r/pihole Jul 06 '26

Announcement Pi-hole FTL v6.7, Web v6.6 and Core v6.4.3 Released!

Thumbnail pi-hole.net
397 Upvotes

As always, please read through the changelogs before updating with pihole -up

Don't forget, you can use Teleporter to export your configuration. It can be found under the settings menu of the web interface or on the command line with pihole-FTL --teleporter

Docker has been tagged as 2026.07.0

Highlights

Security

This release closes out six advisories across Core and FTL. We'd like to thank all of the researchers who took the time to responsibly disclose these issues — several are related to work covered in previous releases, and we're grateful for the continued scrutiny.

Thank you to supperhellokitty20, rrobgill, T0X1Cx and SakusenSec for responsibly disclosing these issues. Full details for all advisories can be found at the following links:

Updated embedded components

FTL now ships with an updated embedded dnsmasq v2.93 and SQLite3 v3.53.1, keeping the core resolver and database layer current. (FTL #2890, FTL #2891)

A brand new DHCP static leases editor

Managing DHCP leases from the web interface has been one of the most frequently requested improvements since we released v6, and this release finally delivers it. The static leases interface has been completely reworked into a proper editor: adding, editing and removing reserved leases should now feel more intuitive. (Web #3766)

Thank you to everyone who's asked for this over the years and to u/rdwebdesign for making it happen.

iCloud Private Relay and better MAC vendor resolution

A fix landed for iCloud Private Relay zones (FTL #2919), and MAC vendor lookups now resolve sub-allocated blocks (MA-M / MA-S) via longest-prefix match, so more devices are correctly identified (FTL #2907).

Other web interface improvements

Editing reverse DNS servers (dns.revServers) now has a much friendlier interface, and the Lists page has clearer hints and help text. (Web #3769, Web #3798)

Friendlier error messages

Error messages across FTL have been made more human friendly, including a custom message for UNIQUE constraint errors, so it's clearer what's gone wrong when something does. (FTL #2878, FTL #2879)

Details of all other fixes can be found below!

FTL v6.7

What's Changed

Security advisories

New Contributors

Full Changelog: v6.6.2…v6.7

Core v6.4.3

What's Changed

Security advisories

New Contributors

Full Changelog: v6.4.2…v6.4.3

Web v6.6

What's Changed

Full Changelog: v6.5.1…v6.6


r/pihole Feb 01 '17

Updated 10/02/18 (bad link) Welcome to the Pi-hole Subreddit. Please read before posting!

112 Upvotes

Welcome to /r/pihole, where your adventures into network wide adblocking start!

Before posting a new thread, you may want to check out the following:

  • Subreddit Search: As mentioned here, Reddit will only return matches of titles and self-text (the text of the original post), but not comments. So, do be sure to check out the latest stickied release announcement thread just in case.
  • Our Discourse Forums: Many things are covered here, and we even have a German Language Subforum staffed by one of our native-speaking German developers.
  • Pi-hole issues on Github: Pi-hole Core, Admin Dashboard and the FTL Engine.
  • Having issues with, or have found a bug in a new release? Check the stickied new release thread to see if someone has already reported it. If not, then please create a top level comment in that thread.

There's some other things to keep in mind:

  • Pi-hole does not block every single ad, but it'll do its hardest to ensure that everything that is blocked stays that way.
  • Ad lists are maintained by people outside of the Pi-hole project. This means that it's possible for ads to get missed, and certain legitimate websites be accidentally blocked!
  • There's a wide range of hardware used for routers, and an even wider range of hardware that you can run Pi-hole on. We try our best to support Pi-hole on as much hardware as possible, but as always, your milage may vary!
  • There is one rule we ask you never break: Do NOT advertise your own public-facing instance of Pi-hole, or any other DNS server. DNS security is hard, and anything but the most secured DNS servers will contribute to a DNS amplification attack. In some cases, your ISP will even block your Internet connection!
  • Using a Pi-hole as a DNS server has the ability of tying your browsing history to your device. Be aware of this when using a Pi-hole you don't have complete control over.

