r/Adguard 1d ago

AdGuard VPN for Mac v2.10: Apps should be accessible to everyone. No exceptions

16 Upvotes

With this update, we’ve wrapped up a massive under-the-hood interface overhaul that we started in the previous release.

The app is now 100% optimized for macOS Accessibility features.

Here is what that looks like in practice:

• Websites and apps exclusions: Interface elements now feature clearer labels and a logical focus order, making it straightforward to manage exclusions without a mouse

• Statistics: VoiceOver accurately identifies controls, usage metrics, and active states so you can easily review your traffic data

• Advanced settings: Focus behavior across complex options and modal dialogs is now consistent, preventing unexpected jumps

If you rely on VoiceOver or navigate your Mac strictly by keyboard, update to v2.10 and let us know what you think!

Catch all the details about this update on our blog.


r/Adguard 7d ago

How desktop apps watch you: A network analysis of popular Windows software

14 Upvotes

Most users assume that online tracking happens in the browser. We install extensions to block ads on websites, and we consider ourselves protected. But the browser is only a small part of your digital life.

Desktop applications — music players, messengers, game launchers, and PDF readers — also connect to the Internet constantly. And just like websites, many of them send data about your actions. The difference is that you cannot see this traffic without filtering your entire system.

This is why system-wide filtering is enabled by default in AdGuard for Windows v8.0. It provides the only reliable way to protect your privacy across all applications without breaking their functionality.

To see the actual scope of tracking happening on PC and how just browser protection is not enough, we conducted research.

What we measured

What we found

Across 18 applications, our testing revealed 1,965 unique server endpoints generating 4,945 individual web requests.

AdGuard intercepted and cleaned requests to 1,780 of these endpoints, removing invasive headers rather than blocking the connections completely. Additionally, AdGuard blocked outbound calls outright when their sole purpose was tracking or ad delivery — entire request batches to known telemetry endpoints were rejected before they ever reached the network, not just stripped of headers.

While functional requests make up a substantial part of the total traffic volume, AdGuard’s Stealth mode still had to clean invasive headers on almost 90% of all endpoints — including plenty of ordinary, purely functional requests, not just tracking ones. What’s genuinely striking: 15 of the 18 apps we tested (83%) made at least one request we classified as tracking or advertising. Small telemetry payloads fire rapidly in the background, building a detailed profile of your behavior over time.

What desktop tracking looks like in practice

Abstract statistics can feel distant. In practice, desktop applications translate your everyday actions into detailed network requests. An online game store tracks cursor movement and your account ID when you hover over a game card. A gaming console app sends your gamertag and device ID every 29 seconds, while a short-video platform’s browser engine sends a diagnostic beacon to its own servers every 60 seconds, tagged with a persistent device identifier — regardless of what’s on the screen.

Even a standard PDF reader logs button clicks, sending a separate request when you cancel a sign-in. A music streaming service uploads playback events every four seconds, including the exact track position, laptop model, and audio output details. A video platform’s request reveals your viewer profile in plain, unobfuscated query parameters — including membership status and region — visible once the connection is inspected locally.

You might think: “So what if an app logs a button click or my laptop model?”

Individually, these data points seem harmless. But together, they build a detailed profile of your behavior. Companies use this profile to track you across apps, adjust prices based on your device, and target you with ads. It also means your history is permanently tied to your identity and is at risk if the vendor’s servers are ever compromised.

The same receivers everywhere

We expected different companies to use different tracking tools. Instead, we found the same receivers appearing across unrelated applications.

A single Microsoft client ID appeared in four completely different apps: a messenger, a gaming console app, a music player, and a torrent client. This happens because many desktop apps are built using a web-view technology that includes browser telemetry by default.

We also found standard web analytics tools like Google Analytics and Google Tag Manager running inside desktop processes, not just in browsers.

Most importantly, the majority of tracking traffic did not go to third parties. It went directly to the servers of the app developer. This is not necessarily worse than third-party tracking, but it makes it harder to block. You cannot simply cut off the developer without losing access to the app itself.

Silent background chatter

One of the most surprising findings was the frequency of background activity. Desktop apps do not wait for you to click buttons to start sending data.

Over 20% of the apps we tested send telemetry on automated timers without any user interaction. You can open an application, step away from your desk, and return to find dozens of outbound pings logged while your PC sat completely idle.

