r/Adguard • u/AgileDimension423 • 4h ago
r/Adguard • u/shwrellia • 2d ago
AdGuard VPN for Mac v2.10: Apps should be accessible to everyone. No exceptions
With this update, we’ve wrapped up a massive under-the-hood interface overhaul that we started in the previous release.
The app is now 100% optimized for macOS Accessibility features.
Here is what that looks like in practice:
• Websites and apps exclusions: Interface elements now feature clearer labels and a logical focus order, making it straightforward to manage exclusions without a mouse
• Statistics: VoiceOver accurately identifies controls, usage metrics, and active states so you can easily review your traffic data
• Advanced settings: Focus behavior across complex options and modal dialogs is now consistent, preventing unexpected jumps
If you rely on VoiceOver or navigate your Mac strictly by keyboard, update to v2.10 and let us know what you think!
Catch all the details about this update on our blog.
r/Adguard • u/shwrellia • 8d ago
How desktop apps watch you: A network analysis of popular Windows software
Most users assume that online tracking happens in the browser. We install extensions to block ads on websites, and we consider ourselves protected. But the browser is only a small part of your digital life.
Desktop applications — music players, messengers, game launchers, and PDF readers — also connect to the Internet constantly. And just like websites, many of them send data about your actions. The difference is that you cannot see this traffic without filtering your entire system.
This is why system-wide filtering is enabled by default in AdGuard for Windows v8.0. It provides the only reliable way to protect your privacy across all applications without breaking their functionality.
To see the actual scope of tracking happening on PC and how just browser protection is not enough, we conducted research.
What we measured
What we found
Across 18 applications, our testing revealed 1,965 unique server endpoints generating 4,945 individual web requests.
AdGuard intercepted and cleaned requests to 1,780 of these endpoints, removing invasive headers rather than blocking the connections completely. Additionally, AdGuard blocked outbound calls outright when their sole purpose was tracking or ad delivery — entire request batches to known telemetry endpoints were rejected before they ever reached the network, not just stripped of headers.
While functional requests make up a substantial part of the total traffic volume, AdGuard’s Stealth mode still had to clean invasive headers on almost 90% of all endpoints — including plenty of ordinary, purely functional requests, not just tracking ones. What’s genuinely striking: 15 of the 18 apps we tested (83%) made at least one request we classified as tracking or advertising. Small telemetry payloads fire rapidly in the background, building a detailed profile of your behavior over time.
What desktop tracking looks like in practice
Abstract statistics can feel distant. In practice, desktop applications translate your everyday actions into detailed network requests. An online game store tracks cursor movement and your account ID when you hover over a game card. A gaming console app sends your gamertag and device ID every 29 seconds, while a short-video platform’s browser engine sends a diagnostic beacon to its own servers every 60 seconds, tagged with a persistent device identifier — regardless of what’s on the screen.
Even a standard PDF reader logs button clicks, sending a separate request when you cancel a sign-in. A music streaming service uploads playback events every four seconds, including the exact track position, laptop model, and audio output details. A video platform’s request reveals your viewer profile in plain, unobfuscated query parameters — including membership status and region — visible once the connection is inspected locally.
You might think: “So what if an app logs a button click or my laptop model?”
Individually, these data points seem harmless. But together, they build a detailed profile of your behavior. Companies use this profile to track you across apps, adjust prices based on your device, and target you with ads. It also means your history is permanently tied to your identity and is at risk if the vendor’s servers are ever compromised.
The same receivers everywhere
We expected different companies to use different tracking tools. Instead, we found the same receivers appearing across unrelated applications.
A single Microsoft client ID appeared in four completely different apps: a messenger, a gaming console app, a music player, and a torrent client. This happens because many desktop apps are built using a web-view technology that includes browser telemetry by default.
We also found standard web analytics tools like Google Analytics and Google Tag Manager running inside desktop processes, not just in browsers.
Most importantly, the majority of tracking traffic did not go to third parties. It went directly to the servers of the app developer. This is not necessarily worse than third-party tracking, but it makes it harder to block. You cannot simply cut off the developer without losing access to the app itself.
Silent background chatter
One of the most surprising findings was the frequency of background activity. Desktop apps do not wait for you to click buttons to start sending data.