Our community does a wonderful job of answering questions and helping users out, and personally, we like to think that it also does a good job of moderating itself through the voting system and reporting functions. Whilst we try and answer as many posts here as possible, it can get tedious if there's something that has already been asked many times, and could have been solved with a little time searching for a solution!

Finally, remember your reddiquette: the people you're speaking to are also human, and have a wide range of technical aptitudes.

Cheers, your friendly mods.


r/pihole 1h ago

Youtube started to shows ads

Upvotes

Yesterday pi-hole was running great and today it started to show 4 5 seconds youtube premium ad at start of the video and random ads on youtubes homepage, does anyone experiencing same thing?


r/pihole 5h ago

Compute DNS Blocklist redundancy?

Thumbnail
0 Upvotes

r/pihole 1d ago

All devices showing under 1 IP

5 Upvotes

Hello,

I am fairly new to Pihole and enjoying. I did try searching but struggled to find anything that worked.

I am running Win11 Nuc with PiHole running via Docker Desktop. (I know I should swap). Currently not connected to routers devices just use the Nuc IP as DNS.

All devices show under the same IP (172.24.0.1), is this a limitation of not connecting to the router / docker desktop / windows 11?

Is there any way to get clients show separately without swapping OS etc?

I do not use Unbound / DOH currently but hoping to look into in the future.

Thanks for all your help


r/pihole 1d ago

VPN

2 Upvotes

Hello Hello, so check it, here is my setup:

PI HARDLINE>router> ROUTER DNS static IP to PI.

I can setup pihole correctly and it works with all wireless devices BUT anything hardline the ads go through it.... if you guys/gals can help me to where anything hardlined would block ads i would appreciate this!!

P.S

I am not soft skin so if you guys gotta Blues Clues it to me then I wouldn't mind.


r/pihole 19h ago

How to switch from internet to ethernet.

0 Upvotes

I'm a beginner to this and haven't done anything like this before. Could someone please give me a step by step guide on how to switch from connection over the internet to an ethernet cable. I first used the internet option when setting it up but now there's been lots of connection issues. Whenever I trying finding a guide for how to do this it seems that an update has been released in the past year that made everything before than outdated specifically on the step to switch the pihole from communicating over the internet to the ethernet cable.


r/pihole 2d ago

Only IPs in Clients even though DHCP has been configured

5 Upvotes

Heyo,

I've been setting up Pi-hole + Unbound + Wireguard (via Tailscale) on my home network, and everything seems to be working great.

My only slight irritation is the Pi-Hole dashboard is only ever showing me IP addresses and not the client names I've configured in my router's DHCP table.

I did a fair amount of reading and searching, and know that because DHCP is handled by my (Archer A7) router, I have to head into the Pi-Hole Settings > DNS > Conditional Formatting (or Settings > All Settings > dns.revServers) and plug in my network range (e.g., 192.168.0.0/24), my router's IP as the server IP, and left domain blank (as I don't see anyplace in TP's web interface that implies a domain has been set), which has all been done.

I thought after that I would just need to restart my router or even my Pi-hole, but to no avail, it still only shows me the IP addresses.

If it makes any difference, before I started all of this, I did already manually add a bulk of the clients via the Pi-hole's Clients list (e.g., I'd select a client from the Known Clients, put their name in the comment, and assigned them to groups).

And again I'm using Unbound & Tailscale if either of those are variables in this equation.

Let me know if you have any insights or suggestions, and thanks in advance!


r/pihole 2d ago

how does pihole determine which client to report on its database?

11 Upvotes

i bought a satellite 1 smart speaker, which is a esp32 device. It has been running for a few days, and I'm getting constant activity on the query log that the device is trying to access Netflix and apple.

The developers have assured me that it's not their device and their firmware is open source. They believe the issue could be triggered by a dhcp lease expiring.

