🔒 Pi-hole - Build a Private DNS Server ...

🔒 Pi-hole - Build a Private DNS Server on Raspberry Pi 5

Apr 22, 2025

image

🛡️ Pi-hole + Unbound Setup Guide

Tired of ads and ISP-level tracking? Let your Raspberry Pi 5 become your home's privacy-first DNS filter and resolver.

With Pi-hole blocking ads & trackers, and Unbound encrypting DNS queries via DNS-over-TLS, you're one step closer to a safer, cleaner internet.


🛠️ What You’ll Need:

  • Raspberry Pi 5 (or similar)

  • Raspberry Pi OS (Bookworm or Bullseye recommended)

  • Internet connection

  • Terminal access (SSH or direct)

1. Install Pi-hole:

curl -sSL https://install.pi-hole.net | bash

2. Install Unbound:

sudo apt update

sudo apt install unbound

3. Configure Unbound:

sudo nano /etc/unbound/unbound.conf.d/pi-hole.conf

Paste this minimal config:

server:

verbosity: 1

interface: 127.0.0.1

port: 5335

do-tcp: yes

do-udp: yes

root-hints: "/var/lib/unbound/root.hints"

harden-glue: yes

harden-dnssec-stripped: yes

use-caps-for-id: no

edns-buffer-size: 1232

prefetch: yes

qname-minimisation: yes

rrset-roundrobin: yes

forward-zone:

name: "."

forward-tls-upstream: yes

forward-addr: 1.1.1.1@853 # Cloudflare

forward-addr: 8.8.8.8@853 # Google

4. Set Root Hints (optional):

wget -O /var/lib/unbound/root.hints https://www.internic.net/domain/named.root

5. Link Pi-hole to Unbound:
Go to Pi-hole Admin Panel → Settings → DNS

  • Check only Custom 1 (IPv4): 127.0.0.1#5335

  • Uncheck all other DNS servers.


6. Restart services:

sudo service unbound restart

sudo service pihole-FTL restart

✅ Testing the Setup

dig example.com @127.0.0.1 -p 5335

🎯 Result:

  • Ads and trackers: Blocked.

  • DNS queries: Encrypted.

  • Logs: Kept local.

  • Speed: Improved with cache.

Enjoy this post?

Buy Mustafa Sönmez a coffee

More from Mustafa Sönmez

PrivacyTermsReport