Back to articles
Technology Insight

Building a Global Private Ad-Blocker: Deploying AdGuard Home on a VPS for Secure, Network-Wide Protection

May 27, 2026

Introduction to Network-Wide Ad-Blocking

In the modern digital landscape, online privacy, security, and performance have become paramount for both individuals and businesses. Every day, users are bombarded with intrusive advertisements, tracking scripts, and malicious domains that not only compromise privacy but also degrade network bandwidth and device performance. While browser-based extensions offer a basic layer of protection, they fall short when dealing with mobile applications, smart TVs, and Internet of Things (IoT) devices.

To achieve comprehensive, network-wide protection, a DNS-level filtering solution is required. AdGuard Home is an open-source, self-hosted DNS server that acts as a gatekeeper for your network traffic. By intercepting DNS queries and blocking known ad and tracking domains before they ever reach your devices, AdGuard Home provides a cleaner, faster, and more secure browsing experience. Deploying this solution on a Virtual Private Server (VPS) allows you to extend this protection globally, ensuring all your devices remain protected regardless of whether you are at home, in the office, or traveling.

Why Choose a VPS Deployment Over Local Hardware?

While many enthusiasts run AdGuard Home or Pi-hole on a local Raspberry Pi or home server, migrating the setup to a cloud-based VPS offers distinct enterprise-grade advantages:

  • Global Availability: A local installation only protects devices connected to your home network unless complex VPN configurations are managed. A VPS deployment provides a dedicated, static IP address accessible from anywhere in the world.
  • High Reliability and Uptime: Cloud providers offer robust infrastructure with 99.9% uptime SLAs, redundant power supplies, and high-speed network connections, ensuring your DNS resolution never drops.
  • Resource Efficiency: Running DNS filtering on a lightweight, cost-effective VPS offloads processing requirements from your local network hardware.
  • Centralized Management: Manage filtering rules, blocklists, and query logs for all your family or corporate devices through a single, unified dashboard.
---

Prerequisites and Server Preparation

Before initiating the installation, ensure you have the following components ready:

  1. A VPS running a clean installation of a Linux distribution (Ubuntu 22.04 LTS or Ubuntu 24.04 LTS is highly recommended).
  2. A registered domain name (e.g., yourdomain.com) to configure SSL certificates for secure DNS protocols.
  3. A non-root user with sudo privileges configured on your server.
  4. Basic familiarity with the command-line interface (CLI).

Step 1: System Update and Security Baseline

Connect to your VPS via SSH and execute the following commands to update the system packages to their latest versions:

sudo apt update && sudo apt upgrade -y

Next, configure a basic firewall using ufw (Uncomplicated Firewall) to secure your server, ensuring essential ports are accessible:

sudo ufw allow 22/tcp
sudo ufw allow 53/tcp
sudo ufw allow 53/udp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 3000/tcp
sudo ufw enable
Important Note: Port 53 is critical for standard DNS traffic, port 3000 is used for the initial AdGuard Home setup wizard, and ports 80 and 443 are required for web administration and SSL certification.
---

Installing AdGuard Home on the VPS

AdGuard Home provides an automated installation script that simplifies the deployment process significantly. Run the following command in your terminal:

curl -s -S -L [https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh](https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh) | sh -s -- -v

This script downloads the latest binary, unpacks it to the /opt/AdGuardHome directory, and registers AdGuard Home as a background system service that starts automatically upon system boot.

Step 2: Disabling the Default Stub Resolver

On many modern Linux distributions like Ubuntu, a built-in DNS service called systemd-resolved runs by default on port 53. This will cause a conflict with AdGuard Home. To resolve this, disable the stub resolver by editing its configuration file:

sudo nano /etc/systemd/resolved.conf

Uncomment the line #DNSStubListener=yes and change it to:

DNSStubListener=no

Save the file and link the correct configuration by executing:

sudo ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf
sudo systemctl restart systemd-resolved
---

Configuring the AdGuard Home Web Interface

With the service running, open your preferred web browser and navigate to your server's IP address on port 3000 (e.g., http://your_vps_ip:3000). You will be greeted by the AdGuard Home initial setup wizard.

Admin Interface and DNS Server Settings

Follow the on-screen steps to configure the listening interfaces. Set the Admin Web Interface to listen on all interfaces or your specific public IP on port 80 or 3000. Set the DNS Server interface to listen on all interfaces (Port 53).

Create a secure administrator username and a strong, complex password. Once completed, the setup wizard will close, and you can log into the main dashboard at http://your_vps_ip.

Advanced Configuration: Securing Your DNS Traffic

Running an open DNS resolver on the public internet can expose your server to Amplification DDoS attacks. Therefore, it is critical to secure your deployment using encrypted DNS protocols: DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT).

Obtaining an SSL Certificate via Let's Encrypt

Install Certbot to automatically fetch and renew a free SSL certificate for your domain name:

sudo apt install certbot -y
sudo certbot certonly --standalone -d dns.yourdomain.com

Once the certificate is generated successfully, navigate to Settings -> Encryption Settings within the AdGuard Home dashboard. Enable encryption, enter your domain name, and provide the paths to your SSL certificate and private key:

  • Certificate Path: /etc/letsencrypt/live/[dns.yourdomain.com/fullchain.pem](https://dns.yourdomain.com/fullchain.pem)
  • Private Key Path: /etc/letsencrypt/live/[dns.yourdomain.com/privkey.pem](https://dns.yourdomain.com/privkey.pem)

After saving, your private ad-blocker will securely accept encrypted queries via DoH and DoT, preventing third parties and Internet Service Providers (ISPs) from snooping on your browsing history.

---

Optimizing Blocklists and Upstream Servers

To maximize filtering efficiency and minimize latency, fine-tune your performance settings:

1. Choosing Reliable Upstream DNS Providers

Navigate to Settings -> DNS Settings. AdGuard Home relies on upstream servers to resolve allowed queries. Input privacy-focused, fast upstream servers using encrypted formats:

[https://dns.cloudflare.com/dns-query](https://dns.cloudflare.com/dns-query)
tls://dns.quad9.net

Select the Parallel requests or Fastest IP address mode to accelerate resolution speeds.

2. Activating Premium Filter Lists

Navigate to Filters -> DNS Blocklists. By default, AdGuard's standard list is enabled. Enhance your protection by adding trusted community lists such as:

  • OISD (Big or Medium) - For comprehensive, false-positive-free ad blocking.
  • StevenBlack Lists - Excellent for consolidating ad, tracking, and malware domains.
  • AdAway - Optimizes performance for mobile applications.
---

Connecting Your Devices Globally

Now that your global private ad-blocker is operational, configure your endpoint devices to utilize it:

  • Android Devices: Go to Settings -> Network & Internet -> Private DNS, select "Private DNS provider hostname", and enter your domain (e.g., dns.yourdomain.com).
  • iOS/macOS Devices: Use an Apple configuration profile generated via tools like dnscontrol or native profile creators to embed your DoH/DoT endpoints directly into the network stack.
  • Home Routers: For full home network coverage, replace your router's default WAN DNS IP addresses with your VPS's static IPv4 and IPv6 addresses.

Conclusion

By establishing a private AdGuard Home instance on a VPS, you create a robust, sovereign security perimeter that safeguards your digital footprint globally. You regain control over your data, reduce mobile bandwidth utilization, and shield your devices from malicious tracking vectors. As cybersecurity threats and invasive marketing strategies continue to evolve, deploying a self-hosted cloud firewall is no longer just an experimental hobby—it is an essential practice for modern digital sovereignty.