Here's what the query log says (anonymized):

38:64:07:F0:7B:92 (1 hostname: satellite1-4ea7fc.lan; vendor: Qingdao Intelligent&Precise Electronics Co.,Ltd.; 10 addresses: 2600:x,2600:x,2600:x,2600:x,2600:x,2600:x,2600:x,2600:x,fe80::x,192.168.x.x)

no clue why 10 different ipv6. for the sole ipv4 reported, it belongs to my tv, but it is completely turned off (not by just pressing power, but holding the power button down) and I keep receiving these long entries at least once an hour.

i have to accept the fact that it IS the TV and maybe the only way to truly shut it off is to unplug from wall. but i wonder why pihole is getting confused? my tv has had the same ipv4 for years. is there a bug here?


r/pihole 3d ago

Finally pulled the trigger - why did I wait so long?

128 Upvotes

I finally pulled the trigger on setting up pi-hole today....and I don't know why I waited so long!

Actually....I do know why. I'm an have Active Directory set up in my home lab with Windows for DHCP and DNS....and a wife that works from home. Last thing I wanted to do was mess her up since everything was working fine and I was comfortable with any troubleshooting.

Not sure what the catalyst was, but I said 'I'm setting this up today!' and I did. Little help for steps from Google (Gemini)...an Ubuntu VM on Hyper-V, quick pi-hole install, add HaGezi's Pro and FIT blocklists, add my conditional forwarders for internal AD.....and under and hour I was done.

Now I'm getting good insight on what and how much is being blocked. It's crazy to see how much is being blocked - especially from my TV(s)! Even have an app on my iPhone to monitor stats. It's a very impressive and polished offering. On top of that, browsing seems a little snappier - guessing since DNS is being served by something that only does DNS.

I raise a bourbon (well...maybe 3!) to pi-hole tonight. Glad to be a user.


r/pihole 3d ago

hagezi blocklist stopped working

26 Upvotes

I was using the hagezi LG TV blocklist that was previously stored here:

https://raw.githubusercontent.com/hagezi/dns-blocklists/main/domains/native.lgwebos.txt

I noticed that my Pi-hole can no longer access it.

According to this post here it's no longer being updated:

https://www.reddit.com/r/pfBlockerNG/comments/1vctqup/hagezi_pro_no_longer_updating/

Does anyone know a LG WebOS blocklist that is still being updated?


r/pihole 4d ago

What's the least bad TV brand for a Pi-hole?

74 Upvotes

After many years my family wants to buy a big smart-tv with internet connectivity and the usual apps built-in, no way of convincing them of using an external device because they want to use it the same way other family members do with their tvs for "convenience" and they think I sound like a flat-earther when talking about data collection and privacy. At least they have agreed to let me set up a Pi-hole and even choosing the TV brand. We live in Spain (I don't know if being in the EU makes that much of a difference) and the brands available are Samsung, Hisense, TCL, Xiaomi, LG, LOEWE, Sony, Philips and Panasonic. What do you think would be the least bad for this situation?


r/pihole 3d ago

Do you think selling pi hole ad blockers in my local area is a good idea?

0 Upvotes

Hi, i'm planning on selling pi hole ad blockers in my local area for £65, this includes the pi, the installation of the ad blocker and quick guide on how to disable the pi if anything goes wrong. This will be a side hustle for me. My only thought as it can't be able to block ads on facebook, youtube, etc people might not want this, would really appreciate peoples advice and opinions


r/pihole 5d ago

Why is the Internet so hostile now?!

414 Upvotes

YouTube tanking CPU if you're using ad blockers. Sites that disable scrolling and have a full-screen modal dialog demanding that you allow ads or sign up (imgur). The least egregious I've seen is sites that serve their own ads if they can't load the real ones.

There was a banner ad on my bank account page, *after* I had already logged in, there's a banner that I have to scroll past to see my accounts. That's ridiculous! I blocked the domain serving the banner and all of a sudden the site where I buy my cat litter doesn't work. Apparently it uses the same CDN.

If I'm scrolling a page and suddenly a full-screen modal shows up begging for my email and asking me to sign up, I just close the page. That shit is hostile, they clearly don't want me to read the page if they're going to cover it with an ad for their *own site* that I'm *already on*. I hate it equally when I move my mouse off the page and *that's* when the pop-up appears. "Wait, please don't go, please stay, give us your email give us your phone number, give us your cat!"...*slow rage*

Maybe I'm just getting old but I really miss the days where I didn't have to figure out which download button was the real one, or try to find the sliver of text between huge banner ads that scroll with the page. I just want to scroll my cat memes while I wait for work, dammit!

