← Back to Portfolio
DNS FILTERING

Pi-hole DNS Protection

Pi-hole runs on my Raspberry Pi as a network-wide DNS sinkhole, blocking suspicious domains, malware infrastructure, and trackers before any device on the network makes a connection. Paired with DNS-over-HTTPS, every query is encrypted end-to-end.

49,305
Total Queries
13,209
Queries Blocked
26.8%
Percentage Blocked
809,883
Domains on Blocklists
11
Active Clients

Project Overview

Standard DNS sends queries in plain text, exposing browsing habits and opening the door to DNS hijacking and surveillance. Pi-hole silently drops queries for known malicious and unwanted domains at the DNS layer, protecting every device on the network without installing anything on individual machines. Cloudflare's DoH proxy (cloudflared) wraps all upstream resolution in TLS, making DNS traffic indistinguishable from regular HTTPS.

How DNS-over-HTTPS Works Here

💻
Device
Any LAN client
DNS query
port 53
🕳️
Pi-hole
Sinkhole / filter
Encrypted
HTTPS / TLS
🔐
cloudflared
DoH proxy
DoH
Resolves
1.1.1.1
☁️
Cloudflare
Upstream resolver

If Pi-hole matches the domain against a blocklist, the query is sinkholed immediately and never reaches cloudflared — saving bandwidth and blocking the threat before any connection is made.

Key Features

Suspicious Domain Categories Blocked

Pi-hole is configured to block entire categories of threat infrastructure, not just individual IPs.

Malware C2 Servers Phishing Domains Cryptomining Pools Botnet Infrastructure Ransomware Callbacks Typosquatted Domains Ad Networks Tracking & Telemetry Fingerprinting Scripts Spam Infrastructure Fake Update Servers Data Broker APIs

Configuration Highlights

Key settings across cloudflared and Pi-hole:

# cloudflared – config.yml (DoH proxy) proxy-dns: true proxy-dns-port: 5053 proxy-dns-upstream: - https://1.1.1.1/dns-query - https://1.0.0.1/dns-query # Pi-hole – upstream DNS points to cloudflared PIHOLE_DNS_1=127.0.0.1#5053 PIHOLE_DNS_2=127.0.0.1#5053 DNSSEC=true CACHE_SIZE=10000 REV_SERVER=true # local reverse DNS

Skills Demonstrated

DNS protocol & architecture
DNS-over-HTTPS (DoH) implementation
Linux system administration
Network security hardening
Threat intelligence integration
DNSSEC configuration
Docker & service management
Firewall & port management
Log analysis & monitoring
Incident response