Back to articles
Technology Insight

Building Your Own Private Cloud Security Service: How to Deploy AdGuard Home on a VPS for Network-Wide Ad and Malware Blocking

June 4, 2026

Introduction: The Growing Need for Network-Wide Security

In today's hyper-connected world, our home networks are flooded with more than just the content we actively seek. Background tracking scripts, intrusive advertising networks, and sophisticated phishing domains constantly consume bandwidth and compromise our digital privacy. While browser-based extensions offer a temporary fix for individual laptops or desktops, they fail to protect the broader ecosystem of connected devices, including smart TVs, gaming consoles, mobile applications, and Internet of Things (IoT) appliances.

To achieve comprehensive protection, modern households require a centralized, server-side solution. This guide provides a detailed, step-by-step walkthrough on how to build your own private Cloud Security Service by deploying AdGuard Home on a Virtual Private Server (VPS). By routing your home DNS traffic through your own self-hosted cloud server, you can eliminate ads and block malware across your entire network, regardless of the operating system or device type.

Why AdGuard Home on a VPS Outperforms Traditional Solutions

Many tech-savvy users are familiar with local DNS sinkholes like Pi-hole deployed on a Raspberry Pi within the local area network (LAN). While effective at home, local deployments possess inherent limitations that a cloud-based VPS deployment elegantly resolves.

1. True Mobility and Ubiquity

When AdGuard Home is hosted on a public VPS, its protective umbrella extends far beyond the physical boundaries of your house. By using modern encrypted DNS protocols such as DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT), you can configure your smartphones, tablets, and laptops to use your private secure DNS server even when connected to public Wi-Fi networks or cellular data.

2. High Availability and Reliability

Residential internet connections are prone to intermittent outages, dynamic IP changes, and hardware failures. A VPS hosted in an enterprise-grade data center guarantees 99.9% uptime, redundant power supplies, and stable static IPv4 and IPv6 addresses, ensuring your core network navigation system never goes offline.

3. Resource Efficiency

AdGuard Home acts as a lightweight, high-performance DNS caching proxy written in Go. Running it on a remote server unburdens your local router's CPU and RAM, allowing consumer-grade network hardware to focus entirely on routing traffic efficiently.

Prerequisites and System Requirements

Before initiating the installation process, ensure you have gathered the following core components:

  • A Linux VPS: A minimal instance from providers such as DigitalOcean, Linode, Vultr, or Hetzner. A single-core CPU with 1 GB of RAM and Ubuntu 22.04 LTS or 24.04 LTS is perfectly adequate.
  • A Domain Name: A registered domain (or subdomain) pointed to your VPS's static IP address. This is strictly necessary for generating SSL certificates to secure encrypted DNS traffic.
  • SSH Access: Root or sudo-privileged terminal access to your remote server.

Step-by-Step Deployment Guide

Step 1: System Preparation and Firewall Configuration

Connect to your VPS via SSH and update the core package repository to ensure all security patches are current:

sudo apt update && sudo apt upgrade -y

By default, Ubuntu systems utilize systemd-resolved, which binds to port 53 (the standard DNS port). We must disable or adjust this service to prevent port conflicts with AdGuard Home. Run the following commands to disable the stub listener:

sudo mkdir -p /etc/systemd/resolved.conf.d
echo -e "[Resolve]\nDNSStubListener=no" | sudo tee /etc/systemd/resolved.conf.d/adguard.conf
sudo systemctl restart systemd-resolved

Next, configure your firewall (UFW) to allow essential management and DNS traffic:

sudo ufw allow 22/tcp
sudo ufw allow 53/tcp
sudo ufw allow 53/udp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 3000/tcp
sudo ufw enable

Step 2: Installing AdGuard Home

Execute the automated installation script provided by the AdGuard team to download and configure the binary for your specific architecture:

curl -s -S -L [https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh](https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh) | sh -s -- -v

Once completed, the script will output the IP address and port (usually http://your-vps-ip:3000) required to access the web-based initialization wizard.

Step 3: Initial Web Setup and SSL Configuration

Navigate to the initialization URL in your web browser. Follow the on-screen prompts to set up your administrative username and secure password. Ensure that the DNS server interface is set to listen on All Interfaces.

Crucial Security Rule: Never leave your cloud DNS server open to the public without encryption or authentication, as it can be weaponized in Distributed Denial of Service (DDoS) DNS amplification attacks.

To secure your connection, obtain a free SSL certificate via Let's Encrypt using certbot:

sudo apt install certbot -y
sudo certbot certonly --standalone -d your-domain.com

Inside the AdGuard Home dashboard, navigate to Settings > Encryption Settings. Enable encryption, enter your domain name, and paste the paths to your private key and certificate chain generated by Certbot.

Optimizing Blocklists and Security Filters

With the infrastructure established, navigating to Filters > DNS Blocklists allows you to curate the filtering engines. For a balanced deployment that maximizes ad-blocking without breaking standard web applications, consider enabling the following lists:

  1. AdGuard Base Filter: The core engine targeting global advertising networks.
  2. Peter Lowe's List: An authoritative, highly curated database of tracking and malware domains.
  3. OISD (Big or Medium): An excellent, comprehensive list designed to minimize false positives while maximizing protection.
  4. Phishing Army: Dedicated strictly to blocking active identity theft and phishing websites.

Connecting Your Home Network and Mobile Devices

To enforce cloud-based security across your home infrastructure, you have two primary options:

Option A: Router-Level Integration (LAN-wide)

Log into your residential router's management dashboard, locate the WAN or DHCP settings, and replace the default ISP DNS addresses with your VPS's public static IPv4/IPv6 addresses. Every device connecting to your home Wi-Fi will instantly inherit protection without further configuration.

Option B: Encrypted Mobile Integration (On-the-Go)

For modern mobile platforms, utilize native encrypted DNS capabilities to retain protection over cellular networks:

  • Apple iOS/macOS: Utilize a generated .mobileconfig profile linked to your DoH/DoT endpoint.
  • Android: Navigate to Settings > Network & Internet > Private DNS and enter your designated domain name (e.g., dns.your-domain.com).

Conclusion: Control and Privacy Reclaimed

By shifting your DNS resolution to a privately controlled VPS running AdGuard Home, you regain absolute visibility and authority over your network's data egress. You effectively eliminate intrusive marketing scripts, harden your household defenses against malware, and drastically reduce bandwidth consumption. Managing your own cloud security service is a highly rewarding project that pays immediate dividends in privacy, speed, and digital peace of mind.