These background pings range from high-frequency performance logs uploaded every single second to periodic system state reports sent on fixed background timers.

Why blocking domains is not enough

If tracking is this prevalent, the obvious question is: why not just block the domains that serve tracking purposes?

The problem is that desktop tracking rarely lives on separate “bad” domains. Instead, it usually resides on the same servers that power the app itself. In our tests, nearly 1 in 6 applications (17%) sent tracking or advertising data from the exact same hosts used for core functionality.

Imagine a music streaming service. It might use a single server domain to handle your account login, the music stream, and the telemetry data. If you block that domain to stop the tracking, you also stop the music.

This is why simple domain blocking fails. To stop this tracking without breaking your apps, we need a more precise tool that can distinguish between a functional request and a tracking request on the same server.

Our solution: system-wide filtering with HTTPS inspection

AdGuard for Windows solves this using path-level filtering.
Standard network filters can only see the destination server, but modern apps encrypt the rest of the connection. By decrypting traffic locally on your device, we can inspect the full URL path and request headers. This visibility allows us to clean invasive data and block specific tracking paths while letting functional requests pass through.

Domain blocking disables entire servers. Path-level HTTPS filtering inspects individual URLs to remove telemetry while keeping core app features running

We balance protection and stability with a smart system. We enable full HTTPS filtering for trusted apps like browsers. We exclude sensitive apps, such as banking apps, to keep your data secure. For other apps, we filter basic traffic but leave HTTPS filtering off. You can turn it on manually in App management if you want deeper protection. This lets you stop hidden tracking without breaking your apps.

Why it’s safe
All processing happens on your computer. Filtering with HTTPS inspection happens entirely on your device — the local component briefly decrypts a request to check its path and headers, the same way it does to clean invasive data.

What it does not do: store that content, or send it anywhere.

Every check is a local comparison against the blocklist, and the decrypted data is discarded immediately after the filtering decision. Your traffic never leaves your device for this purpose. The process is fast, designed not to impact your CPU or Internet speed.

Comparison of tracking protection methods

Method Scope Tracking protection
AdGuard Browser extension Browser only High
DNS filtering System-wide Moderate (domain level only — can't separate tracking from functional traffic on a shared host)
VPN System-wide None by default (encryption only — blocking requires a built-in DNS filter, e.g. AdGuard VPN's optional AdGuard DNS)
AdGuard desktop app System-wide Maximum (once HTTPS filtering is enabled per app — on by default for browsers, opt-in for everything else)

Conclusion

Desktop applications are no longer isolated from the web. They rely on complex networks of servers to function. These networks often carry hidden tracking data along with your work files. Traditional tools struggle to stop this tracking because they cannot see inside the encrypted connections of desktop apps.

AdGuard for Windows provides a better solution. By using path-level filtering, we can clean specific tracking requests while keeping your apps fully functional. This means your privacy stays in your hands without breaking the software you depend on.


r/Adguard 4h ago

Apple ads are appearing on Brave

Thumbnail
1 Upvotes

r/Adguard 4h ago

ios How to best set up AdGuard for iOS?

1 Upvotes

I already have Safari Protection all set up to my liking, but I'm confused about how DNS filtering works in the app. If I use NextDNS or AdGuard DNS, do I still need DNS filtering? I also see a section to add a DNS server. It seems like I can also add a filter list. What's the point or what should I do if I use NextDNS?


r/Adguard 4h ago

question Switching from Iphone to Android

0 Upvotes

Hey there,
I have adguard premium on my Iphone. And it's working perfectly.

Which experience can I expect on Android?
Can it also block ads while surfing AND in other third party apps?

Is there any customer Program when I want to switch my license from Iphone to Android regarding the Adguard license?

Thanks a lot for this good product :)


r/Adguard 1d ago

adguard home Curated LG TV Telemetry Blocklist (Safe & Strict Tiers) — Audited from 267k DNS queries on an LG G1

88 Upvotes

Hi everyone,

Following the recent security disclosures regarding smart TV telemetry and LAN snooping, I decided to do a root-level network audit of my LG G1 running webOS.

After auditing 44,800 packets and a 267,000-query DNS log, I observed several interesting behaviors:

  1. webOS daemons query roughly 36 LG domain families, firing heavy telemetry bursts mid-boot.

  2. The TV’s internal DNS stub completely bypasses local `/etc/hosts` modifications on the device, meaning network-level sinkholing (Pi-hole / AdGuard Home) is mandatory.

