ESP32-C3 AdBlock: Open-Source DIY Hardware DNS Ad Blocker on a $2 SuperMini Board
A compact DIY DNS ad blocker running on a ~$2-$5 ESP32-C3 SuperMini board without needing a Raspberry Pi. Using sorted 40-bit FNV-1a hashes in flash memory, it
Developer ZedAxis (M-Abozaid) has introduced 'ESP32-C3 AdBlock', an open-source hardware DNS sinkhole project that runs entirely on a ~$2 to $5 ESP32-C3 SuperMini microcontroller board to block ads and trackers across an entire home network. Requiring neither a dedicated Raspberry Pi nor an always-on desktop home server, this miniature DIY device draws power directly from a router's rear USB port and connects seamlessly over Wi-Fi.

Image source: ZedAxis (M-Abozaid)
Traditional network-wide DNS filtering solutions, such as Pi-hole or AdGuard Home, typically rely on single-board computers (SBCs) or virtual machines with hundreds of megabytes or gigabytes of RAM to store massive domain blocklists in active memory. This project rethinks that architecture, tailoring a specialized embedded data structure to handle extensive filtering rules inside a bare microcontroller featuring just 400 KB of internal RAM and no external PSRAM.
40-Bit FNV-1a Hashes and Flash Binary Search: Overcoming 400 KB RAM Limits
The core technical breakthrough of ESP32-C3 AdBlock lies in querying blocklists directly from flash memory rather than attempting to hold entire domain lists in RAM.
The ESP32-C3 SuperMini provides only 400 KB of RAM and 4 MB of SPI flash. To accommodate more than 537,000 ad and tracker domains, the project converts domain entries into compact, fixed-size 5-byte (40-bit) FNV-1a hashes, storing them in pre-sorted order directly within the flash partition.
- Extreme Memory Efficiency: Over 140,000 domains can fit into roughly 0.7 MB of flash space, while active RAM consumption during lookup execution remains remarkably lean at approximately 50 KB to 180 KB.
- Fast Binary Search: Incoming UDP DNS requests trigger a binary search over the sorted flash index, resolving and matching blocked domains within 1 to 10 milliseconds.
- Bloom Filter Acceleration: Implementation variants incorporate a 128 KB Bloom filter in RAM as an initial pre-filter stage, reducing latency for clean, unblocked domain queries to well under 1 millisecond.
This design enables a standard low-cost microcontroller to function as a responsive, standalone DNS sinkhole without requiring costly single-board computers or external memory chips.
Router USB Power Direct and Web Dashboard Management
The hardware deployment and day-to-day management are tailored for minimal footprint and straightforward home networking:
- Zero Dedicated Power Brick: The board plugs directly into an available USB port on the back of a home router. The USB connection functions strictly as a 5V power source, while all DNS networking occurs wirelessly via the ESP32's onboard Wi-Fi chip.
- Whole-Network Coverage: Pointing the primary DNS server IP in the router's configuration to the ESP32 board instantly applies ad and tracker filtering to every connected device—including smartphones, smart TVs, tablets, and gaming consoles—without requiring browser extensions or per-device setup.
- Integrated Web Dashboard: A built-in lightweight web server lets administrators inspect real-time query statistics, monitor blocked domain logs, and configure custom whitelists and blacklists from any local browser.
- Open-Source Enclosure and Web Flasher: The repository provides 3D-printable (.stl) case designs for clean physical mounting, alongside support for one-click browser flashing via the Web Serial API in Chromium-based browsers, bypassing the need for manual toolchain compilation.
DNS-Level Filtering Scope and Encrypted DNS Considerations
When deploying a hardware DNS sinkhole, users should understand the operational boundaries inherent to DNS-based filtering.
First, because this sinkhole intercepts DNS queries and resolves blacklisted domains to a null IP (such as 0.0.0.0), it cleanly stops third-party trackers, telemetry, and banner ad networks. However, platform-integrated ads that share the exact first-party domain and media delivery streams as primary content—such as YouTube in-stream video advertisements—cannot be isolated or removed via DNS lookups alone.
Second, modern operating systems and web browsers increasingly default to encrypted DNS protocols like DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT), which bypass local standard DNS (UDP port 53). Ensuring uniform network-wide interception requires router-level firewall rules to redirect or drop outgoing public DoH/DoT connections, forcing connected devices to fall back to the local ESP32 DNS resolver.
Sources
- GitHub Repository: M-Abozaid/esp32-c3-adblock
- X Hardware Demo (@Psalteric): ESP32-C3 AdBlock Hardware Demo
- UNILAD Tech: $5 USB device is capable of blocking ads from over 500,000 websites in just 10 milliseconds