AdGuard Home Hosting
Block ads and trackers on your devices with a private DNS-over-HTTPS resolver and dashboard.
- One click deploy
- 1 GB RAM Memory needed
- 15 GB Disk Space Needed
- From 2 € Price
Official links
AdGuard Home’s official links and original website
AdGuard Home Website
More
Tech
- Docker image
- adguard/adguardhome:latest
- Default port
- 4443
How AdGuard Home works
A supported device sends DNS queries to the AdGuard Home resolver rather than directly to its usual provider. The server checks configured filter lists, rewrites, allow rules, block rules, and upstream settings before returning an answer. The dashboard shows query activity and allows administrators to adjust filtering behaviour for the clients they can identify.
The AvaHost template exposes encrypted DNS through DNS-over-HTTPS and DNS-over-TLS alongside the web interface. Plain DNS on port 53 is not exposed by the platform, so this deployment cannot simply replace the DNS address handed out by a typical home router. Devices must support an encrypted resolver profile or compatible client configuration.
Key AdGuard Home features
Filter lists can block known advertising, tracking, or unwanted domains at the DNS layer. Per-client rules, custom rewrites, upstream choices, and service blocking help tailor policies for different devices or use cases. Query logs and statistics show which domains were requested and how the resolver handled them.
Encrypted DNS protects requests in transit between a configured client and the hosted resolver. Access control is important because a publicly reachable resolver can be abused if it answers arbitrary clients. The catalogue credentials note instructs operators to restrict client access or keep the endpoint private to intended users.
AdGuard Home vs NextDNS
AdGuard Home is a self-hosted DNS filtering server whose lists, logs, client rules, upstreams, and resolver endpoint are administered by the operator. NextDNS is a provider-managed global DNS service that supplies hosted configuration profiles, filtering controls, analytics, and infrastructure across its network.
NextDNS may suit users who want a managed resolver reachable across locations without maintaining a server. AdGuard Home is more appropriate when the operator wants direct control of the instance and policies, but the AvaHost deployment requires encrypted-DNS-capable clients and careful access restriction.
Who uses AdGuard Home
Individuals configure phones, laptops, or browsers to use one consistent filtered resolver while travelling. Small technical teams may apply domain policies to a controlled set of supported devices, and testers can inspect DNS requests during application or website troubleshooting.
This hosted configuration is not suitable as a drop-in router DNS service because plain port 53 is absent. It also should not be exposed as an unrestricted public resolver, and DNS filtering cannot remove advertising delivered from the same domains as desired content.
Self-hosting AdGuard Home: requirements and cost
Resource use depends on query volume, enabled filter lists, client count, log retention, statistics, rewrites, and upstream response behaviour. A separate PostgreSQL or MariaDB service is Not required; AdGuard Home keeps its own persistent configuration and operational data. The small resource profile still needs monitoring if many devices generate sustained traffic.
AdGuard Home has no separate application fee in the catalogue, and AvaHost maps it to Plan 1 at €2. One-click deployment, a custom resolver hostname, automated HTTPS, automatic application updates, and scheduled backups are included. The service exposes DoH and DoT, not ordinary port-53 DNS, and operators must restrict access to avoid creating an open resolver.
F.A.Q
AdGuard Home starts at €2 on Plan 1. The package covers the resolver interface, persistent configuration, custom hostname, automated HTTPS, application updates, and scheduled backups. Query volume, filter-list size, client count, logging, statistics, rewrites, and upstream behaviour are the main reasons to review resource usage later.
The deployment is intended for DNS-over-HTTPS and DNS-over-TLS clients. DoH uses the hosted address with the appropriate query path, while compatible DoT clients use the resolver hostname. Device instructions differ by operating system. Test each client and restrict access before treating the endpoint as a shared resolver.
Not in this AvaHost configuration. Most routers distribute a plain DNS server on port 53, and that port is not exposed by the hosted application platform. The service is suitable for devices that can use encrypted DNS profiles or compatible clients, but it should not be advertised as a direct router-level DNS replacement.
A resolver that answers unknown internet clients can attract abuse and create unwanted traffic. Configure client access restrictions where supported, keep the hostname limited to intended users, use strong dashboard credentials, and review query logs for unexpected activity. DNS encryption secures transport but does not decide who should be permitted to use the service.