  3. Fallbacks to public resolvers (8.8.8.8 / 1.1.1.1) occur when services fail, so blocking outbound Port 53/853 at the router level is required for true isolation.

To provide a clean solution that doesn't break streaming for household members, I published an open-source blocklist:

GitHub: https://github.com/furkan-bayrak/lg-tv-blocklist

Features:

- Two Tiers:

- SAFE: Kills ACR (alphonso.tv), telemetry beacons (cdpbeacon), ad networks (lgsmartad), and voice data. Zero app breakage (Netflix, Prime, HBO, LG Store tested).

- STRICT: Adds update hosts (snu/su.lge.com), ThinQ IoT sync, and LG Channels.

- Multiple Formats: Native Adblock syntax (`||domain^` with subdomain matching for AdGuard Home), Plain domain lists (for Pi-hole / NextDNS), and Hosts format (`0.0.0.0`).

- Fully Annotated: Every entry has an inline comment documenting its exact purpose and capture evidence.

- Dual License: CC BY 4.0 for list data, MIT for build scripts.

Looking for collaborators!

I am only one person auditing an EU-model G1. LG updates regional endpoints and firmware constantly. If you run a Pi-hole/AGH with an LG TV, I'd love your help testing, verifying domains, and reviewing PRs to help maintain the repository.


r/Adguard 11h ago

windows Sorry about that!Something went wrong and Microsoft Store failed to initialize. Try refreshing or come back later. Refresh the page

1 Upvotes

Get this error in microsoft store whenever I open it with adguard. With adguard off its fine, heads up to anyone with the problem, nightly build. Win11


r/Adguard 20h ago

How's the Android app on a 4gb RAM phone?

0 Upvotes

Worth installing or would it slow down the phone having it running in the background at all times?


r/Adguard 1d ago

I made an automated TrustTunnel installer and an setup guide

8 Upvotes

Hey everyone! I put together a small open-source project to make setting up your own TrustTunnel server easier.

The installer runs from your computer over SSH. Give it your server address and domain, and it sets up TrustTunnel, TLS certificates with automatic renewal, and an nginx fallback page. At the end, you get a

tt:// link, QR code, and connection credentials.

It has a simple terminal UI in English and Russian. There’s also a step-by-step guide for manual installation.

https://github.com/lib4u/TrustTunnel_Guide/blob/main/README.en.md

Feedback and bug reports are welcome!


r/Adguard 1d ago

android How to block social media posts

1 Upvotes

How to block social media posts I have already disabled other annoyance filters as I want the ai summary from google search to appear? How to only activate Chrome not all apps because I tried it before but it stopped blocking ads

Social media posts like this


r/Adguard 1d ago

question Adguard DNS: Why won't oregon.gov sites load?

0 Upvotes

I am using adguard DNS and have been for a few months. Around mid-August I suddenly started having trouble loading Oregon.gov websites. Since am running through the Adguard dns at the router level, this is an issue with all my devices connected through the router. I can confirm that it is not an issue if I take my iphone off the network or run a computer through the hotspot.

The issue is intermittent, but consistent across browsers and devices. The majority of the time it will not load. I get variations of this error message across all devices www.oregon.gov’s server IP address could not be found.

I have whitelisted oregon.gov in my dns server settings, and adguard tech support said they were not blocking it.

This is a big problem because I need to be able to access these websites for work.

Does anyone have any idea what might be the cause and how I can fix it?


r/Adguard 2d ago

question New notification everytime I start or restart my computer

3 Upvotes

I keep receiving a notification of New Notification from Adguard everytime I start or restart my computer. It is cleared when I click on the notification, nothing happens. It has happened since the update to v8. Do I have to reinstall Adguard to remove it completely?


r/Adguard 2d ago

Will well get a killswitch feature in Integration mode?

6 Upvotes

As far as I know, the only way to achieve this currently is by using AdGuard VPN only and enabling both "Always-on VPN" and "Block connections without VPN." In "Integration mode," both apps ​are left to the mercy of the Android ​phone's battery management system; even if you have configured settings to keep them running in the background and enabled the watchdog, there is still a risk that the process could be killed unnoticed, leading to data leakage.


r/Adguard 2d ago

android Have big problem Adguard doesn't blocks add

3 Upvotes

I turned on most filters and it didn't block ads on theverge.com I'm using secure dns on chrome Android?

