Pi-hole & AdGuard Home Router DNS Setup Guide

Updated 2026-10-09 • By Devon Brooks, CISSP (Network Security & VPN Specialist)

Configure Pi-hole or AdGuard Home properly by assigning your DNS server a static DHCP reservation and entering its local IP into your router's LAN DHCP DNS Server field rather than the WAN DNS settings. Setting LAN DHCP DNS allows devices to query Pi-hole directly, preserving individual client hostnames in your logs while avoiding DNS loopbacks and enabling Port 53 firewall redirection against hardcoded Smart TV trackers.

Key Technical Takeaways
  • Use LAN DHCP DNS, Never WAN DNS: Enter your Pi-hole IP (e.g., 192.168.1.5) under LAN > DHCP Server > DNS Server so every client queries Pi-hole directly and shows per-device metrics.
  • Never Add a Secondary Public DNS: Leaving 8.8.8.8 in DHCP DNS Slot 2 causes clients to bypass Pi-hole randomly because Secondary DNS is load-balanced, not strictly failover.
  • Enable Conditional Forwarding: Forward reverse ARPA lookups (192.168.1.0/24) and your local domain (.lan or .home.arpa) back to your router IP to resolve human-readable hostnames.
  • Block Hardcoded IoT DNS: Create a LAN-to-WAN DNAT rule redirecting outbound TCP/UDP Port 53 traffic (except from the Pi-hole IP) back to 192.168.1.5:53.

Why You Must Set LAN DHCP DNS Instead of Router WAN DNS

The single most common mistake when deploying Pi-hole or AdGuard Home is entering the sinkhole's local IP address into the router's WAN / Internet DNS settings. When you configure WAN DNS to point to 192.168.1.5, every phone, laptop, and Smart TV on your network continues sending DNS queries to the router's gateway IP (192.168.1.1), and the router proxies those lookups to Pi-hole. Consequently, your Pi-hole dashboard shows 100% of queries originating from a single client—192.168.1.1—making per-device troubleshooting and group filtering impossible.

Instead, keep your router's WAN DNS set to an external upstream provider (such as Cloudflare 1.1.1.1 or Quad9 9.9.9.9) so the router itself can check firmware updates and NTP time even if your Raspberry Pi or Docker host reboots. Then, navigate to LAN > DHCP Server and enter your Pi-hole's reserved IP (192.168.1.5) into Primary DNS Server. Leave Secondary DNS blank (or enter a second local Pi-hole instance)—never put 8.8.8.8 as a secondary DHCP DNS, or clients will leak 30%–50% of ad queries around your sinkhole.

Step-by-Step DHCP Reservation & Conditional Forwarding Setup

Before advertising your DNS sinkhole via DHCP, lock its IP address permanently and configure reverse PTR hostname resolution:

  • 1. Bind a Static DHCP Lease: In your router UI under LAN > DHCP Reservation, bind the MAC address of your Pi-hole or AdGuard Home host to a fixed IP outside your dynamic pool (or at the bottom of the subnet, e.g., 192.168.1.5).
  • 2. Configure Conditional Forwarding in Pi-hole: Open Settings > DNS, scroll to the bottom, and check Use Conditional Forwarding. Enter your local CIDR network (192.168.1.0/24), your router's DHCP gateway IP (192.168.1.1), and your local domain suffix (such as lan or home.arpa).
  • 3. Configure Private Reverse DNS in AdGuard Home: Navigate to Settings > DNS Settings > Private reverse DNS servers, enter 192.168.1.1, and check both Use private reverse DNS resolvers and Enable reverse resolving of clients' IP addresses.
  • 4. Renew Client Leases: Toggle Wi-Fi off/on or run ipconfig /renew so endpoints pick up the new Option 6 DNS server immediately.

Forcing Hardcoded Smart TVs and IoT Devices Through Pi-hole (Port 53 DNAT)

Roku streamers, Google Chromecast, Android TVs, Amazon Echo speakers, and many IP cameras deliberately ignore DHCP Option 6 and send DNS queries directly to hardcoded resolvers like 8.8.8.8:53 or 8.8.4.4:53. Simply blocking outbound port 53 causes several smart TV apps to hang while waiting for a socket timeout. The clean engineering solution is a Destination NAT (DNAT) Port 53 Redirect rule on your firewall, accompanied by a Masquerade (SNAT) rule if your Pi-hole resides on the same subnet:

  • UniFi OS (v8.x+): Enable Settings > Security > Protection > DNS Shield or create a Port Forward / DNAT rule from Source Any (except 192.168.1.5) destined for Port 53 translated to 192.168.1.5:53.
  • Asuswrt-Merlin DNS Director: Go to LAN > DNS Director, set Global Redirection to User Defined 1 (192.168.1.5), and add a Client List exception for your Pi-hole MAC set to No Redirection.
  • OPNsense / pfSense / OpenWrt: Create a Firewall NAT Port Forward on the LAN interface matching Source: !192.168.1.5, Protocol: TCP/UDP, Dest Port: 53 (DNS), and redirect target IP to 192.168.1.5. Also block outbound TCP/UDP 853 (DoT) and known DoH IPs so devices cannot fall back to encrypted DNS.

