else. If an ad and a show share a name, the decision is all-or-nothing.
What the documentation actually establishes
YouTube. Covered earlier in this guide, and the project itself is the source for it. Pi-hole's FAQ on blocking YouTube ads states that "ads are typically served from the same domain as the video is" and that "it's not likely that you'll be able to block in-video ads with Pi-hole", calling it "a moving target". The last dated update on that page is 24 October 2020, so it is the project's stated position rather than a current test result.
Netflix, Hulu and Disney+. Here the honest answer is that the mechanism is not documented. Netflix's own help page on watching with ads confirms only that ads are part of playback: "You can't skip or fast-forward ads while watching TV shows and movies, but you can pause playback during an ad". The same page notes that ad breaks are shown on the progress bar when playback is paused. It says nothing about which domains or CDNs serve those ads. The equivalent Hulu and Disney+ help pages are rendered in the browser with JavaScript and returned no readable text, so nothing could be confirmed from them either way. Reasoning by analogy from YouTube would be a guess, and it is not offered here. What can be said is narrower: the vendor pages checked here say nothing about which domains serve those ads, and Pi-hole itself notes that it "sources its ad domains from third parties (blocklists)", so coverage of any given service is whatever those lists happen to contain.
Spotify. This one is settled outside the technical question. Spotify's User Guidelines list "circumventing or blocking advertisements or creating or distributing tools designed to block advertisements" among prohibited activities, and state on the same page that violations "may result in removal of any content or material you've contributed to the Services and/or termination or suspension of your account". Whatever a blocklist might or might not do, the attempt is against the terms of the account, with account action as the stated consequence. Not a recommended experiment.
Where DNS blocking does have reach
Smart TVs report on their owners through a channel entirely separate from the streams they play. In its 6 February 2017 enforcement action, the FTC and the New Jersey Attorney General announced that VIZIO agreed to pay $2.2 million to settle charges that it "installed software on its TVs to collect viewing data on 11 million consumer TVs without consumers' knowledge or consent". The agency described sets that "capture second-by-second information about video displayed on the smart TV, including video from consumer cable, broadband, set-top box, DVD, over-the-air broadcasts, and streaming devices". That is automatic content recognition, and it is a reporting stream with its own destinations, distinct from whatever app is playing.
Because that traffic goes somewhere else, it is structurally the kind of thing a DNS sinkhole is designed to intercept, in a way in-stream ads are not. No Pi-hole or manufacturer document establishes that it works in practice against any particular television, and no community blocklist is named here, because their real-world effectiveness is unverified. The settings-level approach is covered separately in the guide to disabling smart TV ACR surveillance.
One caution applies to any attempt at aggressive blocking. The Pi-hole FAQ post on tracking down ad domains notes that blocking can break things in ways that are hard to trace: "sometimes certain payment gateways try to collect metrics on the sale, but these domains are blocked by Pi-hole, so the payment cannot be processed". Links passing through a blocked referrer "may land on a blank page instead of the site you meant to go to". A blocklist that reaches too far tends to produce failures that look like broken sites rather than blocked ads.
The short version: the documentation supports a negative answer on in-stream ads only where the mechanism is actually documented, which is YouTube. For Netflix, Hulu and Disney+ it is not established either way. The separate reporting channel a smart TV runs is the part of this that DNS filtering is structurally aimed at, and its real-world effectiveness against any given set remains undocumented.
Hardware Requirements
Minimum (Works Fine)
- Raspberry Pi Zero W ($15)
- 4GB microSD card
- USB power adapter
- Total cost: ~$25
Handles home network easily
Recommended (Better)
- Raspberry Pi 3B+ or 4 ($35-45)
- 16GB microSD (quality matters)
- Official power supply
- Ethernet cable
- Total cost: ~$60
Faster, more reliable, handles heavy use
Alternative Options
- Old laptop/desktop
- Virtual machine
- Docker container
- Cloud VPS ($5/month)
- Spare Android phone (root)
Use what you have
Installation: The Real Steps
Prepare Your Pi
Flash the OS
- Download Raspberry Pi Imager:
https://www.raspberrypi.com/software/ - Insert microSD card
- Choose "Raspberry Pi OS Lite" (no desktop needed)
- Configure:
- Set hostname:
pihole - Enable SSH
- Set username/password (NOT default pi/raspberry)
- Configure WiFi if not using ethernet
- Set hostname:
- Write the image
First Boot
# SSH into your Pi
ssh [email protected]
