809,883Domains on Blocklists
Project Overview
Standard DNS sends queries in plain text, exposing browsing habits and opening the door to DNS
hijacking and surveillance. Pi-hole silently drops queries for known malicious and unwanted domains
at the DNS layer, protecting every device on the network without installing anything on individual
machines. Cloudflare's DoH proxy (cloudflared)
wraps all upstream resolution in TLS, making DNS traffic indistinguishable from regular HTTPS.
How DNS-over-HTTPS Works Here
🕳️
Pi-hole
Sinkhole / filter
🔐
cloudflared
DoH proxy
DoH
☁️
Cloudflare
Upstream resolver
If Pi-hole matches the domain against a blocklist, the query is sinkholed immediately and never
reaches cloudflared —
saving bandwidth and blocking the threat before any connection is made.
Key Features
- Network-wide domain blocking — no per-device configuration needed
- DNS-over-HTTPS via cloudflared, encrypting all upstream queries over port 443
- Custom and community blocklists targeting malware, phishing, and tracking domains
- Real-time query logging and dashboard with per-client breakdown
- Local DNS caching to reduce latency and external query volume
- DNSSEC validation to block spoofed or tampered DNS responses
- Allowlist/denylist overrides for fine-grained control
- Works alongside existing firewall rules and Fail2ban
Suspicious Domain Categories Blocked
Pi-hole is configured to block entire categories of threat infrastructure, not just individual IPs.
Malware C2 Servers
Phishing Domains
Cryptomining Pools
Botnet Infrastructure
Ransomware Callbacks
Typosquatted Domains
Ad Networks
Tracking & Telemetry
Fingerprinting Scripts
Spam Infrastructure
Fake Update Servers
Data Broker APIs
Configuration Highlights
Key settings across cloudflared and Pi-hole:
# cloudflared – config.yml (DoH proxy)
proxy-dns: true
proxy-dns-port: 5053
proxy-dns-upstream:
- https://1.1.1.1/dns-query
- https://1.0.0.1/dns-query
# Pi-hole – upstream DNS points to cloudflared
PIHOLE_DNS_1=127.0.0.1#5053
PIHOLE_DNS_2=127.0.0.1#5053
DNSSEC=true
CACHE_SIZE=10000
REV_SERVER=true # local reverse DNS
Skills Demonstrated
DNS protocol & architecture
DNS-over-HTTPS (DoH) implementation
Linux system administration
Network security hardening
Threat intelligence integration
DNSSEC configuration
Docker & service management
Firewall & port management
Log analysis & monitoring
Incident response