37 KiB
Lists asked for and not added
What became of every address of the owner's list of 2026-10-02: used, kept switched off, already there, or not added. For each list not added: its name, its address, the filing group of the owner, the licence found and where it was read, why the list is not used and what would unlock it. The owner decides.
Checked on 2026-10-02. "Group" is the filing group of the owner (the block of his list the address sits in); "(second list)" is the last block of his list, given without a group: the group named there is a proposal.
The count
The list holds 96 lines and 87 distinct addresses (9 lines are repeats: StevenBlack hosts three times; someonewhocares, AdAway, the first-party trackers of frogeye, the two Disconnect lists, URLhaus and Prigent-Crypto twice each).
| What happened | Addresses | Where |
|---|---|---|
Added to sources.toml and used |
9 | section "Added", at the end |
Added to sources.toml but switched off, for the owner to decide |
1 | section 3 |
Already in sources.toml |
14 | section "Already in sources.toml" |
| Not added: licence forbids a commercial product | 16 | section 1 |
| Not added: licence unknown, contradictory or not readable | 13 | section 2 |
| Not added: licence allows it, waiting for the owner's decision | 34 | sections 4 to 9 |
| Total | 87 |
Several addresses are the same list twice (a mirror, or another syntax). Each one is still listed below under its own address:
big.oisd.nland the file of the oisd repository; the HaGeZiadblock/files and theirwildcard/…-onlydomains.txtfiles;crypto.txtandalt-version/crypto-nl.txtof The Block List Project;- the Firebog files
Prigent-*.txtare folders of the UT1 archive;RPiList-Malware.txtisBlocklisten/malwareof RPiList;Easylist.txtandEasyprivacy.txtare copies of EasyList and EasyPrivacy;AdguardDNS.txtandAdmiral.txtare copies of the AdGuard DNS filter and of the Admiral list of LanikSJ; HostlistsRegistry/assets/filter_7.txtis the AdGuard copy of the Smart-TV list of Perflyst;liste_fr+easylist.txtholds EasyList.
The rule applied
A list is added only when (1) its licence is one of the SPDX ids that
scripts/build.py accepts and lets the list be redistributed in a
commercial product, read at the publisher of the data and never taken from
a mirror alone, (2) its address was downloaded for real with the
User-Agent of the build, (3) its content fits a category of
taxonomy.toml, and (4) it does not take a category over its budget. A
download that fails stops the whole daily build, so an address that could
not be tested is not added.
To test an address from the CI host or any machine:
curl -sS -A "warda-lists/1.0" -o /tmp/list.txt -w '%{http_code}\n' "<address>"
A note on the lists made from other lists. oisd big (added) and the HaGeZi
lists (the base of Warda) are compiled from many public lists and published
by their authors under the GPL-3.0; the licence recorded here is the one
their publisher gives. The page https://oisd.nl/includedlists/big names,
among about 150 sources, three lists refused below when taken directly:
neohosts (non-commercial), w3kbl (no licence stated) and the Disconnect
simple_ad list (CC BY-NC-SA, through a mirror). The StevenBlack hosts
file is refused for that very reason (section 1), because it keeps the
non-commercial lists as whole, named sections. Whether a compiled list can
be relied on under the licence of its compiler alone is a question for the
owner and his legal advice; nothing was changed for oisd big or HaGeZi.
