Why you must not forward port 53
A DNS server that answers anyone on the internet is an open resolver. Attackers send it small queries with a forged sender address – their victim’s – and it replies with much larger answers, flooding the victim. This is called DNS amplification. An open Pi‑hole will be found and used for it quickly, it will use your upload bandwidth, and your provider may contact you or block the port.
Pi‑hole’s own default, Allow only local requests, exists to prevent exactly this. Its settings describe the “permit all origins” modes as dangerous, and they are.
1. Use Pi‑hole through a VPN
With a VPN, your phone joins your home network and sends its DNS queries to Pi‑hole over the encrypted tunnel. You get ad and tracker blocking on mobile data and public Wi‑Fi, and your Pi‑hole remains invisible from the internet.
- Set up WireGuard as in the WireGuard guide. It can run on the same Raspberry Pi as Pi‑hole or on another machine.
- In each client’s configuration, set
DNS =to the Pi‑hole’s LAN address, for exampleDNS = 192.168.1.2. - For blocking everywhere, send all traffic through the tunnel with
AllowedIPs = 0.0.0.0/0, ::/0. If you only route your home range (split tunnel), make sure the Pi‑hole address is inside it.
[Interface]
Address = 10.8.0.2/32
PrivateKey = <phone private key>
DNS = 192.168.1.2
[Peer]
PublicKey = <server public key>
Endpoint = home.yourname.uk.app:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25Tailscale users: add the Pi‑hole machine to your tailnet, then in the Tailscale admin console set its Tailscale address as a global nameserver and turn on Override local DNS.
2. Keep the listening mode on “local”
In the Pi‑hole web interface, go to Settings → DNS and check Interface settings. Leave it on Allow only local requests. That mode answers queries only from subnets directly connected to the Pi‑hole machine.
- If WireGuard runs on the same machine, the VPN range (
10.8.0.0/24) is on thewg0interface, so it counts as local and works. - If WireGuard runs on another machine with the masquerade rule from our guide, VPN clients arrive with that machine’s LAN address, which is local too.
- If queries from VPN clients are refused, you are routing (not masquerading) a VPN range the Pi‑hole isn’t connected to. Choose Permit all origins only if the Pi‑hole machine is firewalled so nothing outside your LAN and VPN can reach port 53 – and never together with a port forward.
From the command line the same setting is dns.listeningMode:
sudo pihole-FTL --config dns.listeningMode # shows the current value, should be LOCAL
sudo pihole-FTL --config dns.listeningMode LOCAL # set it back if needed3. Give the web interface a trusted certificate
Pi‑hole v6 has its own web server and creates a self‑signed certificate at install time, which is why your browser warns about https://pi.hole/admin. A .app name requires a certificate browsers trust, and you can get one without exposing anything by using DNS‑01 validation.
- In the uk.app DNS settings, add an A record
pihole→ the Pi‑hole’s LAN address, for example192.168.1.2. It only needs to resolve for you at home and over the VPN. - On any Linux machine, get a certificate with acme.sh and the uk.app hook, as described in the HTTPS guide. It needs a uk.app API token with
write:records. - Install it in the format Pi‑hole expects – certificate and private key together in one PEM file – and tell Pi‑hole its name:
~/.acme.sh/acme.sh --install-cert -d pihole.yourname.uk.app --ecc \
--fullchain-file /etc/pihole/fullchain.pem --key-file /etc/pihole/key.pem \
--reloadcmd "cat /etc/pihole/fullchain.pem /etc/pihole/key.pem > /etc/pihole/tls.pem && chown pihole:pihole /etc/pihole/tls.pem && chmod 600 /etc/pihole/tls.pem && systemctl restart pihole-FTL"
sudo pihole-FTL --config webserver.domain pihole.yourname.uk.appPi‑hole reads the certificate from /etc/pihole/tls.pem by default (the webserver.tls.cert setting). After the restart, open https://pihole.yourname.uk.app/admin. If you run acme.sh on another machine, copy the combined file across after each renewal instead.
Note
If the name doesn’t resolve at home, your router may be blocking public names that point at private addresses (“DNS rebind protection”). Pi‑hole can also answer it locally: add pihole.yourname.uk.app → 192.168.1.2 under Settings → Local DNS Records.
4. Protect the admin interface
- Set a strong web interface password (
sudo pihole setpassword). - Pi‑hole v6 supports two‑factor authentication with an authenticator app for the web interface and API; enable it in the web interface settings.
- Don’t forward port 80 or 443 to the Pi‑hole either. Use the admin page over the VPN.
5. Dynamic DNS for the VPN endpoint
The only public name you need is the one your VPN clients connect to, such as home.yourname.uk.app. Keep it updated from your router, your NAS or with the cron job in the start guide – a Raspberry Pi running Pi‑hole is a fine place for it.
Check it
- Port 53 is not open: the port checker should show TCP 53 on your public IP as closed or filtered. (It can’t test UDP; if you never forwarded 53, it isn’t open.)
- Blocking works on the go: on mobile data, connect the VPN and visit a site with ads. The Pi‑hole Query Log should show queries from the VPN client or the WireGuard machine.
- The admin page has a padlock at
https://pihole.yourname.uk.app/adminover the VPN.