# Pi-hole's install is one command, the DNS switch is the real work

> Pi-hole is a DNS sinkhole that blocks ads across a network from your own Linux hardware, with nothing installed on the client devices. Its install is one line, its project argues against that one line, and the part that actually changes your network happens in the router after the installer finishes.

**pi-hole/pi-hole** — GitHub describes it as A black hole for Internet advertisements. The repository metadata lists Shell as its primary language. The metadata lists the NOASSERTION license. This article stays within the project description and details documented in the GitHub repository README.

- Repository: https://github.com/pi-hole/pi-hole
- Website: https://pi-hole.net
- Stars: 61,120 · Forks: 3,320
- Language: Shell
- License: NOASSERTION
- Published: 2026-08-13 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/pi-hole-pi-hole

## Piping the installer to bash, and two ways to read it first

One command is the advertised path, and the project then argues against it.

```bash
curl -sSL https://install.pi-hole.net | bash
```

The objection sits a few lines below, in the project's own framing: piping to bash is controversial because it prevents you from reading code that is about to run on your system. Two alternatives are offered that let you read the script first, and both end in the same root invocation of basic-install.sh.

```bash
git clone --depth 1 https://github.com/pi-hole/pi-hole.git Pi-hole
cd "Pi-hole/automated install/"
sudo bash basic-install.sh
```

```bash
wget -O basic-install.sh https://install.pi-hole.net
sudo bash basic-install.sh
```

The shallow clone is worth pausing on. The depth 1 flag fetches the tip of master, so a reviewer reads current code rather than history, which is what makes the review short. A third method leaves the shell behind entirely and points you at the docker-pi-hole repository for the official Docker Images. That is a different repository with its own documentation and its own issue tracker, so the instructions you follow there are not the ones written in this project.

## The router has to hand out the Pi-hole DNS address

Finishing the installer changes nothing on your network, and the post-install section says so. Until clients are told where to send their DNS queries, the sinkhole is running and unused. The preferred fix lives in the router: set it to give DHCP clients the Pi-hole address as their DNS server, which the project says covers every device that joins without further intervention. That one change is what turns a per-machine experiment into network-wide blocking, and it is the reason a DNS sinkhole reaches televisions and phones that no extension can touch.

What the project does not supply is a router-specific procedure. The post-install link goes to a forum thread about configuring devices, and no model list, no address format and no menu path appears in the documentation here. A router that hides its DNS setting therefore removes the first tier entirely, and the reader has to work out which of the two remaining tiers applies to hardware the project never names.

## Pi-hole's own DHCP server needs the router's switched off first

The second tier is a built-in DHCP server, and it arrives with an instruction that is easy to skim past. The project tells you to disable DHCP on your router first, then adds a parenthetical that narrows the whole fallback: if it has that feature available. That concession matters more than it looks. A router that cannot switch its own DHCP off cannot run Pi-hole's replacement server, which leaves the third tier as the only route, and the third tier is manual, meaning you set each device to use Pi-hole as its DNS server.

Two DHCP servers answering on one network is the failure that instruction exists to prevent. Nothing in the documentation describes what a consumer router looks like when that goes wrong, nor whether leases already handed out survive the switch, so the person taking this path needs to know their router's DHCP menu before running the installer rather than after.

## A DNS sinkhole only sees what the resolver sees

Pi-hole describes itself as a DNS sinkhole, and that one word sets the ceiling on what the software can reach. Because nothing is installed on the clients, filtering happens wherever name resolution is answered, which is why the project's own claim is about non-browser locations such as ad-laden mobile apps and smart TVs rather than about browser tabs. The same feature list promises blocking over both IPv4 and IPv6, and a caching layer that answers repeated lookups locally instead of sending them upstream.

What follows from that mechanism is a boundary the documentation leaves open. Traffic that resolves names without asking the network's resolver sits outside the design, and no page here describes that case, what a user sees when it happens, or whether a setting exists to catch it. The stated coverage also ends at ads over two IP versions, with no claim made about content categories, which is worth knowing before you expect a rule set you can point at a device.

## FTLDNS lives in another repository and feeds the dashboard

The Web Interface is not served by this codebase. Statistics come from FTLDNS, a lightweight purpose-built daemon kept in its own repository at pi-hole/ftl, and the dashboard consumes what that daemon reports. The project also states that the daemon's API can be integrated into your own projects, which makes it the one extension point the documentation actually offers.

The values it exposes are named individually: total domains blocked, total DNS queries today, total ads blocked today, the percentage of ads blocked, unique domains, and the number of queries forwarded onward to your chosen upstream. Every one of those is an aggregate for the whole network, and a per-client figure is not among them. Splitting the codebase has two consequences you inherit. Reporting depends on a component this repository does not contain, so keeping the two versions matched falls to you at upgrade time, and the personal view of what one laptop looked up is not what this daemon is described as collecting.

