Block ads and trackers network-wide with DNS
Learn how to block ads and trackers network-wide with DNS in Europe, using encrypted, no-logs resolvers like AEU DNS.
Ads and trackers follow you across the internet, slowing down your devices and invading your privacy. While browser extensions and per-device apps can help, they only cover one device at a time. A more efficient approach is to block ads and trackers network-wide with DNS, filtering unwanted domains for every device on your home or office network at once. This article explains how DNS-level filtering works, its benefits and limits, and how a European, encrypted, no-logs resolver like AEU DNS can do this privately.
First, a quick refresher: DNS, or Domain Name System, is the internet's address book. When you type a website name, your device asks a DNS resolver to translate that name into an IP address. By default, this query is sent in plain text, visible to anyone on the network path, including your internet service provider (ISP). Encrypted DNS, such as DNS over HTTPS (DoH) or DNS over TLS (DoT), protects these queries from prying eyes. DoH uses the same port as web traffic (443), making it hard to block, while DoT uses a dedicated port (853), which is simpler but easier for networks to spot. A newer option, DNS over QUIC (DoQ), uses UDP and offers low latency.
DNS-level filtering works by using a resolver that maintains a blocklist of known ad, tracker, and malware domains. When a device on your network asks to resolve one of these domains, the resolver returns a blocked response, and the connection fails. Because this happens at the DNS level, it applies to every device that uses that resolver, from smart TVs to phones to IoT gadgets. No per-device app is needed, which is a huge advantage for families and businesses with many connected devices.
The benefits are clear: faster page loads, reduced data usage, less exposure to malicious sites, and a quieter online experience. However, DNS filtering has limits. It can only block domains, not in-page first-party ads that come from the same domain as the content you're viewing. For example, a news site that serves its own ads from its own domain will still show those ads. DNS filtering also cannot remove empty ad slots or fix layout issues. Still, it blocks a large portion of third-party trackers and ads, which are often the most invasive.
Now, let's talk about privacy. When you use a DNS resolver, that resolver sees every domain you visit. If the resolver keeps logs, your browsing history could be exposed or handed over to authorities. In Europe, privacy is a fundamental right, and the General Data Protection Regulation (GDPR) sets strict rules. However, not all resolvers are equal. For example, dns0.eu, a French, GDPR-aligned, no-logs public resolver, unfortunately shut down in October 2025. Users who relied on it now need a replacement. Another option is DNS4EU, an EU-backed resolver funded by the European Union. It is EU-based and privacy-conscious, but it keeps anonymized and aggregated logs, so it is not a strict no-logs service. That's a fair trade-off for some, but if you want absolute privacy, a no-logs resolver is better.
NextDNS is a widely used and capable resolver, but it is based in the United States, which means it falls under US jurisdiction. This is a neutral fact, not an accusation, but it matters for Europeans who want their data to stay under EU law. AEU DNS is a European, privacy-first DNS service that is strictly no-logs and under EU jurisdiction. It supports encrypted DNS over HTTPS, TLS, and QUIC, and it can enforce blocklists for ads, trackers, and malware. By using AEU DNS, you get the benefits of network-wide filtering without sacrificing privacy.
How do you set this up? Most routers allow you to change the DNS settings for your entire network. You can enter the AEU DNS server addresses, and every device that connects to your Wi-Fi will automatically use them. Alternatively, you can configure each device individually, but that defeats the purpose of network-wide filtering. For encrypted DNS, you may need to configure each device or use a router that supports DoH or DoT. Many modern routers and operating systems now offer these options.
One important consideration is DNS leaks. A DNS leak occurs when your device sends queries outside the configured resolver, for example, to your ISP, exposing your browsing activity. To prevent this, ensure that your router and devices are set to use only the encrypted resolver, and disable any fallback to plain DNS. Some resolvers, including AEU DNS, offer features to help prevent leaks.
Another feature to consider is SafeSearch, which filters explicit content from search results. A DNS resolver can enforce SafeSearch network-wide by pinning the safe-search hostnames for major search engines. This is useful for families and schools.
In summary, blocking ads and trackers network-wide with DNS is a powerful, efficient, and private solution. It works for every device, requires no apps, and can be combined with encrypted, no-logs resolvers like AEU DNS to keep your browsing private. While it has limitations, it is a solid first line of defense. If you're in Europe and value privacy, choosing a European, no-logs resolver is a smart move. Start by checking your router's DNS settings and make the switch today.
Remember, the internet should serve you, not track you. With DNS-level filtering, you can take back control, one domain at a time.
Terms explained
- DNS
- The Domain Name System, which translates human-readable website names into IP addresses.
- DoH
- DNS over HTTPS, an encrypted DNS protocol that uses port 443 and blends with web traffic.
- DoT
- DNS over TLS, an encrypted DNS protocol that uses a dedicated port 853.
- DoQ
- DNS over QUIC, an encrypted DNS protocol that uses UDP and offers low latency.
- DNS leak
- A situation where your device sends DNS queries outside your configured resolver, exposing your browsing activity.
- SafeSearch
- A search engine feature that filters explicit content, which a DNS resolver can enforce network-wide.
How to protect yourself
- Change your router's DNS settings to a privacy-friendly resolver like AEU DNS to filter ads and trackers for all devices.
- Use encrypted DNS (DoH or DoT) to prevent eavesdropping and DNS leaks.
- Enable SafeSearch through your DNS resolver to filter explicit content on all devices.
- Test for DNS leaks after configuration using online leak test tools.
- Combine DNS filtering with a browser extension for extra coverage against first-party ads.
- Regularly review your resolver's logging policy to ensure it aligns with your privacy expectations.
References
- RFC 8484: DNS Queries over HTTPS (DoH)
- RFC 7858: Specification for DNS over Transport Layer Security (TLS)
- RFC 9250: DNS over Dedicated QUIC Connections