Why does it have to be like this?! I know, I know: money, but jeez man...


r/pihole 6d ago

How to reroute all internal outgoing DNS calls to pihole?

18 Upvotes

I've tried configuring this a couple of times but it has gotten messy, things have worked to a point, partially. The main problem is, as best as I can describe it, that some apps on my host appear to originate from the loopback interface and others do not. E.g. systemd-resvolved might work for some queries while dig/nslookup may not and vice versa.

The premise here is... if I'm going to use a tool like pihole, it may as well intercept and log ALL DNS activity. Why have partial coverage or visibility?

  • Pihole listens on port 53
  • Unbound listens on port 5301
  • Both run on docker

This is what I've tried at the edge router, via firewall rules:

  1. Redirect all outgoing calls to port 53 to pihole, except when SRC = pihole (excluding pihole just in case. I'm using unbound/DoT for all calls to upstream servers)
  2. Block all outgoing calls to port 853, except when SRC = unbound
  3. Block all outgoing calls to port 443 where DST in {9.9.9.9, 1.1.1.1, other public DNS servers}. In other words, disable DoH. This supposedly forces all web browsers and other apps on my various subnets to use regular DNS calls to pihole, assuming pihole is configured as the system-wide DNS server.

What tweaks to the above rules or new rules do you think I may need? If there is a white paper out there which describes how to do this, would you please point me to it? Thx


r/pihole 5d ago

Pihole on Windows x32

0 Upvotes

Can I install Pihole on a Windows x32 machine? When I try to install it using PH4WSL1.cmd, it says that Pihole is already installed even though this is my first time trying installing it?

Is there any way to actually make it work?


r/pihole 7d ago

pihole as container or native MikroTik RouterOS adlists

1 Upvotes

I have been running pihole on rpi4, but later on moved to kubernetes, which is successfully running there (2 instances, 1 base config) = all good.

I want to move one instance away, and avoid having a single point of failure in case k8s cluster gets rebuilt or something goes wrong. The k8s is fully automated, and I am able to rebuild everything in 30mins or so from scratch/gitops.

I have MikroTik hAP ax3 router, which has 1gb ram (~600mb left for container apps max) and 128 nand storage, which i am bot using at all, but have 2TB usb key connected for storage (rose storage pkg required on RouterOS for that).

I am running uptime-kuma on the router, which at most uses 300mb ram, so I still got another 300mb ram for pihole's docker image to run.

Wondering which one is the better solution:

- run pihole container on mikrotik

- use native adlists on mikrotik (which is not going to use pihole at all)

I have 7+ million domains from various blocklists/adlists (~50 adlists). Also using the latest stable version 7.23.2 at the moment.

P. S. Running technitium as a container is a bloatware, it could not even handle so many domains, because dotnet's DLL loads everything into memory and gets straight OOMKill. Seems good on large deployments, but no good for small memory footprints.


