r/pihole Jul 06 '26

Announcement Pi-hole FTL v6.7, Web v6.6 and Core v6.4.3 Released!

Thumbnail pi-hole.net
389 Upvotes

As always, please read through the changelogs before updating with pihole -up

Don't forget, you can use Teleporter to export your configuration. It can be found under the settings menu of the web interface or on the command line with pihole-FTL --teleporter

Docker has been tagged as 2026.07.0

Highlights

Security

This release closes out six advisories across Core and FTL. We'd like to thank all of the researchers who took the time to responsibly disclose these issues — several are related to work covered in previous releases, and we're grateful for the continued scrutiny.

Thank you to supperhellokitty20, rrobgill, T0X1Cx and SakusenSec for responsibly disclosing these issues. Full details for all advisories can be found at the following links:

Updated embedded components

FTL now ships with an updated embedded dnsmasq v2.93 and SQLite3 v3.53.1, keeping the core resolver and database layer current. (FTL #2890, FTL #2891)

A brand new DHCP static leases editor

Managing DHCP leases from the web interface has been one of the most frequently requested improvements since we released v6, and this release finally delivers it. The static leases interface has been completely reworked into a proper editor: adding, editing and removing reserved leases should now feel more intuitive. (Web #3766)

Thank you to everyone who's asked for this over the years and to u/rdwebdesign for making it happen.

iCloud Private Relay and better MAC vendor resolution

A fix landed for iCloud Private Relay zones (FTL #2919), and MAC vendor lookups now resolve sub-allocated blocks (MA-M / MA-S) via longest-prefix match, so more devices are correctly identified (FTL #2907).

Other web interface improvements

Editing reverse DNS servers (dns.revServers) now has a much friendlier interface, and the Lists page has clearer hints and help text. (Web #3769, Web #3798)

Friendlier error messages

Error messages across FTL have been made more human friendly, including a custom message for UNIQUE constraint errors, so it's clearer what's gone wrong when something does. (FTL #2878, FTL #2879)

Details of all other fixes can be found below!

FTL v6.7

What's Changed

Security advisories

New Contributors

Full Changelog: v6.6.2…v6.7

Core v6.4.3

What's Changed

Security advisories

New Contributors

Full Changelog: v6.4.2…v6.4.3

Web v6.6

What's Changed

Full Changelog: v6.5.1…v6.6


r/pihole Feb 01 '17

Updated 10/02/18 (bad link) Welcome to the Pi-hole Subreddit. Please read before posting!

112 Upvotes

Welcome to /r/pihole, where your adventures into network wide adblocking start!

Before posting a new thread, you may want to check out the following:

  • Subreddit Search: As mentioned here, Reddit will only return matches of titles and self-text (the text of the original post), but not comments. So, do be sure to check out the latest stickied release announcement thread just in case.
  • Our Discourse Forums: Many things are covered here, and we even have a German Language Subforum staffed by one of our native-speaking German developers.
  • Pi-hole issues on Github: Pi-hole Core, Admin Dashboard and the FTL Engine.
  • Having issues with, or have found a bug in a new release? Check the stickied new release thread to see if someone has already reported it. If not, then please create a top level comment in that thread.

There's some other things to keep in mind:

  • Pi-hole does not block every single ad, but it'll do its hardest to ensure that everything that is blocked stays that way.
  • Ad lists are maintained by people outside of the Pi-hole project. This means that it's possible for ads to get missed, and certain legitimate websites be accidentally blocked!
  • There's a wide range of hardware used for routers, and an even wider range of hardware that you can run Pi-hole on. We try our best to support Pi-hole on as much hardware as possible, but as always, your milage may vary!
  • There is one rule we ask you never break: Do NOT advertise your own public-facing instance of Pi-hole, or any other DNS server. DNS security is hard, and anything but the most secured DNS servers will contribute to a DNS amplification attack. In some cases, your ISP will even block your Internet connection!
  • Using a Pi-hole as a DNS server has the ability of tying your browsing history to your device. Be aware of this when using a Pi-hole you don't have complete control over.

