Open-source project
hagezi/dns-blocklists avatar
hagezi/dns-blocklists

HaGeZi DNS Blocklists block ads, trackers, and threats network-wide

DNS-Blocklists: For a better internet - keep the internet clean!

26,901 stars820 forksTextGPL-3.0

At a glance

What is it?
HaGeZi DNS Blocklists is a GPL-3.0 set of DNS blocklists that blocks ads, trackers, telemetry, phishing, malware, and scams network-wide, organized into five Multi tiers plus specialized standalone lists, in five standard formats.
Who is it for?
HaGeZi DNS Blocklists is a GPL-3.0, network-wide blocking project that organizes its coverage into five cumulative Multi tiers, a large Threat Intelligence Feeds add-on, and a wide set of specialized standalone lists for scams, pop-ups, new domains, rebind protection, NSFW content, and more. The same domains are published in five standard formats, from Adblock to RPZ, so the lists drop into Pi-hole, AdGuard Home, Unbound, and many other tools without conversion.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly Text, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

Editorial analysis

A network-wide set of DNS blocklists

HaGeZi DNS Blocklists is a set of DNS blocklists that block ads, trackers, telemetry, phishing, malware, scams, and other unwanted domains network-wide. The project is licensed under GPL-3.0 and states that the lists work for any region and with every common DNS server, ad blocker, and content blocker. The README frames the goal as making the internet a cleaner, safer place, and it notes the lists are built from various source blocklists that have been optimized and extended rather than simply concatenated.

The lists are designed to run standalone or alongside each other, and the documentation repeatedly emphasizes that a user should pick the tier and format that match their tool and risk tolerance. New users are pointed at Multi PRO plus the Threat Intelligence Feeds list as a starting combination, with a quick setup guide and a direct link generator offered to remove manual steps.

The five Multi tiers build on each other

The all-in-one Multi list ships in five versions named after cleaning tools: Light is the hand brush for basic protection, Normal is the broom for all-round protection, Pro is the big broom for extended protection and is recommended, Pro++ is the sweeper for advanced and more aggressive protection, and Ultimate is the ultimate sweeper for maximum and most aggressive protection. The documentation explains that the bigger the tool, the more thoroughly it cleans, and the more likely it is to sweep up something the user wanted to keep.

The first five tiers build on each other, so the guidance is to pick exactly one of them. The README's at-a-glance table lists entry counts that grow from Light at 39,461 entries through Normal at 200,527, Pro at 228,000, Pro++ at 254,846, and Ultimate at 281,865, with size-optimized mini versions available for the larger tiers. Each step up also raises the stated risk of breakage, from minimal on Light to high on Ultimate.

Standard formats and how to pick one

Most lists are published in the same five standard formats, and the blocked domains are identical across them, only the syntax differs. The Adblock format targets Pi-hole, AdGuard, AdGuard Home, eBlocker, uBlock Origin, Brave in aggressive mode only, AdBlock-Fast, AdNauseam, and Little Snitch Mini for smaller lists. DNSMasq targets DNSMasq 2.86 or newer and Diversion 5 or newer.

The remaining three are Wildcard Asterisk for Blocky 0.23 or newer, Nebulo, NetDuma, OPNsense, and YogaDNS; Wildcard Domains for DNSCloak, DNSCrypt, FRITZ!Box with FRITZ!OS 8.40 or newer, TechnitiumDNS, adblock-lean, PersonalDNSfilter, and InviZible Pro; and RPZ for Bind, Knot, PowerDNS, Unbound, and other Response Policy Zone software. A handful of lists, including Most Abused TLDs, DNS Rebind Protection, NRD/DGA, and the IP lists, do not follow this pattern and are documented per section.

Threat Intelligence Feeds as an add-on layer

The Threat Intelligence Feeds list, abbreviated TIF, targets malware, cryptojacking, scams, spam, and phishing, and it blocks domains known for spreading malware, running phishing attacks, and hosting command-and-control servers. Unlike the five Multi tiers, TIF works differently: it is an add-on covering live threats and is recommended to run alongside any tier rather than as a replacement for one.