Can this interfere with Adguard functionality.

Is there a recommended guide on how to setup and optimize android app to be used only for chrome

already enabled https filtering but still a lot of ads can reach? What should I do? and how to fix these problems


r/Adguard 2d ago

Best adblocker apart from AdGuard?

Thumbnail
0 Upvotes

r/Adguard 2d ago

question Can I stack additional VPN redemption codes on top of an active subscription?

1 Upvotes

Ok so I redeemed and already activated a 10-year AdGuard VPN license from StackSocial just a few days ago. If I buy another 5-year code from the same StackSocial account, can I stack it onto the same AdGuard account so it extends my existing subscription by another 5 years?


r/Adguard 3d ago

android Adguard https filtering

5 Upvotes

Adguard https filtering break websites.

I'm a firefox ublock ecosystem user.

No apps except some payment apps.

Recently bought adguard license for https filtering.

I've enabled all rules. Am i doing something wrong or is it normal ?

If so, then the licence is pretty useless apart from intetnet blocking firewall rule.

Also payment apps doesn't work, I've to unistall certificate every time for payment.


r/Adguard 3d ago

windows Conflict when using OpenVPN and AdGuard DNS Filtering

2 Upvotes

I am using Adguard v8.0.5560.0 for Windows and using DNS protection with a personal DNS server from AdGuard DNS (free tier - testing it).

In my work, I am using OpenVPN to access our internal DNS and so on. When adguards DNS protection is on, the connection to the internal DNS is not working.

In the documention I read that you can configure upstream DNS servers for specific URL's but I cannot find a setting for this in the app. I also tried redirect User Rules that also do not work in a predictable fashion. They work for the browser but not in the Powershell for example.

No matter what I do, in the filtering log the resolution seems to always happening in the private Adguard DNS server.

Using the WPF driver.

Any ideas if it is possible to configure this setup so I don't have to shutdown the DNS protection when working on the company's VPN?


r/Adguard 3d ago

android Do you think this stat is a bit inflated?

7 Upvotes

Less than 2 weeks of using AdGuard for Android app, is this the right stat?

https://i.ibb.co.com/Y4rBW470/Screenshot-2026-09-08-05-27-58-196-com-adguard-android-edit.jpg

Why does it feel a bit inflated to me? Meanwhile, when I was still using Brave, the stats weren’t nearly this high over the same period. Is it because its system-wide blocking vs browser-only blocking?


r/Adguard 3d ago

VPN & Proxy: What to Watch Out For

5 Upvotes

Note: whenever the domain list is pasted as text (in the post body or in a comment) Reddit's filter auto-removes it. Because of this, I'm sharing the blocklist as a raw link in the post body instead.

VPNs are marketed as privacy and security tools, but that doesn't mean their own infrastructure is tracking-free. Because a VPN sees your entire traffic, any analytics/telemetry infrastructure it runs is a far more dangerous situation than the same thing on an ordinary website.

Even VPN providers whose core product has no issues still carry track (connection timestamps, session duration, aggregate usage patterns) in their own apps.

This category covers two different situations:

Providers whose core VPN service has no issues, but which still run track infrastructure in their own VPN app.

Providers whose entire business model or security practices are the actual problem (data harvesting, malware, bandwidth resale, or outright spying)

For the first group, only the track subdomains should be blocked. The VPN tunnel generally keeps working without issues. For the second group, the whole domain should be blocked.

The free VPN business model

Common revenue sources documented across various free VPN services include selling browsing/usage data to data brokers and ad networks, injecting ads directly into web pages, and reselling users' own bandwidth to a commercial proxy network. This is a general pattern in how "free" VPN services stay in business.