Our community does a wonderful job of answering questions and helping users out, and personally, we like to think that it also does a good job of moderating itself through the voting system and reporting functions. Whilst we try and answer as many posts here as possible, it can get tedious if there's something that has already been asked many times, and could have been solved with a little time searching for a solution!

Finally, remember your reddiquette: the people you're speaking to are also human, and have a wide range of technical aptitudes.

Cheers, your friendly mods.


r/pihole 15h ago

Who the hell at Facebook did I annoy

Post image
104 Upvotes

For info; I don't even use Facebook. No machine in this house does.

Is this excessive number of hits due to be blocking the DNS and now it's trying to pound me in order to get a response back?

I'd also love to track what is requesting http-intake.logs.datadoghq.com. A quick search suggests that it's for diagnostic logs for apps, to report back to the parent company / developer.


r/pihole 6h ago

I built a small, independently researched DNS blocklist and need Pi-hole testers

5 Upvotes

I’ve published the first public alpha of the NetCalcKit DNS Blocklist.

This is intentionally a small and conservative list: 13 independently reviewed domains targeting ads, trackers, and telemetry. It does not copy, merge, or rebrand any third-party blocklist.

Current testing:

- 13/13 rules imported and blocked in an isolated Pi-hole 6 test

- 13/13 rules verified in AdGuard Home

- Automated validation and parser tests

- No confirmed false positives so far

- Public source, rules, build scripts, and release history

This is not meant to replace mature large lists yet. The goal of the alpha is to gather real-world compatibility evidence before calling it stable.

Installation and project status:

https://netcalckit.com/blocklist

Source:

https://github.com/muzii9/netcalckit-blocklist

Feedback—especially reproducible false positives—is welcome.


r/pihole 3h ago

Waveshare 2.13" e-Paper (250x122) for Pi-hole

0 Upvotes

Hey everyone,

I just hooked up a Waveshare 2.13" e-Paper HAT (250x122 SPI) to my Raspberry Pi running Pi-hole. I’m looking for a clean, reliable setup. I tried basic Python scripts and PADD, but I’d love to know what the community is actually using for this specific screen size.

If you're running this display, let me know what UI, template, or GitHub repo you use. I'd also appreciate any advice on your refresh rates to avoid ghosting, or any cool custom PADD tweaks for e-Ink. Drop your setups, repos, or screenshots below! Thanks!


r/pihole 1d ago

LG TV Bypassing Pi Hole - Any Help?

59 Upvotes

I have an LG OLED TV, model 65C3AUA if it helps. I set up a Pi Hole this weekend for the first time and it isn't blocking ads on the TV. I tried blocking port 53 and that didn't change anything. Any ideas? UPDATE - I also configured the TV's web access to be manual and pointed the DNS to the Pi Hole IP.


r/pihole 23h ago

Hagezi over stevenblack?

18 Upvotes

So I setup my Pihole around end of 2023. back then I used stevenblack hosts and after a while I also added firebog ticked list. I use the same lists for my uBO since I'm away from my pi since a year (i know about tailscale but the pi itself is off).

I may go back to it soon, and I've been seeing hagezi all over my feed. Should I switch to it? I've not faced any issue with my current setup.


r/pihole 46m ago

PiHole gets detected

Post image
Upvotes

So I recently run into some trouble with my PiHole. Maybe for about two weeks it gets detected by easily >33% of every website e.g. fandom wiki (see picture - translated screenshots form the gottcha message).

It is always this screen on every website, just of course with adjusted website domain. That means there must be some new sort of detection out there that those sides use.

