# AdAway: a hosts-file and local VPN ad blocker for Android

> AdAway is a GPL-3.0 Android ad blocker that filters through the hosts file or a local VPN. Here is how the two modes differ, how to install it, and where it stops being the right tool.

**AdAway/AdAway** — AdAway is a free and open source ad blocker for Android. 

- Repository: https://github.com/AdAway/AdAway
- Website: https://adaway.org
- Stars: 9,457 · Forks: 718
- Language: C
- License: GPL-3.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/adaway-adaway

## What AdAway blocks, and what it leaves alone

AdAway is an ad blocker for Android that works at the name resolution layer rather than inside a browser. The README describes it as "an open source ad blocker for Android using the hosts file and local vpn." That single sentence defines both its reach and its ceiling. Because filtering happens below the app, every application on the device that resolves a hostname is subject to the same blocklist. A game's interstitial ad, a news app's tracking pixel and a browser's banner all disappear through the same mechanism, with no per-browser extension to install and no browser to choose.

The audience follows from that. This is for people who want a device-wide filter and are comfortable managing a list of hosts sources themselves. It is not a content blocker with cosmetic filtering, so it will not hide the empty box where an ad used to be. It is not a firewall with per-app rules either. The QUERY_ALL_PACKAGES permission exists so the user can pick applications to exclude from the VPN, which is an exclusion list, not a routing policy. If you want to allow one app and block another on the same domain, this is the wrong layer.

## Two filtering paths: hosts file versus local VPN

The repository supports two distinct mechanisms, and the difference matters more than any feature list.

In the hosts-file mode, AdAway writes blocked hostnames into the system hosts file. Name resolution then fails for those domains before any connection is attempted. This is the older and lighter approach, and it requires root, because the system hosts file lives in a protected location. Nothing runs in the background to filter traffic, so there is no persistent service and no battery cost from a tunnel.

In the local VPN mode, AdAway runs a VPN service on the device that intercepts DNS traffic and answers blocked names itself. No root is needed. The cost is structural: Android allows only one active VPN at a time, so enabling AdAway's VPN means you cannot simultaneously run another VPN app, and the FOREGROUND_SERVICE permission is required to keep the service alive. The README also lists ACCESS_NETWORK_STATE "to restart VPN on network connection change" and RECEIVE_BOOT_COMPLETED "to start the VPN on boot," which tells you the service is expected to persist across reboots and network switches. POST_NOTIFICATIONS exists so the VPN controls and update notices can be posted, and the README notes all notifications can be enabled or disabled independently.

The data flow is therefore: AdAway downloads hosts files from sources you configure, merges them into a blocklist, and then either writes that list to the hosts file or feeds it to the local DNS responder inside the VPN service. The blocklist is the artifact; the two modes are just two ways of enforcing it.

## Installing AdAway and running a first update

The README splits releases into two tracks. Preview builds are described as "on the bleeding edge of development" for testers, and stable builds as "ready for every day usage." Both require Android 8 Oreo or above. Stable builds are posted to F-Droid, and the README also links direct APK downloads from the official website for both tracks. For devices older than Android 8, the README says to use version 4 of AdAway.

The README does not document a build command, and it does not list a package manager install step. What it does give is the source of the APK: the stable build is linked from the official website and from F-Droid, and the preview build is linked from the official website and the XDA development thread. Those links are the install path.

On the device, the first real task is picking hosts sources. The README points to the wiki page HostsSources for "an assorted list of sources you can use in AdAway," and says to add the ones you like to the "Hosts sources" section of the app. There is no bundled default list described in the README, so the first run is genuinely a configuration step rather than a one-tap enable.

After adding sources, the app downloads and merges them. In root mode this ends with a hosts file write; in VPN mode the merged list is handed to the local responder and the VPN is started. The README's permission list is the clearest signal of what to expect on first launch: a notification permission prompt, a VPN consent dialog, and, in VPN mode, a persistent notification for the foreground service.

## Where AdAway is the wrong tool

The most concrete limitation is the one-VPN rule. Android permits a single active VPN connection, and AdAway's non-root mode occupies it. Anyone who needs a corporate VPN, a commercial privacy VPN, or a DNS-based filtering profile active at the same time will have to choose. Root mode avoids the conflict entirely, which is why the root path remains attractive despite the extra setup.

The second limitation is that hostname blocking is coarse. It cannot distinguish an ad request from a legitimate API call on the same domain, so aggressive sources can break logins, media playback or in-app purchases. The README offers no rollback guidance and no allowlist documentation beyond the per-app VPN exclusion, so a bad source is diagnosed by removing it. That is a manual loop.