# Or use IP if that doesn't work (find your Pi's IP from your router admin)
ssh [email protected] # Replace xxx with your Pi's actual IP
# Update everything first
sudo apt update && sudo apt upgrade -y
# Set static IP (important!)
sudo nano /etc/dhcpcd.conf Add to dhcpcd.conf:
interface eth0 # or wlan0 for WiFi
static ip_address=192.168.1.100/24 # Pick an IP outside DHCP range
static routers=192.168.1.1 # Your router's IP
static domain_name_servers=1.1.1.1 1.0.0.1 # Temporary upstream DNS Install Pi-hole
# One-liner installation
curl -sSL https://install.pi-hole.net | bash Installation prompts - what to choose:
- Upstream DNS: Cloudflare (1.1.1.1) or Quad9 (9.9.9.9) for privacy
- Blocklists: Keep defaults, add more later
- Protocols: Both IPv4 and IPv6
- IP address: Use the static one you set
- Web interface: Yes, install it
- Web server: lighttpd (default)
- Log queries: Your choice (privacy vs troubleshooting)
- Privacy mode: Show everything (for home use)
π Save the Admin Password!
At the end, Pi-hole shows a random admin password. SAVE IT. You need it for the web interface. To change it later: pihole -a -p newpassword
Configure Your Router
Three ways to use Pi-hole, from easy to best:
Option A: Device by Device (Testing)
Manually set DNS on each device to Pi-hole's IP. Good for testing, annoying long-term.
Option B: Router DHCP Settings (Recommended)
- Log into router admin panel
- Find DHCP settings
- Set Primary DNS: Your Pi-hole IP (192.168.1.100)
- Set Secondary DNS: Leave blank or use Pi-hole IP again
- Save and restart router
Option C: Pi-hole as DHCP Server (Advanced)
- Disable DHCP on router completely
- Enable DHCP in Pi-hole settings
- Pi-hole assigns IPs and forces its DNS
- Most reliable, but Pi offline = network offline
β‘ Quick Test
Visit: http://192.168.1.100/admin (your Pi-hole IP)
Should see the dashboard. Check "Queries Blocked" increasing = it's working.
Essential Configuration
Add Better Blocklists
Default lists are weak. Add these:
The Essentials
# OISD (comprehensive, well-maintained)
https://dbl.oisd.nl/
# Developer Dan's lists
https://www.github.developerdan.com/hosts/lists/ads-and-tracking-extended.txt
# NoTracking list
https://raw.githubusercontent.com/notracking/hosts-blocklists/master/hostnames.txt For Maximum Blocking
# Energized Ultimate (aggressive)
https://block.energized.pro/ultimate/formats/hosts
# The Block List Project
https://blocklistproject.github.io/Lists/ads.txt
https://blocklistproject.github.io/Lists/tracking.txt
https://blocklistproject.github.io/Lists/malware.txt To add: Web Interface β Group Management β Adlists β Paste URL β Add
Then update gravity: pihole -g
β οΈ Don't Go Crazy
More lists β better. Overlapping lists waste memory. 2-3 good lists block 99% of crap. Start conservative, add more if needed.
Whitelist Essentials
Some stuff breaks. Common fixes:
# Microsoft (if you use Windows/Office)
click.email.microsoftonline.com
officeclient.microsoft.com
# Banking apps often need
chase.com
wellsfargo.com
[your bank's domains]
# Shopping
amazon.com
ebay.com
target.com
# Streaming services
netflix.com
hulu.com Add via: Web Interface β Whitelist β Add domain
Configure DNS Settings
Enable DNSSEC
Settings β DNS β DNSSEC β Enable
Prevents DNS hijacking. Some ISPs break it. If internet stops working, disable it.
Conditional Forwarding
Makes local hostnames work (printer.local, nas.local):
- Enable: Yes
- Router IP: 192.168.1.1
- Domain: local (or home.arpa)
DNS Privacy (Advanced)
Use DNS-over-HTTPS to hide queries from ISP:
# Install cloudflared
wget https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-arm
sudo mv cloudflared-linux-arm /usr/local/bin/cloudflared
sudo chmod +x /usr/local/bin/cloudflared
# Configure as service (see Cloudflare docs)
# Point Pi-hole to 127.0.0.1#5053 Using the Dashboard
What to Watch
- Queries Blocked: Should be 15-40% for most networks
- Top Blocked Domains: Shows what's trying to track you
- Top Clients: Which devices query most (smart TVs are chatty)
- Query Log: Real-time DNS requests (privacy implications)
Suspicious Activity
Watch for:
- Thousands of requests to same domain (malware)
- Unknown devices (neighbors on your WiFi?)