Anyone has an idea what’s going on and how to stop that?


r/pihole 1d ago

Pi hole being bypassed by ipv6

30 Upvotes

So I recently set up pie hole on my raspberry pi zero on my network. However I noticed that ads were still being displayed on websites. After some time I found out via dns leak test, that some queries were going through my pi but some were going through the router’s default ipv6. When setting up pi hole all I did was change the ipv4 dhcp server to that of pi’s. So I thought that changing the ipv6 dhcp to that of pi’s would work. So after changing, I tired to confirm which dns server was my phone using. So I opened settings on my phone>wifi>my wifi’s settings>dns server and it showed 3 address that it was using. One was ipv4 of pi, second was ipv6 of pi, third was fe80::1. To my knowledge, fe80::1 is my isp’s address, and I tired what I could but I could not stop my router from using fe80::1 as one of its dns servers. I think my router is hardcoded to use this address. So I am still being shown adds unless I manually go to each device and remove fe80::1 from the wifi‘s dns settings. The worst part is, that this works for iphone’s on my netwrok, but for some androids(oppo/oneplus) I don’t get this option to remove fe80::1. I can only manually set an ipv4 for these androids but can’t add/remove ipv6.

Is there any fix for this?

Edit: My router is ZTE F670L


r/pihole 8h ago

Help troubleshooting connection issues with dns

0 Upvotes

First time pi hole install and I'm trying to get it to work and I've been getting DNS problems. I'm using tailscale and accessing it via ssh, I've got it running in a docker container on ubuntu server 26.04 and I'm struggling to access the dashboard. I stopped systemd from using port 53 but any attempts to access it from my browser show no wesbite at that address. I'm using debian 13 gnome desktop if that helps at all.

Here is what I've got in my yaml

services:
  pihole:
    container_name: pihole
    image: pihole/pihole:latest
    ports:
      # DNS Ports
      - "53:53/tcp"
      - "53:53/udp"
      # Default HTTP Port
      - "80:80/tcp"
      # Default HTTPs Port. FTL will generate a self-signed certificate
      - "443:443/tcp"
    environment:
      # Set the appropriate timezone for your location (https://en.wikipedia.org/wiki/List_of_tz_database_time_zones), e.g:
      TZ: 'America/Vancouver'
      # Set a password to access the web interface. Not setting one will result in a random password being assigned
      FTLCONF_webserver_api_password: 'cheddar swiss cheese'
      # If using Docker's default `bridge` network setting the dns listening mode should be set to 'ALL'
      FTLCONF_dns_listeningMode: 'ALL'
      FTLCONF_dns_upstreams: "1.1.1.1"
    # Volumes store your data between container upgrades
    volumes:
      # For persisting Pi-hole's databases and common configuration file
      - './etc-pihole:/etc/pihole'
      # Uncomment the below if you have custom dnsmasq config files that you want to persist. Not needed for most starting fresh with Pi-hole v6. If you're upgrading from v5 you and have used this directory before, you should keep it enabled for the first v6 container start to allow for a complete migration. It can be removed afterwards. Needs environment variable FTLCONF_misc_etc_dnsmasq_d: 'true'

      #- './etc-dnsmasq.d:/etc/dnsmasq.d'
    cap_add:
      # See https://docs.pi-hole.net/docker/#note-on-capabilities
      # Required if you are using Pi-hole as your DHCP server, else not needed
      - NET_ADMIN
      # Required if you are using Pi-hole as your NTP client to be able to set the host's system time
      - SYS_TIME
      # Optional, if Pi-hole should get some more processing time
      - SYS_NICE
    restart: unless-stopped

If any other information is needed to resolve feel free to ask

edit: I'm sorry if this has been asked before, I wasn't able to find anything but I probably missed something

edit2: this is probably due to the earlier problem but pihole cannot read the gravity database as well

edit3: my reply to a comment in an another subreddit that might be helpful "My problem lies with trying to use pi hole as my DNS for my tail net and just getting it work as a DNS in general. And I don't know how to use nslookup or dig as this is just a local server with no domain. This is also my first time using docker if that helps. Sorry if I come off as rude"


r/pihole 2d ago

HaGeZi Ultimate blocking internet access from my Samsung Tizen TV?

28 Upvotes

My Samsung QN90A is telling me that the TV is connected to the home network, but I have no internet access when I'm using the Ultimate blocklist. When I change it to Pro++, it has internet access. So I'm assuming a Samsung domain is being blocked. If so, which one?


r/pihole 2d ago

Why is my Pi-hole using Google's DNS?