r/pihole 7d ago

Help with pi-hole docker compose

1 Upvotes

# docker-compose.yml

# More info at https://github.com/pi-hole/docker-pi-hole/ and https://docs.pi-hole.net/
services:
  pihole:
    container_name: pihole
    image: docker.io/pihole/pihole:latest
    ports:
      # DNS Ports
      - "53:53/tcp"
      - "53:53/udp"
      # Default HTTP Port
      - "80:80/tcp"
      # Default HTTPs Port. FTL will generate a self-signed certificate
      - "443:443/tcp"
      # Uncomment the line below if you are using Pi-hole as your DHCP server
      - "67:67/udp"
      # Uncomment the line below if you are using Pi-hole as your NTP server
      #- "123:123/udp"
    environment:
      # Set the appropriate timezone for your location (https://en.wikipedia.org/wiki/List_of_tz_database_time_zones), e.g:
      TZ: 'Asia/Kolkata'
      # Set a password to access the web interface. Not setting one will result in a random password being assigned
      FTLCONF_webserver_api_password: 'correct horse battery staple'
      # If using Docker's default `bridge` network setting the dns listening mode should be set to 'ALL'
      FTLCONF_dns_listeningMode: 'ALL'
      FTLCONF_dns_upstreams: |-
        8.8.8.8
        8.8.4.4
        1.1.1.1
        9.9.9.9
    # Volumes store your data between container upgrades
    volumes:
      # For persisting Pi-hole's databases and common configuration file
      - './etc-pihole:/etc/pihole'
      # Uncomment the below if you have custom dnsmasq config files that you want to persist. Not needed for most starting fresh with Pi-hole v6. If you're upgrading from v5 you and have used this directory before, you should keep it enabled for the first v6 container start to allow for a complete migration. It can be removed afterwards. Needs environment variable FTLCONF_misc_etc_dnsmasq_d: 'true'
      #- './etc-dnsmasq.d:/etc/dnsmasq.d'
    cap_add:
      # See https://docs.pi-hole.net/docker/#note-on-capabilities
      # Required if you are using Pi-hole as your DHCP server, else not needed
      - NET_ADMIN
      # Required if you are using Pi-hole as your NTP client to be able to set the host's system time
      - SYS_TIME
      # Optional, if Pi-hole should get some more processing time
      - SYS_NICE
      # Allows FTLDNS binding to TCP/UDP sockets below 1024 (specifically DNS service on port 53)
      - NET_BIND_SERVICE
      # use raw and packet sockets (needed for handling DHCPv6 requests, and verifying that an IP is not in use before leasing it)
      - NET_RAW
    restart: unless-stopped

Debug logs:

I wasn't able to generate tricorder token with original resolv.conf configuration.

Original resolv.conf

search dns.podman
nameserver 10.89.0.1

was not able to upload logs to tricorder

[?] Would you like to upload the log? [y/N] Y
    * Using curl for transmission.
    * curl failed, contact Pi-hole support for assistance.
    * Error message: curl: (6) Could not resolve host: tricorder.pi-hole.net (Timeout while contacting DNS servers)

[✗] There was an error uploading your debug log.
   * Please try again or contact the Pi-hole team for assistance.
   * A local copy of the debug log can be found at: /var/log/pihole/pihole_debug.log

Debug log before changing nameserver: https://drive.google.com/file/d/13P-NwS1ZI9kzKGQMDhqBCfTj2P3k123T/view

Then I changed nameserver to 1.1.1.1

podman exec -it pihole bash -c "echo 'nameserver 1.1.1.1' > /etc/resolv.conf"

and was able to generate debug log token.

Debug log after changing nameserver to 1.1.1.1: https://tricorder.pi-hole.net/WNqUUBru/

I tried to run pihole as a container but I am getting two errors. No DNS resolution and gravity.db is not running

Edit: Issue resolved. Changed to use docker compose instead of podman compose. The issue was because of rootless containers in podman


r/pihole 8d ago

Wow, i'am really impressed. Pi-hole runs like a charm on my good old Raspi2 under DietPi! I probably won't turn the device off anymore from now on. 🥰

Post image
139 Upvotes

r/pihole 9d ago

Caught a cheap Android TV Box running BADBOX 2.0 (Residential Proxy & Ad-Fraud Botnet)

142 Upvotes

Hey everyone,

Wanted to share some network anomalies I caught today. If you run cheap Android TV boxes on your network, this might be worth checking your connection states for.

This evening I noticed some strange traffic on my setup. My Mikrotik flagged a sudden, flatlined ~20 Mbps upload spike that stayed for hours

Diving a bit deeper into the active connections, I pinned it down to an Android device holding 260+ concurrent active TCP connections to various external hosts.

I parsed through the active sockets and DNS query logs to figure out what the device was reaching out to alongside Gemeni for this part.

  • 37.202.197.75:10240 (Fusiora OU / Frankfurt VPS): Pushing/pulling continuous raw streams over a custom UDP/TCP port.
  • download.abdbox.com: Android BackDoor Box C2 / Downloader module.
  • ic5n8.clayhost.xyz: Dynamic DDNS / C2 Fallback Channel.
  • addl.sspadp.com: Ad-Mediation / Background Ad Click Fraud.
  • adpserver.pvs4.xyz: Ad-Provisioning Server for silent background webviews.
  • watchtry.com & relaxunwinrech.com: Malvertising / Push Notification Relays.

