Contents8 sections
AdGuard Home runs on every Raspberry Pi. AdGuard publishes Linux builds for ARMv6, ARMv7 and 64-bit ARM, so you download the right tarball, unpack it, install it as a service, and point your router's DNS at the Pi. From then on, every device on the network gets tracker and ad domains blocked without installing anything.
It's one of the two usual answers to "what do I put on a spare Pi?" (the other is Pi-hole). Here's what it does, and where DNS blocking stops.
What it is
AdGuard Home is a DNS server that answers requests for known ad and tracking domains with a dead end, so devices never connect to them. The README says it's built on the same software as AdGuard's public DNS service, and the two "share a lot of code." The difference is control: you choose the blocklists, see the query log and write your own rules.
It's free and open source under GPL-3.0. The latest release is v0.107.79, published 18 August 2026 (GitHub releases API, checked 29 September 2026). The version number still starts with 0.107, and has for many releases. That's how the project numbers its versions. Don't read it as a sign the software is unfinished.
Raspberry Pi install
AdGuard's knowledge base has a short Pi guide. The core of it:
wget 'https://static.adguard.com/adguardhome/release/AdGuardHome_linux_armv6.tar.gz'
tar -f AdGuardHome_linux_armv6.tar.gz -x -vThe guide says to swap armv6 for "the ARM version that is best supported by your Pi." Which one that is depends on the board and the OS you run: ARMv6 for a Pi 1 or original Zero, and 64-bit ARM (arm64) for a 64-bit OS on a newer Pi. Then install it as a service with sudo ./AdGuardHome -s install.
The official platform table lists Linux builds for AMD64, x86, 64-bit ARM, ARMv5, ARMv6 and ARMv7. There are also MIPS, 64-bit PowerPC LE and 64-bit RISC-V builds.
Parts of the Pi guide are dated. It tells you to SSH in as pi with the password raspberry. Raspberry Pi OS dropped the default pi user in April 2022, and you now create an account at first boot or in Raspberry Pi Imager. Use that account instead.
Requirements. People search for "adguard home raspberry pi requirements," but the official docs don't state a minimum RAM or CPU. This page won't invent one. If you need a figure for a Pi Zero, measure it on your own board.
Ports you'll need
From the getting-started guide:
- 3000/TCP for the first-run setup wizard. On first launch, it listens on
0.0.0.0:3000. - 53 for DNS itself. Binding to port 53 usually needs root, so the guide has you run it with
sudo(or register it as a service). - 80/TCP for the web interface. The guide lists it as a required port, and the setup wizard lets you change it.
- If you use it, the built-in DHCP server needs its usual ports as well.
Two gotchas come up constantly. First, on Ubuntu, systemd-resolved already sits on 127.0.0.53:53. The FAQ explains how to free the port. Second, you don't have to run as root forever: the docs show how to give the binary CAP_NET_BIND_SERVICE (plus CAP_NET_RAW for DHCP) so it runs as a normal user.
Docker and other installs
There's an official Docker image and an official Snap package. The Docker image covers 64-bit AMD, x86, 64-bit ARM, ARMv6, ARMv7 and 64-bit PowerPC. The Snap covers 64-bit AMD, x86, 64-bit ARM and ARMv7.
One difference matters: auto-updates are disabled for Docker, Home Assistant and Snap installs. You update by pulling a new image. Community packages exist too, including an OpenWrt LuCI app and a Cloudron app, maintained by third parties.
Features that set it apart
The README has a comparison table against Pi-hole. The features AdGuard Home ships without add-ons:
- Encrypted DNS in both directions. It can use DNS-over-HTTPS, DNS-over-TLS, DNS-over-QUIC and DNSCrypt upstreams. It can also act as a DoH, DoT, DoQ or DNSCrypt server for your own devices, which is handy for phones away from home.
- Per-client configuration. Different rules for the kids' tablet and the TV.
- Parental control and safe search. Adult-domain blocking and forced safe search on search engines are built in.
- Access settings. You can restrict which clients may use the server.
- HTTPS for the admin interface.
- Cross-platform. Native builds for Windows, macOS, FreeBSD and OpenBSD as well as Linux.
- A built-in DHCP server.
A caution on that table: it still says Pi-hole needs lighttpd to be configured by hand for HTTPS. Pi-hole v6 (February 2025) replaced lighttpd with a web server built into pihole-FTL, with native HTTPS support. Treat the table as AdGuard's view, partly dated. The fair, current comparison is on Pi-hole vs AdGuard Home.
What it can't block
AdGuard is upfront about this, and it's the most useful paragraph in the README. A DNS-level blocker cannot remove:
- YouTube and Twitch ads
- Sponsored posts on Facebook, X and Instagram
As the README puts it, "any advertising that shares a domain with content cannot be blocked by a DNS-level blocker." If "adguard home block youtube ads" is why you're here, the honest answer is no. That's true of Pi-hole and every other DNS blocker, too. A content blocker in the browser is still the tool for that job.
Where DNS blocking earns its keep is on devices where you can't install an ad blocker: smart TVs, speakers and IoT gadgets.
Who it suits
Pick AdGuard Home if you want encrypted DNS and per-device rules working in one binary, if you might run it on Windows or a NAS, or if you just want fewer moving parts. If you prefer a larger community of blocklists and guides, look at Pi-hole. If you want to compare more options, including Technitium and Blocky, see Pi-hole alternatives.
For other things to run on the same board, see Raspberry Pi self-hosted apps.
At a glance
- Licence
- GPL-3.0
- Open source
- Yes
- Runs as
- Self-hosted
- Runs on
- LinuxmacOSWindowsFreeBSDOpenBSDDocker
- Pricing
- Free (open source) (checked 2026-09-29)
- Latest release
- v0.107.7918 August 2026
Pros and cons
Pros
- A single binary, with official builds for ARMv5, ARMv6, ARMv7 and 64-bit ARM on Linux
- DNS-over-HTTPS, DNS-over-TLS, DNS-over-QUIC and DNSCrypt built in, as both client and server
- Per-client settings, parental-control blocking and forced safe search out of the box
- Runs on Windows and macOS natively, not only Linux
- Can run without root on Linux by granting the binary network capabilities
Cons
- DNS blocking can't remove YouTube or Twitch ads, or sponsored social posts (AdGuard says so itself)
- The official docs don't publish minimum RAM or CPU figures
- Some of the official Raspberry Pi guide is dated (it still mentions the old default 'pi' password)
- Auto-update is disabled in Docker, Snap and Home Assistant installs; you update the image yourself
Sources (9)ShowHide
- AdGuard Home README (overview, comparison, known limitations) · accessed 2026-09-29
- AdGuard DNS Knowledge Base: AdGuard Home, Getting started · accessed 2026-09-29
- AdGuard DNS Knowledge Base: AdGuard Home, Supported platforms · accessed 2026-09-29
- AdGuard DNS Knowledge Base: AdGuard Home, Raspberry Pi · accessed 2026-09-29
- AdGuard DNS Knowledge Base: AdGuard Home, Encryption · accessed 2026-09-29
- AdGuard DNS Knowledge Base: AdGuard Home, FAQ · accessed 2026-09-29
- Raspberry Pi: Bullseye update, April 2022 (default 'pi' user removed) · accessed 2026-09-29
- GitHub releases API: AdguardTeam/AdGuardHome latest (v0.107.79, 2026-08-18) · accessed 2026-09-29
- AdGuard Home LICENSE.txt (GPL-3.0) · accessed 2026-09-29