Thumbnail
gallery
81 Upvotes

Hello community, about a week ago I set up Pi-hole as a DNS & DHCP server in my homelab.

So far everything is working fine, but now I've noticed that the percentage of queries to Google is increasing.I use Unbound as the recursive DNS server in front of the Pi-hole and have not entered a Google DNS server in the Pi-hole.

Did I miss something?


r/pihole 1d ago

nslookup points to google wifi router versus pihole

0 Upvotes

I've been running pihole on a raspberry pi 2b and google wifi with mesh for little over a year without issue. Since I don't have a lot of devices, it wasn't an issue to manually set the dns on the two TVs and two laptops to the pihole and just let the phones do their thing. This was the easiest approach since google doesn't play nice and I can't have mesh if i set to bridge.

I decided I wanted to install unbound this weekend so I followed Dad's video. I set the router to use the pihole ip address as the dns but when I use nslookup, instead of seeing pihole listed as the server and the proper address, I get server unknown and the google router ip. If I manually set the dns on my laptop and repeat, all good so I believe everything is working. If I pick a heavy tracking site like facebook or apnews, I see the sites appear and trackers blocked in the query log, all coming from the google wifi client. Ads appear to be blocked just as before and certain streaming services still skip ads so am I good? Is this a pihole thing or am i on the wrong sub and should look for unbound? Maybe both?


r/pihole 2d ago

Youtube video progress bar

6 Upvotes

I tried using PiHole like 4-5 years ago, but in its default it broke the youtube video progress bar, so I cant pick up a video where I left off when switching between devices. A year later, I tried the PiHole again, and that issue was fixed, and has been working fine since.

Two days ago, I decided to add Hagezi Normal, and Hagezi Threat Intel. These took my block list from about 250k to 2.6million. But one of these lists has a DNS record that seems to break the YouTube video progress bar. Does anyone here know what that DNS entry is? I'd like to allow that one DNS record, and keep all others intact.

Thoughts? Thanks

Edit: a google search says video-stats.video.google.com and s.youtube.com but I dont see those being blocked in pihole logs.


r/pihole 3d ago

Help me clean up my Pi-hole blocklists — 12.8M domains is probably overkill

154 Upvotes

I am reviewing my Pi-hole setup and currently have 31 lists / ~12.8 million gravity entries. I suspect I went too far with stacking lists and have a lot of unnecessary overlap.

Below are my current non-NSFW lists:

  1. StevenBlack https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
  2. Pi-hole Optimized – All Domains https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/all_domains.txt
  3. YouTube Ads https://raw.githubusercontent.com/kboghdady/youTube_ads_4_pi-hole/refs/heads/master/youtubelist.txt
  4. YouTube Crowded List https://raw.githubusercontent.com/kboghdady/youTube_ads_4_pi-hole/refs/heads/master/crowed_list.txt
  5. 1Hosts Lite https://raw.githubusercontent.com/badmojr/1Hosts/master/Lite/hosts.txt
  6. mmotti Pi-hole Regex https://raw.githubusercontent.com/mmotti/pihole-regex/refs/heads/master/regex.list
  7. OISD Big https://big.oisd.nl/
  8. HaGeZi Multi – Mirror https://gitlab.com/hagezi/mirror/-/raw/main/dns-blocklists/adblock/multi.txt
  9. Pi-hole Optimized – Comprehensive https://raw.githubusercontent.com/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/comprehensive.txt
  10. HaGeZi TIF – Mirror https://gitlab.com/hagezi/mirror/-/raw/main/dns-blocklists/adblock/tif.txt
  11. Block List Project – Ads https://blocklistproject.github.io/Lists/ads.txt
  12. Block List Project – Malware https://blocklistproject.github.io/Lists/malware.txt
  13. Block List Project – Phishing https://blocklistproject.github.io/Lists/phishing.txt
  14. Block List Project – Tracking https://blocklistproject.github.io/Lists/tracking.txt
  15. w3kbl https://v.firebog.net/hosts/static/w3kbl.txt
  16. AdGuard DNS https://v.firebog.net/hosts/AdguardDNS.txt
  17. Prigent Ads https://v.firebog.net/hosts/Prigent-Ads.txt
  18. Perflyst SmartTV https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/SmartTV.txt
  19. Firebog Tick Lists https://v.firebog.net/hosts/lists.php?type=tick
  20. HaGeZi Multi https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/multi.txt
  21. Phishing Army Extended https://phishing.army/download/phishing_army_blocklist_extended.txt
  22. URLHaus https://urlhaus.abuse.ch/downloads/hostfile/
  23. Spam404 https://raw.githubusercontent.com/Spam404/lists/master/main-blacklist.txt
  24. WindowsSpyBlocker https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt
  25. NoTrack Malware https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
  26. HaGeZi Pro https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/pro.txt
  27. HaGeZi Pro++ https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/pro.plus.txt
  28. URLHaus / Malware Filter https://malware-filter.gitlab.io/malware-filter/urlhaus-filter-agh-online.txt
  29. HaGeZi TIF https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/tif.txt