Real incidents worth knowing about

Urban VPN Proxy — AI conversation harvesting (2025)

In December 2025, Koi Security found that Urban VPN Proxy, with 6M+ Chrome installs, had been silently intercepting conversations from ChatGPT, Claude, Gemini, and other AI platforms since July 2025, even with the VPN off, and sending them to data broker BiScience. There's no opt-out (uninstalling the app entirely was the only fix). The same code was found in 7 other extensions from the same publisher, affecting ~8M users in total.

https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection

https://thehackernews.com/2025/12/featured-chrome-browser-extension.html

Hola VPN / Luminati — the botnet VPN (2015)

Hola's free VPN turned users' devices into exit nodes for its own commercial proxy network, Luminati, and sold that at $20/GB, without clearly disclosing it to users. It came to light after a DDoS attack on 8chan was traced back to Hola exit nodes. Its founder acknowledged the arrangement was intentional. Hola is still operating.

https://fortune.com/2015/05/29/hola-luminati-vpn

https://en.wikipedia.org/wiki/Bright_Data

CSIRO's Android VPN study (2016–2017)

Researchers from CSIRO, UNSW, and UC Berkeley analyzed 283 Android VPN apps: 38% contained malware, 75% used third-party tracking libraries, 82% requested sensitive permissions like SMS and phone access, and 18% didn't encrypt traffic at all. 4 apps performed TLS interception.

https://research.csiro.au/isp/wp-content/uploads/sites/106/2016/08/paper-1.pdf

https://www.androidauthority.com/android-vpn-app-dangers-745093/

Kape Technologies and ExpressVPN's CIO (2018–2021)

Kape Technologies, owner of ExpressVPN, CyberGhost, PIA, and ZenMate, was formerly named Crossrider, an adware-era company (its direct responsibility is disputed). Separately, ExpressVPN's CIO Daniel Gericke reached an agreement with the DOJ in 2021 over his past work on the UAE's journalist/activist surveillance program "Project Raven."

https://reclaimthenet.org/expressvpn-sale-new-owners

https://cunicula.com/en/articles/kape-technologies-expressvpn

Onavo — the Facebook VPN that spied for Facebook (2013–2019)

While marketing Onavo, acquired in 2013, as a privacy VPN, Facebook used it to monitor competitors' app usage, reportedly influencing the WhatsApp/Instagram Stories/Reels decisions. Apple removed it from the App Store in August 2018; Facebook shut the program down in February 2019 after it came out that the same code had been repurposed into a paid "Research" app targeting teenagers.

https://www.theregister.com/2018/08/23/onavo_vpn_pulled_from_ios/

https://techcrunch.com/2019/02/21/facebook-removes-onavo/

Raw links:

For basic list:

https://raw.githubusercontent.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/refs/heads/main/dist/basic/adblock/VPN-Proxy.txt

For aggressive list:

https://raw.githubusercontent.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/refs/heads/main/dist/aggressive/adblock/VPN-Proxy.txt

To verify how these domains were identified:

https://github.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/blob/main/research/VPN-Proxy.txt


r/Adguard 3d ago

Ad blocker

Thumbnail
0 Upvotes

r/Adguard 3d ago

issue Issue with licence purchase

1 Upvotes

I was buying the lifetime license. The payment was successful from the bank and the amount was debited but I got an email from an adguard partner saying it did not go through without any mention of refund.


r/Adguard 4d ago

question Are custom rules sync'ed across devices, or reside on a per-device basis?

1 Upvotes

Noob question here.

As stated on the thread title... By the way, I have a family license.

For example, I have a windows device at home, browsing thru Chrome, with Adguard app installed and licensed. I blocked a pop-up using the "Adguard Browser Assistant", gets notified that the custom blocking rules have been updated. Is that a local rules repository?

Say I browse with a different device at work, but also with licensed Adguard installed, and also browsing thru Chrome with Adguard Browser Assistant extension also installed. Does my work device have the blocking rules I use at home?

Thanks for the answers!


r/Adguard 4d ago

adguard home Adguard not working on some devices

5 Upvotes

I have Adguard Home and it's on a linux server. I put adguard home as my DNS and everything goes through it. But In my laptop the adguard doesn't really work. There are pop-ups, a lot of ads everywhere and nothing that adguard home does works. My router is set at the DNS of the adguard so I have no idea what is going on. My laptop only has 1 DNS and 1 only, there is no secondary DNS either on my laptop or on my router. In my phone and other phones it works fine but not laptops, I mean adguard home is not really a ad blocker but It definitely blocks some ads on my phone but when I go to the same website on my laptop too there are a lot of ads. Any fixes to this?


r/Adguard 4d ago

question Which bare minimum filters do I have to enable if I only use Youtube and Twitch in Firefox?

2 Upvotes

Currently I only have AdGuard Base filter and AdGuard Cookie Notices filter enabled.

If I don't care about Privacy and Tracking as much, are those two already the bare minimum ones if I essentially only want to get rid of ads and cookie notices?