- Weird domains at 3 AM (compromised IoT)
- Constant NTP requests (DDoS bot)
When Stuff Breaks
Site Won't Load
- Check Query Log for blocked domain
- Temporarily whitelist:
pihole -w domain.com - Test if it fixes issue
- Permanently whitelist if needed
Slow Internet
- Check Pi's CPU:
htop - Reduce blocklists
- Restart DNS:
pihole restartdns - Check upstream DNS response time
YouTube Ads Still Show
Normal. YouTube serves ads from same servers as videos. Options:
- Browser: uBlock Origin
- Mobile: YouTube Vanced/ReVanced
- TV: SmartTubeNext
Emergency Bypass
If Pi-hole dies and network breaks:
- Change router DNS back to 1.1.1.1 or 8.8.8.8
- Or set DNS manually on important devices
- Fix Pi-hole without pressure
Always know how to bypass in emergency!
Advanced Tricks
Per-Client Settings
Kids get stricter blocking than adults:
- Group Management β Groups β Add groups (Kids, Adults)
- Group Management β Clients β Assign devices to groups
- Group Management β Adlists β Assign lists to groups
- Kids get aggressive lists, adults get normal
Time-Based Rules
Block social media during homework:
# Cron job to enable/disable domains
# Block Facebook at 3pm
0 15 * * * pihole -b facebook.com instagram.com
# Unblock at 8pm
0 20 * * * pihole -b -d facebook.com instagram.com VPN Access
Use Pi-hole when away from home:
- Install PiVPN alongside Pi-hole
- Connect to home VPN
- All traffic routes through Pi-hole
- Ad-free browsing everywhere
Monitoring Specific Devices
See what your smart TV is doing:
# Watch Samsung TV queries in real-time
pihole -t | grep "samsung"
# Export specific device's history
sqlite3 /etc/pihole/pihole-FTL.db "SELECT * FROM queries WHERE client='192.168.1.50';" > tv_queries.txt Keeping It Running
Regular Updates
# Update Pi-hole
pihole -up
# Update OS
sudo apt update && sudo apt upgrade
# Update blocklists
pihole -g Backups
Settings β Teleporter β Backup
Saves all settings, lists, and configs. Store backup off-Pi.
SD Card Health
SD cards die. Reduce writes:
# Move logs to RAM
sudo nano /etc/fstab
# Add:
tmpfs /var/log tmpfs defaults,noatime,size=64M 0 0 Monitoring Health
# Check status
pihole status
# View diagnostics
pihole -d
# Check disk space
df -h
# Temperature (Pi only)
vcgencmd measure_temp Alternatives to Pi-hole
AdGuard Home
More modern UI, built-in DoH/DoT, easier setup. Heavier on resources. Good Pi-hole alternative.
NextDNS
Cloud-based, no hardware needed. $2/month. Easy but you trust someone else with your DNS.
pfBlockerNG
For pfSense routers. More powerful, more complex. Enterprise-grade.
The Bottom Line
Pi-hole is fantastic for:
- Blocking ads without installing software
- Reducing tracking across all devices
- Stopping smart TV telemetry
- Learning what's phoning home
- Protecting less technical family members
Pi-hole won't:
- Make you anonymous
- Block all ads (YouTube, Facebook)
- Protect outside your network
- Stop ISP surveillance
- Block malware perfectly
It's one layer of defense. Use it with:
- uBlock Origin in browsers
- VPN for anonymity
- HTTPS everywhere
- Good security practices
Start Small
$25 Raspberry Pi Zero. One hour setup. Blocks millions of tracking attempts. Every smart device you own is trying to phone home. Pi-hole stops them.
Your network. Your rules. No ads.
Related Guides
- Home VPN Server Setup - Combine Pi-hole with VPN for mobile ad-blocking anywhere
- Build Your Own Cloud VPN - Hide your location with a VPS-based VPN
- Self-Hosted Cloud Storage - Run Nextcloud on the same Raspberry Pi
- VPN Strategy Guide - When and how to use different VPN types