36,367 stars · GPL-3.0-only, read from /blob/master/LICENSE.txt — plain and unmodified, and the only real copyright line is the FSF's own 'Copyright (C) 2007 Free Software Foundation, Inc.'; the appendix carries the unfilled 'Copyright (C) <year> <name of author>' template, so AdGuard asserts no copyright in the licence file at all · v0.107.79 (2026-08-18), read from /releases/latest as a yearless '18 Aug 15:45' and settled by the ungh releases record (2026-08-18T15:45:27Z). The 0.108 line has been in beta since 2026-07-30 (v0.108.0-b.90) while 0.107.x keeps taking stable patches · Track this in Scout
A home DNS server that refuses to answer for advertising and tracking addresses, with encrypted DNS built in.
▶Repo detailsthe review · specs · pros & cons · install
What it is
AdGuard Home is a DNS server — the service that turns a name like example.com into a numeric address — with blocklists, a web page of statistics and per-device rules. It also speaks the encrypted forms of DNS, so the questions the household asks are not readable by the network in between.
What it is good for. A household or a small office with devices that cannot run an ad blocker: a smart television, a games console, a phone with a locked-down browser. One always-on machine does the work for all of them. It is also the clearest way to see what a device is quietly talking to, which is often a surprise.
- Encrypted DNS is built in. Several alternatives need a second program bolted alongside for it.
- Per-device rules, a readable statistics page and a query log, all in one program with no database to install.
- Plain, unmodified GPL-3.0. That licence binds distribution, not use: running it at home for any number of people triggers nothing.
- The project's own documented install pipes a script from the internet straight into a shell, and it fetches that script from the development branch rather than a fixed release, so what runs is whatever that branch holds at that moment. All three variants in the README do this. The alternative is to download the release archive and run
sudo ./AdGuardHome -s installby hand. - On first start it serves an unauthenticated setup page on every network interface, port 3000, and the administrator account is created on that page. Between the first start and finishing the form, anyone who can reach that port can claim the account. Finish the setup immediately, on a trusted network.
- It is a single point of failure for the whole house. If the machine stops, nothing resolves names until somebody changes the setting back. Also worth knowing: the stable line is 0.107.x, and the 0.108 line has been in test builds since July 2026, so the version you install is not the newest number on the releases page. The project publishes no memory, disk or processor requirement anywhere, which is a real gap for software commonly run on a small single-board computer.
pi-hole/pi-holeThe same whole-network blocking with its own admin page, but encrypted DNS needs a companion service alongside it rather than being built in.
Track this in Scout- 0xERR0R/blocky
A deliberately lightweight blocking DNS proxy driven by a settings file, with no full admin page of this kind.
Track this in Scout - TechnitiumSoftware/DnsServer
A complete DNS server first, with zones and signing, and blocking as one of its abilities rather than the whole purpose.
Track this in Scout
docker run --name adguardhome --restart unless-stopped \ -v /my/own/workdir:/opt/adguardhome/work \ -v /my/own/confdir:/opt/adguardhome/conf \ -p 53:53/tcp -p 53:53/udp -p 80:80/tcp -p 443:443/tcp -p 3000:3000/tcp \ -d adguard/adguardhome
