Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarBlue team tool

zachlagden/Pi-hole-Optimized-Blocklists

Pre-built, deduplicated Pi-hole blocklists merged from 35 curated sources — a 2.4M+ domain master list plus advertising, tracking, malware/phishing, suspicious, and NSFW categories. Hosts format, rebuilt weekly. 417 stars.

417 stars15 forkspushed Jul 27, 2026MIT

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

Pi-hole Optimized Blocklists

<div align="center">

Image: Total Domains Image: Updated Weekly Image: License

Pre-optimized, deduplicated blocklists for [Pi-hole](https://pi-hole.net/)

</div>

[!NOTE]
New — `nsfw_abp.txt`, a subdomain-blocking NSFW list. An ABP-format version of nsfw.txt that blocks adult domains and all their subdomains (e.g. cdn.example.com as well as example.com) for more complete filtering. Requires Pi-hole Core ≥ 5.16 / FTL ≥ 5.22. See Available Lists.
Looking for more features? Check out Zach's Lists — a full-featured blocklist platform with custom source selection, smart whitelisting, and multiple output formats.

---

Available Lists

| List | Description | Domains | |------|-------------|--------:| | [all_domains.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/all_domains.txt) | Everything combined (except NSFW) | 3,263,656 | | [advertising.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/advertising.txt) | Ad networks & services | 105,375 | | [tracking.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/tracking.txt) | Analytics & telemetry | 18,476 | | [malicious.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/malicious.txt) | Malware, phishing, scams | 2,649,874 | | [suspicious.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/suspicious.txt) | Potentially unwanted | 71,810 | | [comprehensive.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/comprehensive.txt) | Curated multi-category | 779,304 | | [nsfw.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/nsfw.txt) | Adult content (separate) | 437,476 | | [nsfw_abp.txt](https://media.githubusercontent.com/media/zachlagden/Pi-hole-Optimized-Blocklists/main/lists/nsfw_abp.txt) | Adult content — ABP format, blocks subdomains too | 437,476 |

Note: nsfw.txt is not included in all_domains.txt because it blocks legitimate adult sites. Add it separately if you want NSFW blocking. nsfw_abp.txt is the same domains in ABP form (||domain^) so subdomains are blocked too — use it instead of nsfw.txt for more thorough filtering (needs Pi-hole Core ≥ 5.16).

Last updated: July 26, 2026

Quick Start

  1. Go to Pi-hole admin → Settings → Adlists
  2. Add the raw URL for your chosen list(s)
  3. Run pihole -g to update
The lists may include ABP-style entries (||domain^) that block a domain and all its subdomains. These require Pi-hole Core ≥ 5.16 / FTL ≥ 5.22 (released 2023; standard on current installs). Note that pihole -q won't enumerate the individual subdomains covered by an ABP entry.

Report a Domain

Found a domain that should be blocked or a false positive? Open an issue using one of the templates:

  • [Block Domain](../../issues/new?template=block-domain.yml) — request a malicious, ad, tracking, or suspicious domain to be blocked
  • [False Positive](../../issues/new?template=false-positive.yml) — report a legitimate domain that's being incorrectly blocked
  • [Bug Report](../../issues/new?template=bug_report.yml) — report a problem with the lists or automation

The maintainer reviews each report, verifies it, and opens a PR. Once merged, the change takes effect on the next weekly update.

FAQ

<details> <summary><b>What's the difference between this and Zach's Lists?</b></summary>

This repository provides static, pre-built blocklists updated weekly. Zach's Lists offers additional features:

  • Custom source selection — pick which blocklists to include
  • Smart whitelisting — regex, wildcards, subdomain patterns
  • Multiple formats — hosts, plain, and Adblock syntax
  • Real-time build progress

Both use the same underlying sources and are maintained by the same person. </details>

<details> <summary><b>How often are these lists updated?</b></summary>

Every Sunday at midnight UTC via GitHub Actions. Community-reported domains are included once their PR is merged before the next run. </details>

<details> <summary><b>Which list should I use?</b></summary>

  • comprehensive.txt — Good balance for most users
  • all_domains.txt — Maximum blocking (may cause false positives)
  • Individual category lists — If you want granular control

</details>

<details> <summary><b>How do community-reported domains work?</b></summary>

Domains reported via issues are added to custom/<category>.txt files in the repo. These are referenced as sources in blocklists.conf via raw GitHub URLs, so the optimizer picks them up on the next weekly run just like any other upstream source. </details>

Contributing

See CONTRIBUTING.md for details on how to report domains, submit PRs, and use the automated workflows.

Sponsors

Thanks to everyone who supports this project.

One-Time

![@rnsimmons](https://github.com/rnsimmons)

Star History

<a href="https://www.star-history.com/?repos=zachlagden%2FPi-hole-Optimized-Blocklists&type=date&legend=top-left"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=zachlagden/Pi-hole-Optimized-Blocklists&type=date&theme=dark&legend=top-left&sealed_token=9Jx5LBkT4JfsbRkS1zAKlFHNeQ3iRm9sS6CrpYijixM6LUn-KDK1ImRifPQLvWqJT7QYPbB9hHHwcO8fT5G3xLbi_Z7v7hc7aKUgEBg433TXmeOEcC2OjZWc0-yZ66e3vOxVHuqnbRD-27PyiP5vcW4pGCTZocg0a2TP3CJPXJ_xOkGpfY55tLDvpxMz" /> <source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=zachlagden/Pi-hole-Optimized-Blocklists&type=date&legend=top-left&sealed_token=9Jx5LBkT4JfsbRkS1zAKlFHNeQ3iRm9sS6CrpYijixM6LUn-KDK1ImRifPQLvWqJT7QYPbB9hHHwcO8fT5G3xLbi_Z7v7hc7aKUgEBg433TXmeOEcC2OjZWc0-yZ66e3vOxVHuqnbRD-27PyiP5vcW4pGCTZocg0a2TP3CJPXJ_xOkGpfY55tLDvpxMz" /> <img alt="Star History Chart" src="https://api.star-history.com/chart?repos=zachlagden/Pi-hole-Optimized-Blocklists&type=date&legend=top-left&sealed_token=9Jx5LBkT4JfsbRkS1zAKlFHNeQ3iRm9sS6CrpYijixM6LUn-KDK1ImRifPQLvWqJT7QYPbB9hHHwcO8fT5G3xLbi_Z7v7hc7aKUgEBg433TXmeOEcC2OjZWc0-yZ66e3vOxVHuqnbRD-27PyiP5vcW4pGCTZocg0a2TP3CJPXJ_xOkGpfY55tLDvpxMz" /> </picture> </a>

License

MIT License — see LICENCE for details.