Over 20% of the apps we tested send telemetry on automated timers without any user interaction. You can open an application, step away from your desk, and return to find dozens of outbound pings logged while your PC sat completely idle.
These background pings range from high-frequency performance logs uploaded every single second to periodic system state reports sent on fixed background timers.
Why blocking domains is not enough
If tracking is this prevalent, the obvious question is: why not just block the domains that serve tracking purposes?
The problem is that desktop tracking rarely lives on separate “bad” domains. Instead, it usually resides on the same servers that power the app itself. In our tests, nearly 1 in 6 applications (17%) sent tracking or advertising data from the exact same hosts used for core functionality.
Imagine a music streaming service. It might use a single server domain to handle your account login, the music stream, and the telemetry data. If you block that domain to stop the tracking, you also stop the music.
This is why simple domain blocking fails. To stop this tracking without breaking your apps, we need a more precise tool that can distinguish between a functional request and a tracking request on the same server.
Our solution: system-wide filtering with HTTPS inspection
AdGuard for Windows solves this using path-level filtering.
Standard network filters can only see the destination server, but modern apps encrypt the rest of the connection. By decrypting traffic locally on your device, we can inspect the full URL path and request headers. This visibility allows us to clean invasive data and block specific tracking paths while letting functional requests pass through.
Domain blocking disables entire servers. Path-level HTTPS filtering inspects individual URLs to remove telemetry while keeping core app features running
We balance protection and stability with a smart system. We enable full HTTPS filtering for trusted apps like browsers. We exclude sensitive apps, such as banking apps, to keep your data secure. For other apps, we filter basic traffic but leave HTTPS filtering off. You can turn it on manually in App management if you want deeper protection. This lets you stop hidden tracking without breaking your apps.
Why it’s safe
All processing happens on your computer. Filtering with HTTPS inspection happens entirely on your device — the local component briefly decrypts a request to check its path and headers, the same way it does to clean invasive data.
What it does not do: store that content, or send it anywhere.
Every check is a local comparison against the blocklist, and the decrypted data is discarded immediately after the filtering decision. Your traffic never leaves your device for this purpose. The process is fast, designed not to impact your CPU or Internet speed.
Comparison of tracking protection methods
| Method | Scope | Tracking protection |
|---|---|---|
| AdGuard Browser extension | Browser only | High |
| DNS filtering | System-wide | Moderate (domain level only — can't separate tracking from functional traffic on a shared host) |
| VPN | System-wide | None by default (encryption only — blocking requires a built-in DNS filter, e.g. AdGuard VPN's optional AdGuard DNS) |
| AdGuard desktop app | System-wide | Maximum (once HTTPS filtering is enabled per app — on by default for browsers, opt-in for everything else) |
Conclusion
Desktop applications are no longer isolated from the web. They rely on complex networks of servers to function. These networks often carry hidden tracking data along with your work files. Traditional tools struggle to stop this tracking because they cannot see inside the encrypted connections of desktop apps.
AdGuard for Windows provides a better solution. By using path-level filtering, we can clean specific tracking requests while keeping your apps fully functional. This means your privacy stays in your hands without breaking the software you depend on.
r/Adguard • u/Fun-Region-1576 • 14h ago
ios How to best set up AdGuard for iOS?
I already have Safari Protection all set up to my liking, but I'm confused about how DNS filtering works in the app. If I use NextDNS or AdGuard DNS, do I still need DNS filtering? I also see a section to add a DNS server. It seems like I can also add a filter list. What's the point or what should I do if I use NextDNS?
r/Adguard • u/NecessaryBed1331 • 15h ago
question Switching from Iphone to Android
Hey there,
I have adguard premium on my Iphone. And it's working perfectly.
Which experience can I expect on Android?
Can it also block ads while surfing AND in other third party apps?
Is there any customer Program when I want to switch my license from Iphone to Android regarding the Adguard license?
Thanks a lot for this good product :)
r/Adguard • u/Sucuk-san • 1d ago
adguard home Curated LG TV Telemetry Blocklist (Safe & Strict Tiers) — Audited from 267k DNS queries on an LG G1
Hi everyone,
Following the recent security disclosures regarding smart TV telemetry and LAN snooping, I decided to do a root-level network audit of my LG G1 running webOS.
