3 min read

šŸ›”ļø How I Stopped Ads, Trackers, and Malware Before They Even Reach My Devices

šŸ›”ļø How I Stopped Ads, Trackers, and Malware Before They Even Reach My Devices
Photo by Zulfugar Karimov / Unsplash

One DNS server. Every device on my network. Protected.


You install an ad blocker on Chrome. Done, right?

Not really.

Your phone has no protection. Your smart TV doesn't. Your IoT devices are quietly phoning home to servers you've never heard of. Browser extensions only protect one browser, on one device.

I moved the block upstream — to the DNS layer. Where nothing can bypass it.


šŸ¤” Why DNS Is the Right Place to Block

Every request your device makes starts with a DNS lookup.

Your device → "Where is connect.facebook.net?"
DNS server  → "IP: 157.240.x.x"
Your device → connects, loads tracker

If I control the DNS server, I intercept that first question and reply:

Your device → "Where is connect.facebook.net?"
AdGuard     → "NXDOMAIN — doesn't exist"
Your device → request dies. Nothing loads.

The block happens before the request leaves your network. Before it reaches the device. Before anything renders.

That's AdGuard Home — a self-hosted DNS server with blocklists built in.


šŸ–„ļø Where It Runs in My Setup

I run AdGuard Home on my k3s homelab — the same 5-node Raspberry Pi + NUC cluster from my previous post.

Two instances for DNS redundancy:

Instance Node IP Role
Primary zeta-core 192.168.50.240 Primary DNS via MetalLB
Secondary zeta-lite 192.168.50.115 Fallback DNS

My ASUS RT-AX53U router has both IPs set as DNS servers. If zeta-core has a slow boot after a power cut (it does, sometimes), zeta-lite keeps DNS alive for the whole network. Internet survives. Nobody notices.

Upstream DNS is set to 1.1.1.1 (Cloudflare) + 8.8.8.8 (Google) — AdGuard forwards clean queries there.


šŸ” What I Found When I First Looked at the Query Log

Opening the AdGuard dashboard for the first time was genuinely unsettling.

On a normal evening:

  • šŸ“ŗ Smart TV → 47 requests to tracking and analytics domains in one hour
  • šŸ“± Phone → reached for Google ad servers 23 times while I was asleep
  • šŸ’” Smart bulbs → pinged manufacturer servers every 4 minutes
  • 🌐 One website → tried to load from 11 different ad networks simultaneously

Nearly 1 in 5 DNS queries on my network was going somewhere it had no business going.

After AdGuard — almost all of it blocked silently.


šŸ›”ļø What the Blocklists Actually Cover

AdGuard Home uses community-maintained blocklists. I run three:

  • AdGuard DNS filter — ads, trackers, malware domains
  • Steven Black's Hosts — extended malware + phishing coverage
  • OISD — broad tracker and telemetry coverage

What gets blocked in practice:

Category Examples
Ads DoubleClick, media.net, outbrain
Trackers Facebook pixel, hotjar, mixpanel
Malware domains Flagged phishing and C2 domains
Telemetry Windows telemetry, smart TV analytics
Crypto miners coin-hive variants, cryptojacking scripts

You can whitelist anything that breaks — I had to whitelist a couple of work SSO domains early on. Takes 30 seconds.


āš™ļø Router Config — The One Change That Protects Everything

In my ASUS RT-AX53U:

LAN → DHCP Server → DNS settings:
  DNS Server 1: 192.168.50.240   ← AdGuard primary (MetalLB)
  DNS Server 2: 192.168.50.115   ← AdGuard secondary (zeta-lite)

That's it. Every device on WiFi — phones, laptops, TVs, guest network, IoT — now routes DNS through AdGuard. No per-device config. No app installs.


šŸ“Š Real Numbers from My Network

  • Blocked percentage: ~18–22% of all queries
  • Top blocked category: Tracking & Telemetry
  • Biggest offender: Smart TV (not even close)
  • Latency impact: <1ms added — completely imperceptible

The smart TV stat is what gets people. It looks like a TV. It behaves like a data collection endpoint that occasionally plays Netflix.


šŸ’¬ Final Thought

You can't install an ad blocker on a smart TV. You can't configure protection on every guest's phone. But you can control the one thing everything has to go through — DNS.

AdGuard Home runs quietly in my cluster, blocking thousands of requests a day, protecting every device on my network without any of them knowing it exists.

Silent. Invisible. Always working. That's the infrastructure I like.


Want the full k3s deployment — Kubernetes manifests, MetalLB service, Traefik ingress, ArgoCD app definition? That's the next post.

Subscribe to RootBySatya so you don't miss it.

— Satya šŸ‘Øā€šŸ’» Platform Engineer | Homelab | GitOps | DNS nerd