## The project points beginners at its own shell scripts

The project makes a point of its own readability. The install script and the debug script, basic-install.sh and piholeDebug.sh, are called a valuable resource for anyone who wants to learn how to write scripts or code a program, and pull requests against both are invited. That fits a codebase whose primary language is Shell: a .shellcheckrc sits at the root, the command line entry point is a file named pihole, and the tree separates an automated install/ directory, an advanced/ directory, manpages/ and a test/ directory. The layout tells you what an upgrade has to touch, and the two named scripts tell you which file to open when something misbehaves.

Support follows the same pattern. Requests go through a template the project asks you to fill out, whether the change is a typo or a feature, and the forum is the primary channel rather than the repository. Nothing here answers a question on demand.

## v6.4.3 shipped 2026-07-06 and the tree moved on 2026-09-26

The repository is not archived and the last push landed on 2026-09-26, so work is still landing. Releases move at a different pace. v6.4.1 shipped on 2026-04-03, v6.4.2 on 2026-04-24 and v6.4.3 on 2026-07-06, which puts ten weeks between the last two, and about twelve weeks have passed since v6.4.3 with commits in between. A fresh install therefore gets v6.4.3, and anyone tracking master is running something the newest tag does not contain.

This is a volunteer project, and the documentation is unusually direct about what that means for the person running it. Volunteer developers cover the recurring costs, the same page asks you to check the FAQs before starting a discussion because there is no spare time to reply to every request for assistance, and help is routed to a Discourse forum with feature requests and issue reporting kept in separate categories. A fault in a Shell install script is something you diagnose with piholeDebug.sh and post with a completed template, not something with a reply scheduled against it.

## A LICENSE file at the root that the project never sets out

The licensing picture is thin in the place where it matters least to read and most to check. A LICENSE file sits at the repository root, and the project's own description calls it free, open-source software whose stated purpose is that you remain in control of your own privacy. The terms themselves appear nowhere in the documentation, so a question about redistribution, or about what a fork must carry, is answered by that file and not by the README.

The funding section of the same page is worth reading for a different reason. Beyond donations the project lists GitHub Sponsors, Patreon, and a set of links to hosting providers that the text marks as affiliate links, alongside a credit for a sticker. That is context for the volunteer support model rather than a licence term, and it is the one part of the document that hints at what running a deployment costs the people who maintain it. For a compliance question, the file to open is LICENSE at the root of the repository.

## Conclusion

Pi-hole fits a household or small office that controls its own router and wants blocking to reach smart TVs and phones, where a browser extension cannot go. It does not fit a network whose router cannot be told which DNS server to hand out and whose devices cannot be configured one at a time, because there is no cloud service and no per-device agent in this design. Before installing, check that your router has a DNS setting at all, since the documented fallback depends on being able to switch DHCP off. Then read the LICENSE file at the repository root, since the project calls itself free without setting out the terms.

## FAQ

### What exactly does a Pi-hole do?

It is a DNS sinkhole, so it blocks unwanted content by answering name lookups for the whole network without installing any client-side software. The project claims blocking in non-browser locations such as ad-laden mobile apps and smart TVs, over both IPv4 and IPv6, with DNS caching for repeated queries.

### How do I install Pi-hole?

The one-step route is curl -sSL https://install.pi-hole.net | bash, which the project itself calls controversial. Two review-first alternatives are given: a shallow git clone followed by sudo bash basic-install.sh, or wget the script first and then run it with sudo bash.

### How do I use Pi-hole after installing it?

You still have to point clients at it. Set the router to give DHCP clients the Pi-hole address as their DNS server, or disable the router's DHCP and use Pi-hole's built-in DHCP server, or set each device by hand as a last resort.

### How do I run Pi-hole with Docker?

The installation documentation refers you to the separate docker-pi-hole repository for the official Docker Images. The root of this repository carries a .dockerignore but no Dockerfile, so the container path is maintained elsewhere.

### Is Pi-hole still effective?

The repository is not archived and the last push was on 2026-09-26, with releases v6.4.1, v6.4.2 and v6.4.3 dated 2026-04-03, 2026-04-24 and 2026-07-06. The project publishes no figure for how much it blocks, so effectiveness cannot be read from its documentation.

### Can Pi-hole block YouTube ads?

The project claims blocking in non-browser locations and over both IPv4 and IPv6, but names no individual site. No per-service claim appears in the documentation, so a specific streaming case is not covered by any statement the project makes.

## Sources

- [Official documentation](https://pi-hole.net)
- [Official README](https://github.com/pi-hole/pi-hole#readme)
- [Project repository](https://github.com/pi-hole/pi-hole)
- [Release notes](https://github.com/pi-hole/pi-hole/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/pi-hole-pi-hole
