Contents9 sections
Pi-hole v6, released on 18 February 2025, moved the web interface and a new REST API directly into the pihole-FTL binary. That removed the old lighttpd and PHP dependencies, added native HTTPS, and consolidated the settings into one file, /etc/pihole/pihole.toml. If you're following a guide that tells you to edit lighttpd config or juggle several settings files, it was written for v5.
Pi-hole is the DNS sinkhole most people mean when they say "block ads on the whole network." Here's what it needs, what v6 changed, and what it still leaves to other tools.
What it is
Pi-hole answers your network's DNS queries and returns nothing for domains on its blocklists, so phones, laptops, TVs and anything else using it never reach those ad and tracker servers. It has three parts, each with its own repository and version number:
- Core (the installer and
piholecommand): v6.4.3, released 6 July 2026 - FTL (the DNS resolver, now also the web server and API): v6.7.1, released 19 September 2026
- Web (the admin interface): v6.6, released 6 July 2026
The versions above come from the GitHub releases API, checked 29 September 2026. All three are licensed under the European Union Public Licence 1.2. The core licence notes that commits made before version 3.0 keep their earlier licences.
What changed in v6
From the official announcement:
- Embedded web server and REST API. Both now live inside
pihole-FTL, which "eliminates the need for lighttpd and PHP." The query log gets server-side pagination, so it's faster on large logs. - Subscribed allowlists. Pi-hole calls them "Antigravity": they work like blocklists but allow domains instead of denying them.
- One config file. Settings moved to a single commented TOML file at
/etc/pihole/pihole.toml, migrated automatically from v5. You can change settings by editing it, throughpihole-FTL --config, through the API or web UI, or withFTLCONF_environment variables. Settings made through environment variables become read-only, and Pi-hole says that's the preferred method in Docker. - Redesigned web interface with Basic and Expert modes.
- Native HTTPS, with your own certificate or an auto-generated one.
- An Alpine-based Docker image, which Pi-hole says cuts the image size significantly.
The "pihole v6 api key" question
v6 has no static API token. The API docs say authentication is session-based: you POST your password to /api/auth and get a session ID back. For scripts and integrations, you can create an application password so your real admin password never goes into a config file. Old v5 integrations that used a static token need updating.
Requirements
The prerequisites page is modest:
- 512MB RAM
- 2GB free disk space minimum, 4GB recommended
- A static IP address. A DHCP reservation on your router is fine.
pihole-FTL is pre-built for x86_64 (amd64 and i686), ARMv6, ARMv7, ARMv8 (aarch64) and riscv64. That covers every Raspberry Pi from the original Zero onwards, including the Zero 2 W. Other architectures mean compiling FTL yourself.
Officially supported operating systems are Alpine, Armbian, Debian, CentOS Stream, Fedora, Raspberry Pi OS and Ubuntu, on systemd or sysvinit, and only while those releases are actively maintained. There's no native Windows or macOS build. On those, you'd use Docker.
Ports
| Port | What for |
|---|---|
| 53 TCP/UDP | DNS. Turn off any other DNS server on the box first. |
| 80 / 443 TCP | Web interface. If those ports are taken, FTL tries 8080/8443 instead. |
| 67 UDP / 547 UDP | Only if you enable the DHCP server (IPv4 / IPv6). |
| 123 UDP | Only if you use FTL's NTP server. |
The docs also give example firewall rules that keep these ports closed to the internet. Pi-hole is designed for your LAN. Don't expose port 53 publicly.
Installing
The README's quick route is:
curl -sSL https://install.pi-hole.net | bashThe README also offers two cautious alternatives: download the script and read it first, or clone the repo. There's also the official docker-pi-hole image. With Docker, configure through FTLCONF_ environment variables, as the v6 announcement recommends.
Encrypted and recursive DNS
Pi-hole forwards the queries it doesn't block to an upstream resolver. It doesn't speak DNS-over-HTTPS or DNS-over-TLS upstream by itself. The official docs cover two add-ons:
- Unbound. Run your own recursive resolver on the same box, so no single upstream provider sees all your lookups. This is the popular "pihole v6 unbound" setup, and the guide is maintained.
- cloudflared (DoH). This is no longer recommended. The docs now carry a warning: Cloudflare deprecated the
proxy-dnsfeature in November 2025, and cloudflared versions updated after 2 February 2026 will no longer work as the guide describes. Existing installs keep working for a while. The guide says new installs this way "are not recommended."
If encrypted DNS upstream matters to you, that's the biggest gap between Pi-hole and AdGuard Home, which has DoH, DoT and DoQ built in.
What it can't do
No DNS blocker can remove ads served from the same domain as the content. AdGuard's documentation lists YouTube and Twitch ads and sponsored social posts as examples, and the same limit applies to Pi-hole. If you searched "pihole youtube ads," the realistic answer is a browser content blocker.
Who it suits
Pi-hole suits you if you run Linux or Docker, like having each piece do one job (Pi-hole for blocking, Unbound for resolving), and value the large community of blocklists and guides. If you want encrypted DNS and per-device rules in a single binary, or you need Windows or macOS, read Pi-hole vs AdGuard Home or the wider Pi-hole alternatives list.
A Pi Zero 2 W or an old Pi 3 is enough for the documented requirements. For other things to run on the same board, see Raspberry Pi self-hosted apps.
At a glance
- Licence
- EUPL-1.2
- Open source
- Yes
- Runs as
- Self-hosted
- Runs on
- LinuxDocker
- Pricing
- Free (open source; donations requested) (checked 2026-09-29)
- Latest release
- v6.4.36 July 2026
Pros and cons
Pros
- Light: the docs ask for 512MB RAM and 2GB of free disk space
- v6 dropped lighttpd and PHP; one pihole-FTL binary now serves DNS, the web UI and the REST API
- Native HTTPS for the admin interface since v6
- Subscribed allowlists ('Antigravity') alongside blocklists
- Official guides for pairing it with Unbound as a private recursive resolver
Cons
- Linux only (or Docker); no native Windows or macOS build
- No built-in encrypted upstream DNS; the official cloudflared DoH guide is now deprecated
- Needs a static IP (a DHCP reservation is fine)
- DNS blocking can't remove ads served from the same domain as the content, such as YouTube's
Sources (12)ShowHide
- Pi-hole blog: Introducing Pi-hole v6 (2025-02-18) · accessed 2026-09-29
- Pi-hole docs: Prerequisites (hardware, OS, architectures, ports) · accessed 2026-09-29
- Pi-hole README (install methods) · accessed 2026-09-29
- Pi-hole docs: API authentication · accessed 2026-09-29
- Pi-hole docs: Unbound guide · accessed 2026-09-29
- Pi-hole docs: cloudflared (DoH) guide, deprecation warning · accessed 2026-09-29
- Pi-hole docker-pi-hole repository · accessed 2026-09-29
- GitHub releases API: pi-hole/pi-hole latest (v6.4.3, 2026-07-06) · accessed 2026-09-29
- GitHub releases API: pi-hole/FTL latest (v6.7.1, 2026-09-19) · accessed 2026-09-29
- GitHub releases API: pi-hole/web latest (v6.6, 2026-07-06) · accessed 2026-09-29
- Pi-hole core LICENSE (EUPL-1.2) · accessed 2026-09-29
- AdGuard Home README: known limitations of DNS-level blocking · accessed 2026-09-29