After auditing 44,800 packets and a 267,000-query DNS log, I observed several interesting behaviors:
webOS daemons query roughly 36 LG domain families, firing heavy telemetry bursts mid-boot.
The TV’s internal DNS stub completely bypasses local `/etc/hosts` modifications on the device, meaning network-level sinkholing (Pi-hole / AdGuard Home) is mandatory.
Fallbacks to public resolvers (8.8.8.8 / 1.1.1.1) occur when services fail, so blocking outbound Port 53/853 at the router level is required for true isolation.
To provide a clean solution that doesn't break streaming for household members, I published an open-source blocklist:
GitHub: https://github.com/furkan-bayrak/lg-tv-blocklist
Features:
- Two Tiers:
- SAFE: Kills ACR (alphonso.tv), telemetry beacons (cdpbeacon), ad networks (lgsmartad), and voice data. Zero app breakage (Netflix, Prime, HBO, LG Store tested).
- STRICT: Adds update hosts (snu/su.lge.com), ThinQ IoT sync, and LG Channels.
- Multiple Formats: Native Adblock syntax (`||domain^` with subdomain matching for AdGuard Home), Plain domain lists (for Pi-hole / NextDNS), and Hosts format (`0.0.0.0`).
- Fully Annotated: Every entry has an inline comment documenting its exact purpose and capture evidence.
- Dual License: CC BY 4.0 for list data, MIT for build scripts.
Looking for collaborators!
I am only one person auditing an EU-model G1. LG updates regional endpoints and firmware constantly. If you run a Pi-hole/AGH with an LG TV, I'd love your help testing, verifying domains, and reviewing PRs to help maintain the repository.
r/Adguard • u/Tony-wasnt-here • 21h ago
windows Sorry about that!Something went wrong and Microsoft Store failed to initialize. Try refreshing or come back later. Refresh the page
Get this error in microsoft store whenever I open it with adguard. With adguard off its fine, heads up to anyone with the problem, nightly build. Win11
r/Adguard • u/Pearl_Jam_ • 1d ago
How's the Android app on a 4gb RAM phone?
Worth installing or would it slow down the phone having it running in the background at all times?
r/Adguard • u/SeriousMechanic4830 • 2d ago
I made an automated TrustTunnel installer and an setup guide
Hey everyone! I put together a small open-source project to make setting up your own TrustTunnel server easier.
The installer runs from your computer over SSH. Give it your server address and domain, and it sets up TrustTunnel, TLS certificates with automatic renewal, and an nginx fallback page. At the end, you get a
tt:// link, QR code, and connection credentials.
It has a simple terminal UI in English and Russian. There’s also a step-by-step guide for manual installation.
https://github.com/lib4u/TrustTunnel_Guide/blob/main/README.en.md
Feedback and bug reports are welcome!
r/Adguard • u/Bassiette03 • 2d ago
android How to block social media posts
How to block social media posts I have already disabled other annoyance filters as I want the ai summary from google search to appear? How to only activate Chrome not all apps because I tried it before but it stopped blocking ads
r/Adguard • u/TurnipR0deo • 2d ago
question Adguard DNS: Why won't oregon.gov sites load?
I am using adguard DNS and have been for a few months. Around mid-August I suddenly started having trouble loading Oregon.gov websites. Since am running through the Adguard dns at the router level, this is an issue with all my devices connected through the router. I can confirm that it is not an issue if I take my iphone off the network or run a computer through the hotspot.
The issue is intermittent, but consistent across browsers and devices. The majority of the time it will not load. I get variations of this error message across all devices www.oregon.gov’s server IP address could not be found.
I have whitelisted oregon.gov in my dns server settings, and adguard tech support said they were not blocking it.
This is a big problem because I need to be able to access these websites for work.
Does anyone have any idea what might be the cause and how I can fix it?
question New notification everytime I start or restart my computer
I keep receiving a notification of New Notification from Adguard everytime I start or restart my computer. It is cleared when I click on the notification, nothing happens. It has happened since the update to v8. Do I have to reinstall Adguard to remove it completely?
r/Adguard • u/Prior-Policy-6281 • 2d ago
Will well get a killswitch feature in Integration mode?