TIF is the largest list by a wide margin, with 2,712,863 entries in its full form, and the documentation warns it can eat a lot of memory depending on the ad blocker. It is too big for the iOS AdGuard mobile app, AdGuard Home needs at least 2 GB of RAM for the full version, and the RPZ version is split into two files that both must be used. Medium and mini versions exist, at 872,903 and 183,386 entries, for blockers that struggle with the full size, and an IPv4 version is offered for firewalls.

Specialized standalone lists beyond the Multi tiers

Beyond the Multi tiers and TIF, the project maintains a long catalog of focused standalone lists. These include Fake for scam and fake sites at 17,257 entries, Pop-Up Ads for annoying and malicious pop-ups at 50,651 entries, Newly Registered Domains for disposable attacker domains, Dynamic DNS abuse protection, Badware Hoster, Most Abused TLDs, and DNS Rebind Protection.

Further standalone categories cover DoH, VPN, Tor, and Proxy bypass prevention, search engines that skip Safesearch, URL shorteners, anti-piracy, gambling, social networks, NSFW or adult content, and native trackers built into devices, apps, and operating systems. The documentation also offers a Direct Link Generator that selects the format for a chosen app or device and copies every download link in one go, plus a Blocklist Lookup to check any domain or IP against every list.

Entry counts and the trade-off of aggression

The README is explicit that entry counts change with every build, so the numbers in the tables are snapshots rather than guarantees. The central trade-off is spelled out in the cleaning-tools note: more aggressive tiers clean more thoroughly but raise the chance of blocking a domain the user wanted to keep, which is why Light carries minimal breakage risk while Ultimate carries high risk.

The project supports this with practical guidance rather than just bigger lists. The Pro tier is recommended as the personal go-to for solid blocking with little hassle, Pro++ is aimed at experienced users who can unblock mistakes, and Ultimate ships detailed known-issue notes for Facebook, Windows, and Xbox trackers plus location and IP trackers that may trigger extra CAPTCHAs or reduced functionality. The size-optimized mini versions let limited-hardware DNS or browser blockers still use the higher tiers.

Editorial conclusion

HaGeZi DNS Blocklists is a GPL-3.0, network-wide blocking project that organizes its coverage into five cumulative Multi tiers, a large Threat Intelligence Feeds add-on, and a wide set of specialized standalone lists for scams, pop-ups, new domains, rebind protection, NSFW content, and more. The same domains are published in five standard formats, from Adblock to RPZ, so the lists drop into Pi-hole, AdGuard Home, Unbound, and many other tools without conversion. The documentation is candid that entry counts shift per build and that aggression trades breakage risk for thoroughness, pointing new users at Multi PRO plus TIF and providing a direct link generator and lookup tool to simplify setup. It is a maintained, source-transparent option for anyone running DNS or content blocking at the network level.

Frequently asked questions

What are the best DNS blocklists?

The README presents HaGeZi DNS Blocklists as one maintained, GPL-3.0 set that covers ads, trackers, telemetry, phishing, malware, and scams network-wide, with five Multi tiers and a Threat Intelligence Feeds add-on. Which set is best depends on a user’s tool, region, and tolerance for breakage, and the documentation recommends starting with Multi PRO plus the TIF list rather than claiming a single universal winner.

Which DNS blocks 18+ content?

The project includes a dedicated NSFW list whose stated purpose is to block adult content. It is one of the specialized standalone lists in the catalog alongside gambling, social networks, and similar category-based blocklists, and it is published in the same standard formats as the rest of the project.

What is a DNS blocklist?

A DNS blocklist is a set of domains that a DNS server or content blocker refuses to resolve, which blocks the associated ads, trackers, telemetry, phishing, malware, scams, and other unwanted traffic network-wide. The README describes HaGeZi as exactly such a set, usable with any common DNS server, ad blocker, or content blocker and for any region.

Official sources

  1. hagezi/dns-blocklists on GitHub
  2. Issues
  3. License: GPL-3.0
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/hagezi-dns-blocklists.svg)](https://hysenlabs.com/projects/hagezi-dns-blocklists)