The third is platform reach. The README's requirements are explicit about Android 8 and above, and it directs older devices to version 4. There is no iOS, desktop or router build described. If your goal is to block ads across a household rather than on one handset, a DNS resolver at the network level fits better.

Finally, the QUERY_ALL_PACKAGES permission is broad by design and exists to populate the VPN exclusion picker. That is a legitimate use, but it is the kind of permission that draws scrutiny in app store review, which is consistent with the project distributing through F-Droid and its own website rather than depending on a single store.

## How AdAway compares with a DNS resolver such as Pi-hole

Pi-hole and AdAway solve overlapping problems at different layers. Pi-hole runs on a server on your network and answers DNS for every device that points at it. AdAway runs on the phone and filters only that phone.

The practical difference is coverage versus portability. A Pi-hole protects a television, a laptop and a phone with one blocklist and one place to edit it, but it does nothing when the phone leaves the house on cellular data unless you also configure a VPN back home. AdAway keeps working wherever the device goes, but every device needs its own install and its own source list. There is no shared configuration between them described in the README.

The second difference is enforcement. Pi-hole is a DNS server, so a client that hardcodes a different resolver bypasses it. AdAway's VPN mode intercepts DNS on the device itself, which is harder to route around from inside an app, though it still applies only to that device. If you already run a home resolver and want mobile coverage, the two are complementary rather than competing; if you want one install and no server, AdAway is the simpler shape.

## Maintenance, licence and what GPL-3.0 means here

The repository is not archived, and the last push was on 2026-09-13. Releases move more slowly than commits: the most recent listed release is v6.1.4 from 2024-10-27, preceded by v6.1.3 and v6.1.2 earlier in 2024. So the codebase sees ongoing work while tagged stable releases are spaced out. Users who want fixes before they are tagged are pointed by the README at preview builds from the XDA thread and the official website.

Upgrade cost is low in normal use. In VPN mode the app updates itself through the builtin updater, which is why REQUEST_INSTALL_PACKAGES is requested; F-Droid installs update through F-Droid. Root-mode users should expect to re-apply the hosts file after a system update, since the file is part of the system partition's state, though the README does not spell out that procedure.

AdAway is licensed under GPLv3+, with the full text in LICENSE and additional notes in LICENSE.md. The practical implication for most users is none: you install and run it. For anyone redistributing a modified build, the copyleft terms apply to the distributed work, and the repository carries a THIRD_PARTY_LICENSES.md alongside its own licence. This is a description of the project's stated terms, not legal advice; read LICENSE.md before redistributing.

On privacy, the README states that INTERNET permission is used to download hosts files and application updates, and that bug reports and telemetry are sent "if the user wants to (opt-in only)," linking to a wiki page on telemetry. That opt-in framing is the detail worth checking against your own expectations.

## Conclusion

Adopt AdAway if you run Android 8 Oreo or above and want an ad blocker whose source code you can read, whose hosts sources you choose yourself, and whose telemetry is opt-in. Do not adopt it if you need per-app filtering rules, if your device is older than Android 8 (the README points those users at version 4), or if you are unwilling to accept a persistent VPN notification in non-root mode. Before installing, verify which mode your device supports, since the hosts-file path needs root and the VPN path does not, and read the HostsSources wiki page to pick sources rather than trusting a bundled default.

## FAQ

### What is AdAway?

AdAway is a free and open source ad blocker for Android that filters using the hosts file and a local VPN. It is licensed under GPLv3+ and requires Android 8 Oreo or above.

### How does AdAway work?

It downloads hosts files from sources you configure and merges them into a blocklist, then either writes that list to the system hosts file (root mode) or enforces it through a local VPN service that intercepts DNS (non-root mode).

### Can I use AdAway without root?

Yes. The local VPN mode needs no root, but Android allows only one active VPN, so it cannot run alongside another VPN app. The hosts-file mode does require root.

### Is AdAway safe to use?

The project is open source under GPLv3+ and the README states that bug reports and telemetry are sent only if the user opts in. Its permissions are documented, including QUERY_ALL_PACKAGES, which is used to let the user pick apps to exclude from the VPN.

### How do I install AdAway on Android?

Stable builds are published to F-Droid and the official website, and preview builds come from the XDA development thread and the website. Both require Android 8 Oreo or above; the README directs older devices to version 4.

## Sources

- [AdAway/AdAway on GitHub](https://github.com/AdAway/AdAway)
- [License: GPL-3.0](https://github.com/AdAway/AdAway/blob/master/LICENSE)
- [Project website](https://adaway.org)
- [README](https://github.com/AdAway/AdAway/blob/master/README.md)
- [Releases](https://github.com/AdAway/AdAway/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/adaway-adaway