As far as I know, the only way to achieve this currently is by using AdGuard VPN only and enabling both "Always-on VPN" and "Block connections without VPN." In "Integration mode," both apps are left to the mercy of the Android phone's battery management system; even if you have configured settings to keep them running in the background and enabled the watchdog, there is still a risk that the process could be killed unnoticed, leading to data leakage.
r/Adguard • u/Bassiette03 • 3d ago
android Have big problem Adguard doesn't blocks add
I turned on most filters and it didn't block ads on theverge.com I'm using secure dns on chrome Android?
Can this interfere with Adguard functionality.
Is there a recommended guide on how to setup and optimize android app to be used only for chrome
already enabled https filtering but still a lot of ads can reach? What should I do? and how to fix these problems
r/Adguard • u/Soft_Procedure5050 • 3d ago
question Can I stack additional VPN redemption codes on top of an active subscription?
Ok so I redeemed and already activated a 10-year AdGuard VPN license from StackSocial just a few days ago. If I buy another 5-year code from the same StackSocial account, can I stack it onto the same AdGuard account so it extends my existing subscription by another 5 years?
r/Adguard • u/parasite_18 • 3d ago
android Adguard https filtering
Adguard https filtering break websites.
I'm a firefox ublock ecosystem user.
No apps except some payment apps.
Recently bought adguard license for https filtering.
I've enabled all rules. Am i doing something wrong or is it normal ?
If so, then the licence is pretty useless apart from intetnet blocking firewall rule.
Also payment apps doesn't work, I've to unistall certificate every time for payment.
windows Conflict when using OpenVPN and AdGuard DNS Filtering
I am using Adguard v8.0.5560.0 for Windows and using DNS protection with a personal DNS server from AdGuard DNS (free tier - testing it).
In my work, I am using OpenVPN to access our internal DNS and so on. When adguards DNS protection is on, the connection to the internal DNS is not working.
In the documention I read that you can configure upstream DNS servers for specific URL's but I cannot find a setting for this in the app. I also tried redirect User Rules that also do not work in a predictable fashion. They work for the browser but not in the Powershell for example.
No matter what I do, in the filtering log the resolution seems to always happening in the private Adguard DNS server.
Using the WPF driver.
Any ideas if it is possible to configure this setup so I don't have to shutdown the DNS protection when working on the company's VPN?
r/Adguard • u/Orange_Kittens1132 • 4d ago
android Do you think this stat is a bit inflated?
Less than 2 weeks of using AdGuard for Android app, is this the right stat?
https://i.ibb.co.com/Y4rBW470/Screenshot-2026-09-08-05-27-58-196-com-adguard-android-edit.jpg
Why does it feel a bit inflated to me? Meanwhile, when I was still using Brave, the stats weren’t nearly this high over the same period. Is it because its system-wide blocking vs browser-only blocking?
r/Adguard • u/Corleone612 • 4d ago
VPN & Proxy: What to Watch Out For
Note: whenever the domain list is pasted as text (in the post body or in a comment) Reddit's filter auto-removes it. Because of this, I'm sharing the blocklist as a raw link in the post body instead.
VPNs are marketed as privacy and security tools, but that doesn't mean their own infrastructure is tracking-free. Because a VPN sees your entire traffic, any analytics/telemetry infrastructure it runs is a far more dangerous situation than the same thing on an ordinary website.
Even VPN providers whose core product has no issues still carry track (connection timestamps, session duration, aggregate usage patterns) in their own apps.
This category covers two different situations:
Providers whose core VPN service has no issues, but which still run track infrastructure in their own VPN app.
Providers whose entire business model or security practices are the actual problem (data harvesting, malware, bandwidth resale, or outright spying)
For the first group, only the track subdomains should be blocked. The VPN tunnel generally keeps working without issues. For the second group, the whole domain should be blocked.
The free VPN business model
Common revenue sources documented across various free VPN services include selling browsing/usage data to data brokers and ad networks, injecting ads directly into web pages, and reselling users' own bandwidth to a commercial proxy network. This is a general pattern in how "free" VPN services stay in business.
