Back to articles
Technology Insight

Building Your Own Network-Wide Ad-Blocking DNS Server with AdGuard Home on a Linux VPS

May 29, 2026

Introduction: The Quest for Clean, Secure, and Private Browsing

In today's hyper-connected digital ecosystem, modern internet browsing has become increasingly compromised by intrusive advertisements, tracking scripts, and malicious telemetry. While browser-based extensions offer a temporary fix, they are fundamentally limited. They fail to protect non-browser applications, smart TVs, IoT devices, and mobile applications, while simultaneously consuming valuable local device resources.

The ultimate solution lies in network-wide filtering via a self-hosted DNS server. By deploying AdGuard Home on a Linux Virtual Private Server (VPS), you can establish a centralized, high-performance DNS sinkhole. This setup intercepts and drops unwanted traffic before it ever reaches your devices. This comprehensive guide provides a step-by-step, production-grade blueprint to self-hosting your own private, ad-blocking DNS infrastructure.


Why AdGuard Home on a VPS Beats Traditional Solutions

While local deployments like Pi-hole on a Raspberry Pi are popular for home networks, migrating your DNS architecture to a cloud-based VPS offers distinct structural advantages for businesses and remote professionals:

  • Universal, Location-Independent Protection: Whether you are working from a corporate office, a home network, or a public Wi-Fi hotspot, your devices remain protected by routing traffic through your cloud VPS.
  • Enterprise-Grade Reliability: Cloud VPS providers offer high-availability infrastructure, redundant power supplies, and robust network uplinks, minimizing the risk of downtime that could disrupt internet connectivity.
  • Resource Efficiency: Instead of running heavy browser extensions on every endpoint, the computational overhead of filtering is entirely offloaded to the remote server.
  • Advanced Protocol Support: A VPS allows you to easily implement modern, encrypted DNS protocols like DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT), securing your queries against local ISP eavesdropping and man-in-the-middle attacks.

Prerequisites and System Requirements

Before initiating the deployment, ensure you have gathered the necessary infrastructure components:

  1. A Linux VPS: A minimal instance with 1 vCPU, 1GB RAM, and Ubuntu 22.04 LTS or Debian 12 is highly recommended. Providers like DigitalOcean, Linode, or Vultr work perfectly.
  2. A Static IPv4/IPv6 Address: Provided automatically by your VPS hosting platform.
  3. A Registered Domain Name: Essential for generating valid SSL/TLS certificates required by DoH and DoT protocols (e.g., dns.yourdomain.com).
  4. Root or Sudo Access: SSH administrative privileges to configure the Linux environment.

Step 1: Preparing the Server Environment

First, establish an SSH connection to your remote VPS and update the system packages to their latest stable releases to patch any security vulnerabilities:

sudo apt update && sudo apt upgrade -y

By default, many modern Linux distributions come with systemd-resolved enabled, which binds to port 53 (the standard DNS port). This will create a conflict with AdGuard Home. To check for conflicts and disable it, execute the following commands:

sudo systemctl disable systemd-resolved
sudo systemctl stop systemd-resolved
Important Architectural Note: Once systemd-resolved is disabled, temporary local DNS resolution on the server may break. Edit /etc/resolv.conf and add a public upstream DNS server (like Cloudflare or Google) to maintain internet connectivity during the installation: nameserver 1.1.1.1.

Step 2: Automated Installation of AdGuard Home

The AdGuard Home development team provides an official, streamlined installation script that handles binary deployment and service configuration automatically. Execute the following command on your server:

curl -s -S -L [https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh](https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh) | sh

Upon successful execution, the script will download the latest compiled binary, move it to the appropriate system directory, and register AdGuard Home as a background systemd daemon. The terminal output will display the specific IP address and port (usually port 3000) required to access the initial web configuration wizard.


Step 3: Initial Setup and Web Interface Configuration

Open a web browser on your local machine and navigate to http://your-vps-ip:3000. Follow these essential configuration steps within the setup wizard:

1. Network Interfaces Configuration

For the Admin Web Interface, bind it to all interfaces or select your specific public IP address, and set the custom port to 80 or 8080. For the DNS Server Interface, ensure it is set to listen on All Interfaces on port 53. This guarantees the server can accept incoming DNS queries from external devices.

2. Administrator Credential Creation

Establish a highly secure, complex password for your administrator account. Since this web interface will be accessible via the public internet, avoiding weak credentials is vital to prevent unauthorized system modifications.


Step 4: Securing Your Infrastructure with Encryption (DoH / DoT)

Sending standard DNS queries over unencrypted UDP/TCP port 53 leaves your browsing data vulnerable to inspection. To mitigate this risk, you should secure your AdGuard Home server using Let's Encrypt SSL certificates to enable DNS-over-HTTPS and DNS-over-TLS.

Install the certbot utility to automate certificate acquisition:

sudo apt install certbot -y
sudo certbot certonly --standalone -d dns.yourdomain.com

Once the certificate is successfully issued, log into your AdGuard Home web dashboard and navigate to Settings > Encryption Settings. Check the box to enable encryption, enter your domain name, and provide the absolute system paths to your certificate files:

  • Path to certificate: /etc/letsencrypt/live/[dns.yourdomain.com/fullchain.pem](https://dns.yourdomain.com/fullchain.pem)
  • Path to private key: /etc/letsencrypt/live/[dns.yourdomain.com/privkey.pem](https://dns.yourdomain.com/privkey.pem)

Click save. Your DNS server is now fully equipped to handle encrypted queries via port 853 (DoT) and port 443 (DoH).


Step 5: Optimizing Upstream DNS and Ad-Blocking Filters

To ensure rapid query resolution and maximum privacy, navigate to Settings > DNS Settings. Replace the default upstream servers with privacy-centric options, utilizing fast parallel queries (Bootstrap DNS):

[https://dns.cloudflare.com/dns-query](https://dns.cloudflare.com/dns-query)
[https://dns.quad9.net/dns-query](https://dns.quad9.net/dns-query)

Next, configure your blocklists by navigating to Filters > DNS Blocklists. AdGuard Home pre-configures the standard AdGuard base filter, but you can enhance your security posture by subscribing to additional curated repositories:

  • OISD (Big/HaGeZi): Excellent for comprehensive telemetry, tracking, and malware blocking without causing false positives.
  • Steven Black's List: A highly respected consolidated list targeting adware, malware, and fake news domains.

Step 6: Client Configuration and Testing

To route your network traffic through your new server, update the DNS settings on your target devices:

  • Mobile Devices (iOS/Android): Utilize the native Private DNS or Encrypted DNS profile options, inserting your domain name (e.g., dns.yourdomain.com).
  • Routers: For full home or office coverage, modify the WAN/LAN DNS settings on your edge router to point directly to your VPS's static IPv4 address.

Verify functionality by opening the AdGuard Home dashboard and reviewing the Query Log. You should see incoming requests successfully classified, with advertising and tracking domains highlighted in red as "Blocked".


Conclusion and Best Practices

By successfully deploying AdGuard Home on a Linux VPS, you have created a powerful, scalable, and secure DNS filtering system. This architecture protects your entire ecosystem from unwanted data tracking, intrusive ads, and malicious web threats. To maintain long-term stability and security, ensure you regularly run system updates, monitor your server's firewall rules to prevent open-resolver abuse, and periodically update your DNS blocklist subscriptions.

Building Your Own Network-Wide Ad-Blocking DNS Server with AdGuard Home on a Linux VPS | DPTCloud