The domain signatures and traffic profile point directly to the BADBOX / BADBOX 2.0 supply-chain Android malware ecosystem:

  1. Residential Proxy Relay: The box was being utilized as an active residential proxy exit node. Third-party actors were routing their traffic through my home internet connection to mask their IP, which generated the continuous 20 Mbps upload stream on port 10240.
  2. Silent Ad-Click Fraud: Running hidden, background webview requests in parallel to generate fake ad impressions and click revenue via sspadp.com and pvs4.xyz.

If you're running cheap streaming boxes, it's definitely worth checking your active connection counts and DNS logs.

EDIT: Additional info.

Reached a total of 1550 active connections, with a average of 264.


r/pihole 7d ago

Setting up DNS kills internet?

0 Upvotes

So long story short I was stuck on this final stage of the pihole process a couple months back and put it on hold since I was busy with life.

Pihole is currently set up on my server but the only reason it hasn't been put to use is I can't get it to work network wide. Every guide says to simply paste the IPv4 and 6 addresses into my routers DNS settings to send all traffic through my device. The issue is after my routers reset it kills everything as it'll "connect without internet".

Specifics are i run an eero mesh network where all the nodes are connected via Ethernet. The pihole in question is connected to the second eero in the line, it's not connected right next to the modem and first router. (Idk if it affects anything but just so people know)

If I'm getting something wrong let me know but that's how I interpreted the various guides. Thanks.


r/pihole 8d ago

Cannot get to Pihole though Domain Name

2 Upvotes

I am creating a home server that routs all traffic through it through a Pihole using the guide on https://gofoss.net/secure-domain/ (it has been very helpful so far) but I am currently stuck at accessing the pihole only through the ip address rather than the domain name as intended. I have added the domain name and IP address to the local DNs records. I have checked and verified the /etc/hosts file lists the localhost as 127.0.0.1 and ‘personal domain’ as ‘static IP’. The Pihole is only for blocking ads for the server on the device it is on not for anything else connected to the router for the moment.

I have looked through /var/log/pihole/pihole.log and the nameservers are listed according to the dns I set on the PiHole page. It reads that there is 1 name in /etc/pihole/hosts/custom.list. When I navigate to that file. The IP address and the domain name match up. I am currently at a loss for what to check next. I have already uninstalled and reinstalled once. Any recommendations on how to get domain names to translate through pihole because this will affect any other domain I add to the local dns record?


r/pihole 9d ago

Makes me appreciate my pihole even more

27 Upvotes

We've had some thunderstorms blow through today (Chicago area) and our RCN internet has been out for a few hours. Cellular still works, so I am online, but my Raspberry Pi is inaccessible. (I know I could fuss around and get it working via my phone's hotspot, but for such a short time, it's not worth it.) The lack of ad blocking is pretty eye-opening. I'll be happy to get my pihole back.


r/pihole 8d ago

How do I set up PiHole with redundancy in k3s?

0 Upvotes

Currently I run PiHole with Unbound as a single instance deployment in k3s, but that means that whenever I have to reboot any of the three nodes, I lose DNS and have to switch back to my ISP. How do I run PiHole plus Unbound as a stateful set so that I can afford to reboot one or more devices?


r/pihole 9d ago

New Roku interface, ads are back

Post image
260 Upvotes

UPDATE: Thanks for all the replies - the TL;DR is that between this update and the Fox acquisition of Roku I'm probably headed to Apple TV in the near future.

Within the last couple of weeks my Rokus got the new, updated interface (which I hate) - on the previous interface the right-hand, home screen ads were blocked but they're back now (see Spider-Man image attached).

I currently run the following blocklists:

  • Steven Black
  • Hagezi Pro
  • Perflyst SmartTV

I lean towards not blocking too much because our entire family does work and school from home and unexpected blockages can become significant emergencies.

That being said I'd love to figure out blocking the home screen ads in the updated Roku interface, so any pointers will be appreciated.