
🛡️ Pi-hole + Unbound Setup Guide
Tired of ads and ISP-level tracking? Let your Raspberry Pi 5 become your home's privacy-first DNS filter and resolver.
With Pi-hole blocking ads & trackers, and Unbound encrypting DNS queries via DNS-over-TLS, you're one step closer to a safer, cleaner internet.
🛠️ What You’ll Need:
Raspberry Pi 5 (or similar)
Raspberry Pi OS (Bookworm or Bullseye recommended)
Internet connection
Terminal access (SSH or direct)
1. Install Pi-hole:
curl -sSL https://install.pi-hole.net | bash
2. Install Unbound:
sudo apt update
sudo apt install unbound
3. Configure Unbound:
sudo nano /etc/unbound/unbound.conf.d/pi-hole.conf
Paste this minimal config:
server:
verbosity: 1
interface: 127.0.0.1
port: 5335
do-tcp: yes
do-udp: yes
root-hints: "/var/lib/unbound/root.hints"
harden-glue: yes
harden-dnssec-stripped: yes
use-caps-for-id: no
edns-buffer-size: 1232
prefetch: yes
qname-minimisation: yes
rrset-roundrobin: yes
forward-zone:
name: "."
forward-tls-upstream: yes
forward-addr: 1.1.1.1@853 # Cloudflare
forward-addr: 8.8.8.8@853 # Google
4. Set Root Hints (optional):
wget -O /var/lib/unbound/root.hints https://www.internic.net/domain/named.root
5. Link Pi-hole to Unbound:
Go to Pi-hole Admin Panel → Settings → DNS
Check only Custom 1 (IPv4):
127.0.0.1#5335
Uncheck all other DNS servers.
6. Restart services:
sudo service unbound restart
sudo service pihole-FTL restart
✅ Testing the Setup
dig example.com @127.0.0.1 -p 5335
🎯 Result:
Ads and trackers: Blocked.
DNS queries: Encrypted.
Logs: Kept local.
Speed: Improved with cache.
