For an open source alternative to Pi-hole, the first results are pi-hole/pi-hole (Pi-hole is the flagship self-hostable DNS sinkhole and network-wide ad blocker, featuring a built-in web administration dashboard, query logging, and custom blocklist management), geerlingguy/internet-pi (This project configures a Raspberry Pi as a network-wide DNS sinkhole and performance monitor, serving as a self-hostable home ad-blocker with management tools) and pi-hole/docker-pi-hole (This repository provides a containerized implementation of the network-wide DNS sinkhole, offering local network integration, a web administration interface, and custom blocking lists as required). adguardteam/adguardhome and 0xerr0r/blocky round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
We curate open-source GitHub repositories matching “open source alternatives to pi-hole”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.
Pi-hole is a self-hosted network utility that functions as a DNS sinkhole server to provide network-wide ad blocking. By acting as a dedicated network gateway, it intercepts and discards requests for known advertising, tracking, and malicious domains across an entire local network, preventing unwanted content from loading on any connected device. The software operates through a lightweight background daemon that handles high volumes of concurrent DNS queries with minimal resource overhead. It utilizes a host-file injection mechanism to redirect traffic toward its local filtering engine and ap
Pi-hole is the flagship self-hostable DNS sinkhole and network-wide ad blocker, featuring a built-in web administration dashboard, query logging, and custom blocklist management.
Internet-pi is a network appliance configuration for Raspberry Pi that provides automated network provisioning, telemetry tracking, and DNS-based sinkhole services. It functions as a home network gateway and monitoring station. The project integrates a DNS sinkhole for network-wide advertisement and tracking blocking, alongside local DNS resolution for connected devices. It includes an internet performance monitor to track connection uptime, ping statistics, and bandwidth speed tests over time. The system further incorporates an IoT device dashboard for collecting and visualizing real-time m
This project configures a Raspberry Pi as a network-wide DNS sinkhole and performance monitor, serving as a self-hostable home ad-blocker with management tools.
This project provides a containerized DNS sinkhole and network-wide traffic filtering solution. It functions as a central network resolver that intercepts domain queries, allowing users to block advertisements, trackers, and malicious domains by returning null responses to connected devices. The platform distinguishes itself through its integrated DHCP server and comprehensive management capabilities, which allow for automated IP address allocation and granular control over network traffic. It supports complex filtering through regular expression matching, hierarchical rule prioritization, an
This repository provides a containerized implementation of the network-wide DNS sinkhole, offering local network integration, a web administration interface, and custom blocking lists as required.
AdGuardHome is a network-wide software solution that provides centralized control over domain name resolution, content filtering, and local network management. It functions as a recursive DNS server and DHCP address server, intercepting network traffic to enforce security policies and block unwanted content across all connected devices. By acting as a central gateway, it ensures that every device on a home or office network benefits from consistent protection and private, authenticated name resolution. The software distinguishes itself through granular client management and robust security fe
AdGuardHome is a self-hostable network-wide DNS ad blocker and sinkhole featuring a web administration interface, query logging, custom blocklists, and local network integration.
Blocky is a stateless DNS proxy that functions as a network-wide ad-blocker and content filter. It operates as a single binary or Docker container with no database or persistent state, accepting DNS queries over UDP, TCP, HTTPS, TLS, QUIC, and HTTP/3 through a unified plugin-based query pipeline. The core of the system is a client-group policy engine that assigns devices to named groups and applies per-group blocklists, allowlists, and upstream resolvers, with all configuration changes applied through hot-reloading without requiring a restart. The project distinguishes itself through its modu
Blocky is a self-hostable network-wide DNS ad blocker with custom blocking lists, query logging, and a web administration interface, though it uses a stateless design without a persistent database rather than traditional local state storage.
DnsServer is a recursive and authoritative DNS server that provides domain name resolution and zone hosting. It functions as both a recursive resolver, performing iterative lookups across the internet, and an authoritative manager for primary and secondary DNS zones. The system distinguishes itself through high-availability clustering and a programmable HTTP API for automating server configurations and bulk record management. It supports a wide range of encrypted transport protocols, including TLS, HTTPS, and QUIC, and allows for custom functionality via a plugin-based request interception fr
Technitium DNS Server is a fully-featured recursive and authoritative DNS server that supports domain blocking and query management, making it an effective self-hostable network sinkhole even though it is primarily designed as a general-purpose DNS platform.