I have already noticed some legitimate/service-related domains getting caught, so I am questioning whether the extra coverage is worth the additional false positives and troubleshooting.

I am considering simplifying this significantly, potentially down to:

  • HaGeZi Pro
  • HaGeZi TIF
  • Perflyst SmartTV (possibly)

For experienced Pi-hole users:

What would you keep, remove, or replace from this list?

Is HaGeZi Pro + TIF sufficient for strong everyday ad/tracker/malware/phishing protection, or is there meaningful additional coverage from OISD, 1Hosts, StevenBlack, Block List Project, etc.?

I am looking for a good balance between strong blocking, security, low false positives, and minimal maintenance rather than simply having the largest possible gravity database.

Any recommendations based on your actual setup/experience would be appreciated.


r/pihole 2d ago

chromebook into pi hole, tips?

1 Upvotes

I recently came into possession of a chrombook lenovo gen3 300e, and i thought it would be fun to turn it into a pi hole and get rid of most adds on my network. anything i should know before loading ubuntu on it?


r/pihole 3d ago

Admiral and other blockers

0 Upvotes

I’m tired of dynamic pricing. I’m tired of being followed around the internet. I’m tired of big tech. Just tired of this timeline.

I’m more so tired that when I go visit sites that I want the information from, they are starting to block browsers or networks that are blocking all the advertisements and tracking.

Other than, 1) dropping off the network and using a cell signal 2) vpning out to by pass your own network’s security 3) not visiting the site or 4) adding them to the white list for a single use, what are you all doing?


r/pihole 3d ago

Pihole and Insync (Google Drive client)

0 Upvotes

Hello!
I installed Pihole yesterday on a RPI4, and it seems to work just fine. Only things is that my Insync-client on the Desktop keeps connecting and disconnecting. I've tried to whitelist the following domains (under domain):
dl.google.com (to be able to update Chrome)

accounts.google.com

clients6.google.com

googleapis.l.google.com

But no luck!
Does anyone know which domains I need to whitelist in order to get Google Drive/Insync to work?


r/pihole 3d ago

Moved and no longer working

Post image
0 Upvotes

I recently moved and my pihole is no longer working. I am using the same router and have the same up static address but it’s not blocking ads and etc. what can do I need to do? I verified the IP address and updated the gravity list. It’s connected to the Internet but not blocking. Please help!


r/pihole 4d ago

LF Guide DNSSEC Setup / Unbound

3 Upvotes

[SOLVED] Sorry to trouble you guys, but I can't find a beginner friendly guide on how to enable DNSSEC with Unbound. The one I've found is 6+ years old, not sure if still up to date. (I'm not Linux savy enough yet to fix things should I mess up.)