Preventing IPv6 DNS Bypass (RA RDNSS & DHCPv6)

If your ISP provides Dual-Stack IPv6, Windows, macOS, iOS, and Android devices will prefer IPv6 DNS resolvers over IPv4 resolvers within milliseconds. If your router advertises your ISP's IPv6 DNS servers via Router Advertisements (RA RDNSS) or Stateless DHCPv6, 80% of your household traffic will completely bypass your IPv4 Pi-hole setup.

To prevent IPv6 DNS leaks, assign a stable Unique Local Address (ULA, fd00::/8) or Link-Local address (`fe80::...`) to your Pi-hole/AdGuard host and enter that address into your router's IPv6 LAN DNS / RDNSS field. On consumer routers that do not allow custom IPv6 LAN DNS (such as certain Netgear or TP-Link stock firmware builds), disable Advertisement of IPv6 DNS so dual-stack clients resolve both A (IPv4) and AAAA (IPv6) records exclusively over your IPv4 Pi-hole address (`192.168.1.5`), preserving full IPv6 internet connectivity without leaking DNS queries.

Router DNS Configuration Methods & Client Visibility Comparison

Configuration LocationPer-Client Logs in Pi-hole?DNS Loopback Risk?Works if Pi-hole Offline?
LAN > DHCP DNS Server (Recommended)Yes — shows exact client IP & hostnameNone (when WAN uses 1.1.1.1)Router stays online; LAN needs fallback or reboot
WAN / Internet DNS Server (Avoid)No — all queries show as 192.168.1.1High — infinite loop if Conditional Fwd is onNo — router loses WAN resolution
DHCP DNS 1 = Pi-hole, DNS 2 = 8.8.8.8Partial — misses 30–50% of queriesNoneYes, but ad blocking fails randomly
Asuswrt-Merlin DNS Director (User Defined)Yes — intercepts hardcoded Port 53 tooNone (with MAC exclusion set)Requires toggling DNS Director off if Pi dies
High-Availability (2x Pi-holes + Keepalived)Yes — 100% client visibilityNoneYes — automatic VRRP/DHCP failover

Pi-hole & AdGuard Home Router Integration Checklist

  1. Bind a permanent DHCP reservation for your Pi-hole or AdGuard Home server (e.g., 192.168.1.5) in your router's LAN settings.
  2. Set your router's WAN DNS to a reliable public upstream (1.1.1.1 or 9.9.9.9) and never point WAN DNS to your local Pi-hole IP.
  3. Enter 192.168.1.5 in LAN > DHCP Server > Primary DNS and leave Secondary DNS empty (unless running a second local Pi-hole).
  4. Enable Conditional Forwarding (Pi-hole) or Private Reverse DNS (AdGuard Home) pointing to 192.168.1.1 without enabling 'Never forward non-FQDNs' if loops occur.
  5. Configure a Port 53 DNAT redirect rule (excluding source IP 192.168.1.5) and block outbound TCP/UDP 853 to stop Smart TV DNS bypasses.
  6. Verify IPv6 RDNSS / DHCPv6 DNS settings by running nslookup flurry.com from a smartphone to confirm both IPv4 and IPv6 queries hit your sinkhole.

Frequently Asked Questions

Why am I seeing a DNS loop holding thousands of queries per minute between my router and Pi-hole?

A DNS loop happens when you simultaneously set your router's WAN DNS to point to Pi-hole AND enable Conditional Forwarding inside Pi-hole pointing back to the router. Fix this immediately by changing your router's WAN DNS to 1.1.1.1 or 9.9.9.9 while keeping Pi-hole exclusively in the LAN DHCP DNS field.

Should I chooses Pi-hole or AdGuard Home for a home office network in 2026?

Both block ads and trackers identically well using standard hosts/AdBlock filter lists. Choose AdGuard Home if you want native out-of-the-box Encrypted Upstream DNS (DoH, DoT, DoQ) and one-click per-client service blocking (YouTube, TikTok, Roblox) in a single binary; choose Pi-hole v6 if you want deep dnsmasq customization and local recursive resolution via Unbound.

Why does Safari on iPhone and macOS bypass my Pi-hole even after DHCP renewal?

If you subscribe to iCloud+, Apple's iCloud Private Relay routes Safari traffic and DNS queries through oblivious HTTP relays. Either disable Private Relay for your home Wi-Fi SSID in iOS Settings, or note that Pi-hole v6 and AdGuard Home automatically return NXDOMAIN for mask.icloud.com and mask-h2.icloud.com when configured to block Private Relay.

How do I stop my network from losing internet if my Raspberry Pi SD card fails?

Run a secondary Pi-hole or AdGuard Home container on an always-on NAS or mini PC, advertise its IP in DHCP DNS Server 2, and synchronize blocklists and local DNS records automatically using orbital-sync (Pi-hole) or adguardhome-sync.

Reviewed by Devon Brooks, CISSP (Network Security & VPN Specialist)

Part of the Packetsaver Network Engineering Team. All configurations and firmware safety instructions follow vendor-verified RFC and IEEE standards. Read our testing methodology →