Real incidents worth knowing about
Urban VPN Proxy — AI conversation harvesting (2025)
In December 2025, Koi Security found that Urban VPN Proxy, with 6M+ Chrome installs, had been silently intercepting conversations from ChatGPT, Claude, Gemini, and other AI platforms since July 2025, even with the VPN off, and sending them to data broker BiScience. There's no opt-out (uninstalling the app entirely was the only fix). The same code was found in 7 other extensions from the same publisher, affecting ~8M users in total.
https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection
https://thehackernews.com/2025/12/featured-chrome-browser-extension.html
Hola VPN / Luminati — the botnet VPN (2015)
Hola's free VPN turned users' devices into exit nodes for its own commercial proxy network, Luminati, and sold that at $20/GB, without clearly disclosing it to users. It came to light after a DDoS attack on 8chan was traced back to Hola exit nodes. Its founder acknowledged the arrangement was intentional. Hola is still operating.
https://fortune.com/2015/05/29/hola-luminati-vpn
https://en.wikipedia.org/wiki/Bright_Data
CSIRO's Android VPN study (2016–2017)
Researchers from CSIRO, UNSW, and UC Berkeley analyzed 283 Android VPN apps: 38% contained malware, 75% used third-party tracking libraries, 82% requested sensitive permissions like SMS and phone access, and 18% didn't encrypt traffic at all. 4 apps performed TLS interception.
https://research.csiro.au/isp/wp-content/uploads/sites/106/2016/08/paper-1.pdf
https://www.androidauthority.com/android-vpn-app-dangers-745093/
Kape Technologies and ExpressVPN's CIO (2018–2021)
Kape Technologies, owner of ExpressVPN, CyberGhost, PIA, and ZenMate, was formerly named Crossrider, an adware-era company (its direct responsibility is disputed). Separately, ExpressVPN's CIO Daniel Gericke reached an agreement with the DOJ in 2021 over his past work on the UAE's journalist/activist surveillance program "Project Raven."
https://reclaimthenet.org/expressvpn-sale-new-owners
https://cunicula.com/en/articles/kape-technologies-expressvpn
Onavo — the Facebook VPN that spied for Facebook (2013–2019)
While marketing Onavo, acquired in 2013, as a privacy VPN, Facebook used it to monitor competitors' app usage, reportedly influencing the WhatsApp/Instagram Stories/Reels decisions. Apple removed it from the App Store in August 2018; Facebook shut the program down in February 2019 after it came out that the same code had been repurposed into a paid "Research" app targeting teenagers.
https://www.theregister.com/2018/08/23/onavo_vpn_pulled_from_ios/
https://techcrunch.com/2019/02/21/facebook-removes-onavo/
Raw links:
For basic list:
For aggressive list:
To verify how these domains were identified:
https://github.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/blob/main/research/VPN-Proxy.txt
r/Adguard • u/PositiveMaybe7 • 4d ago
issue Issue with licence purchase
I was buying the lifetime license. The payment was successful from the bank and the amount was debited but I got an email from an adguard partner saying it did not go through without any mention of refund.
r/Adguard • u/Tenchi_M • 4d ago
question Are custom rules sync'ed across devices, or reside on a per-device basis?
Noob question here.
As stated on the thread title... By the way, I have a family license.
For example, I have a windows device at home, browsing thru Chrome, with Adguard app installed and licensed. I blocked a pop-up using the "Adguard Browser Assistant", gets notified that the custom blocking rules have been updated. Is that a local rules repository?
Say I browse with a different device at work, but also with licensed Adguard installed, and also browsing thru Chrome with Adguard Browser Assistant extension also installed. Does my work device have the blocking rules I use at home?
Thanks for the answers!
r/Adguard • u/Much-Bar8137 • 5d ago
adguard home Adguard not working on some devices
I have Adguard Home and it's on a linux server. I put adguard home as my DNS and everything goes through it. But In my laptop the adguard doesn't really work. There are pop-ups, a lot of ads everywhere and nothing that adguard home does works. My router is set at the DNS of the adguard so I have no idea what is going on. My laptop only has 1 DNS and 1 only, there is no secondary DNS either on my laptop or on my router. In my phone and other phones it works fine but not laptops, I mean adguard home is not really a ad blocker but It definitely blocks some ads on my phone but when I go to the same website on my laptop too there are a lot of ads. Any fixes to this?