Wirehole is a containerized network stack that integrates a WireGuard VPN server with recursive DNS resolution and sinkhole-based advertisement filtering. It bundles these interdependent services into a single managed environment using a compose-based deployment. The system enables network-wide ad blocking and tracker filtering by intercepting DNS queries via a sinkhole. It implements recursive DNS resolution to resolve domain names independently of external upstream providers and provides a web-based interface for managing VPN client peers and keys. Additional capabilities include split-tun
Wirehole is a containerized network stack that combines a WireGuard VPN with DNS ad-blocking, but it acts as a deployment orchestrator rather than a standalone DNS sinkhole application.
This project is an adblock filter list aggregator and DNS blocklist generator. It merges multiple blocking rule sources into a single deduplicated set and processes these rules into formatted lists compatible with DNS servers, browser extensions, and network proxy tools. The system includes a domain resolvability validator that checks filter lists against global DNS services to remove unreachable or invalid domains. It also features a filter rule parser that extracts target domains and IP addresses from complex syntaxes while removing comments. The project covers rule aggregation, syntax-awa
This project provides a blocklist generator and rule aggregator rather than a self-contained DNS sinkhole and ad blocker server, making it a useful companion tool rather than the network-wide blocking application you are looking for.
This project is a comprehensive repository of curated domain blocklists designed for network-wide DNS filtering. It functions as a DNS sinkhole feed, providing the necessary data to intercept and block unwanted network requests at the resolution layer before they reach their destination. By returning null or loopback addresses for identified domains, it prevents connections to malicious infrastructure, advertising servers, and tracking endpoints across all devices on a network. The repository distinguishes itself through a tiered categorization logic that allows users to select protection lev
This repository provides curated domain blocklists for network-wide filtering rather than the actual DNS sinkhole software required to host and run them.
This project is a DNS privacy proxy and resolver that functions as a local bridge, converting plaintext DNS traffic into encrypted requests. It acts as a client for DNS-over-HTTPS and DNS-over-TLS protocols to prevent interception and spoofing of network requests. The system implements network privacy hardening by routing domain lookups through secure tunnels, which reduces the amount of plain text data leaked to internet service providers. It utilizes a profile-based connection management system to map security profiles to specific encrypted endpoints, preventing DNS hijacking and man-in-the
This project is a DNS privacy proxy and resolver rather than a network-wide DNS sinkhole with ad-blocking and administration features, making it a different category of tool.
This project provides a system-wide content filtering utility that controls network traffic by redirecting domain resolution requests to local null addresses. By mapping unwanted hostnames to these addresses at the operating system level, it effectively blocks connections to advertising, tracking, and malicious domains across all applications on a machine. The core of the system is a data-driven build pipeline that aggregates multiple curated source lists into a single, unified configuration file. This process is highly customizable, allowing users to employ declarative filtering logic throug
This project aggregates and generates unified hosts files for system-wide blocking, which makes it a useful blocklist provider rather than a self-contained DNS sinkhole with a web administration interface and query logging.
This project is a network security tool providing an application network firewall, a DNS blocklist manager, and a VPN client with multi-hop capabilities. It functions as a traffic controller that allows or blocks internet access for specific applications on a device. The system distinguishes itself through a DNS-over-HTTPS firewall and traffic obfuscation tools that inject random packets to mask communication patterns and bypass regional internet censorship. It utilizes multi-hop routing to hide the origin of network traffic by chaining connections through multiple remote servers. The softwa
This project is an Android-based application firewall and DNS tool for individual devices rather than a self-hostable, network-wide DNS sinkhole for local networks.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| pi-hole/pi-hole | 59.3K | Shell | NOASSERTION | |
| geerlingguy/internet-pi | 4.7K | Jinja | MIT | |
| 10.8K |
| Shell |
| other |
| adguardteam/adguardhome | 34.9K | Go | GPL-3.0 |
| 0xerr0r/blocky | 6.7K | Go | apache-2.0 |
| technitiumsoftware/dnsserver | 7.5K | C# | gpl-3.0 |
| iamstoxe/wirehole | 5K | — | — |
| 217heidai/adblockfilters | 7.1K | Python | gpl-3.0 |
| hagezi/dns-blocklists | 20.1K | Text | gpl-3.0 |
| paulmillr/encrypted-dns | 4.4K | JavaScript | unlicense |