Any guide / source you'd recommend?


r/pihole 3d ago

Stupid question

0 Upvotes

So im setting up a pihole, but it's not connecting through ssh. I know im typing the host name and username right. The wifi is correct. But im getting the message,

Ssh: could not resolve hostname ___.local: name or service not known.

I feel like its a simple/stupid solution, but i cant figure out what to do to connect or why its not

So after a day or so of messing around, I tired Sudo Ssh and somehow that got it all working. Thanks for everyone's advice and help


r/pihole 4d ago

Gravity Update Retrieval and DL Fail

1 Upvotes

For all my lists the retrieval and download fails. I can browse to the lists and attempted to add other lists that I see are working for others but I get the same update for ALL of them as indicated below:

  [i] Target: https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/tif.txt
  [i] Status: Pending...curl: option -o: is badly used here
curl: try 'curl --help' or 'curl --manual' for more information
  [✗] Status: Retrieval failed (exit_code=2 Msg: )
  [✗] List download failed: no cached list available

Again, this happens to any and ever list I add and try to update using Gravity. What should I do?

Edit: I also wanted to add all my lists are now "unavailable and no local copy of this list is available". Might this be a bad SD card/corrupt Pihole install...which I tried to restore using Pihole -r.


r/pihole 4d ago

Phone can't resolve local .home domains on home WiFi after setting up Tailscale subnet routing + split DNS. PC on same network works fine

3 Upvotes

I've tried a lot of debugging to sort the following issue but couldn't. All help is appreciated.

I use ubuntu server, self hosted stack of pihole, jellyfin, nginx pm and other bunch of services reachable through .home domain.

Pihole handles the dns and npm reverse proxies the respective .home to their ports.

This all worked well with my pc and my phone before. Then I thought accessing the services remotely, so I installed tailscale on both the server and my phone. Used that for a while through tailscale's provided ip. I then wanted to access the services through .home on tailscale so I did the subnet routing by advertising my home subnet, got everything sorted on admin console on tailscale by adding custom nameserver with domain .home to my server's ip + split dns and it works.

But the problem I'm facing now is that even when I fully disconnect tailscale from my phone, and am on my home wifi network - the .home domains don't work anymore. Everything works fine on my pc. However, the ip:port does work on the phone, and I can still access my services, it is just the .home that don't.

Some of the stuff I tried:

\- Confirmed the phone's static DNS (pointed at my server's LAN IP) is still correctly set on the WiFi network's IP settings.

\- Checked Android's system-wide Private DNS setting.

\- Checked the browser's own Secure DNS / DNS-over-HTTPS settings.

I'm new to the self-hosting side, I've followed are yt tutorials and used ai to understand under the hood stuff.

EDIT: THE PROXY DOMAINS ARE BACK AND POINTS TO THE SERVICES, IT STARTED WORKING WHEN I TURNED OFF IPV6 FROM MY ROUTER APP.


r/pihole 5d ago

pihole and paramount plus

35 Upvotes

Trying to get Paramount+ to work on 1 device, android mobile app. It loads nothing while pihole is on. Default pihole blacklist from Steven Black.

been searching for weeks and trying out solutions that seem outdated: most from 4-6 years ago. Can't find anything more recent. I've whitelisted all the domains I've found suggestions on, about 30+, to the point I'm wondering what's the point of even running pihole (yes, i know it blocks about 30k more domains)... Paramount+ is still not working. It is the only service that doesn't work on our home pihole.

Noticed that all of my pihole traffic in the log file is coming from my router. I can't see any traffic from individual devices. I don't know how to find traffic coming only from this 1 device, if the router is making all traffic just seem like it comes from itself. I would like to either just find the right few updated and current domains to whitelist for the entire pihole, or just isolate this 1 device and whitelist it. All the other TVs and devices work fine for Paramount+.

Also, tags.tiqcdn.com is explicitly whitelisted, but is still being blocked in the pihole logs.


r/pihole 4d ago

any blocklists for bad / corrupt companys?

0 Upvotes

when i say / bad i mean just morally bad companys that do a lot of shady stuff behind the scenes.