1. Licence that forbids a commercial product
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| StevenBlack unified hosts | https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts |
Hosts list | MIT for the project. The file keeps each of its sources as a named section, under the licence of that source: mvps.org (CC BY-NC-SA 4.0), someonewhocares.org ("non-commercial with attribution"), yoyo.org (McRae GPL, see below), URLHaus (terms of abuse.ch, see below), adaway.org (CC BY 3.0). Table "Sources of hosts data" of https://github.com/StevenBlack/hosts; the # Start … lines of the file |
Four sections are under terms that forbid or restrict a commercial product, and a fifth (AdAway, CC BY 3.0) is refused by the build with GPL data. Its other sections are added or listed here under their own names (KADhosts, hostsVN: added) | Written permission of MVPS, Dan Pollock, Peter Lowe and abuse.ch, or a file built without these sections |
| Dan Pollock's hosts | https://someonewhocares.org/hosts/zero/hosts |
Hosts list | "You are free to copy and distribute this file for non-commercial uses, as long the original URL and attribution is included." https://someonewhocares.org/hosts/ | Non-commercial | Written permission of Dan Pollock ([email protected]) |
| MVPS hosts | https://winhelp2002.mvps.org/hosts.txt |
Hosts list | CC BY-NC-SA 4.0; "this file is free to use for personal use only", "License info for commercial purposes contact Winhelp2002" (header of the file) | Non-commercial; last updated 2021-03 | Written permission of the author ([email protected]) |
| yhosts | https://raw.githubusercontent.com/VeleSila/yhosts/master/hosts |
Hosts list | CC BY-NC-ND 4.0, and "not for commercial activities" in its terms of use. README of https://github.com/VeleSila/yhosts | Non-commercial and no derivatives; stopped in 2022 | Written permission of the author |
| neohosts (Firebog copy) | https://v.firebog.net/hosts/neohostsbasic.txt |
Suspicious Lists | "MIT & SATA": MIT with added terms. The README says the project may not be used for commercial purposes, and that any activity for profit counts as one. README of https://github.com/neoFelhz/neohosts | Non-commercial; project stopped; the host refuses robots, download not tested | Written permission of the authors |
| RPiList phishing (Firebog copy) | https://v.firebog.net/hosts/RPiList-Phishing.txt |
Phishing List | CC BY-NC 4.0 (origin: RPiList/specials, Blocklisten/Phishing-Angriffe). https://github.com/RPiList/specials/blob/master/LICENSE.md |
Non-commercial | Written permission of RPiList |
| RPiList malware (Firebog copy) | https://v.firebog.net/hosts/RPiList-Malware.txt |
Malicious Lists | CC BY-NC 4.0 (origin: RPiList/specials, Blocklisten/malware). Same file |
Non-commercial | same |
| RPiList malware | https://raw.githubusercontent.com/RPiList/specials/master/Blocklisten/malware |
(second list) Malicious Lists | CC BY-NC 4.0. Same file | Non-commercial (and 624,000 names) | same |
| RPiList easylist | https://raw.githubusercontent.com/RPiList/specials/master/Blocklisten/easylist |
(second list) Advertising Lists | CC BY-NC 4.0. Same file | Non-commercial | same |
| Peter Lowe's ad servers | https://pgl.yoyo.org/adservers/serverlist.php?hostformat=hosts&showintro=0&mimetype=plaintext |
Advertising Lists | McRae GPL: "strictly forbidden to redistribute or use the work in any manner that could possibly be construed as making anybody any money". https://pgl.yoyo.org/license/ | Non-commercial | Written permission of Peter Lowe ([email protected]) |
| Disconnect ads | https://s3.amazonaws.com/lists.disconnect.me/simple_ad.txt |
Advertising Lists | CC BY-NC-SA 4.0. LICENSE of https://github.com/disconnectme/disconnect-tracking-protection | Non-commercial | A commercial licence from Disconnect ([email protected]) |
| Disconnect malvertising | https://s3.amazonaws.com/lists.disconnect.me/simple_malvertising.txt |
Malicious Lists | CC BY-NC-SA 4.0. Same file | Non-commercial | same |
| Phishing Army (extended) | https://phishing.army/download/phishing_army_blocklist_extended.txt |
Malicious Lists | "This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License." https://phishing.army/ | Non-commercial (and made from OpenPhish, see the last line of this table) | Written permission of the author (Andrea Draghetti) |
| URLhaus host file (abuse.ch) | https://urlhaus.abuse.ch/downloads/hostfile/ |
Malicious Lists | Terms of abuse.ch, "Effective Date: 4th November 2025": access "for not-for-profit purposes"; use "by companies, networks, or individuals with commercial or for-profit needs may require a paid subscription, which will be managed by Spamhaus"; no derivative work "without the express consent". The header of the file points to these terms and no longer names the CC0. https://abuse.ch/terms-of-use/ | The terms no longer allow a commercial product without an agreement | A written answer of abuse.ch / Spamhaus, or their commercial subscription |
| ThreatFox host file (abuse.ch) | https://threatfox.abuse.ch/downloads/hostfile/ |
(second list) Malicious Lists | Same terms. https://abuse.ch/terms-of-use/ | same | same |
| phishing-filter (malware-filter) | https://malware-filter.gitlab.io/malware-filter/phishing-filter-hosts.txt |
Malicious Lists | CC BY-SA 4.0 for the file, but it is made from the OpenPhish feed, whose terms say "You agree not to use any part of the Services for any commercial purposes" and forbid redistribution, from PhishTank and from IPThreat. README of https://github.com/curbengh/phishing-filter; https://openphish.com/terms.html | A copy of a feed that forbids commercial use | Written permission of OpenPhish, or a version of the list without OpenPhish |
2. Licence unknown, contradictory or not readable
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| hostsfile.org hosts (BadHosts) | https://hostsfile.org/Downloads/hosts.txt |
Hosts list | Unclear. Header of the file (dated 2018-04-20): "It is licensed under the LGPL as GPLv2", with a link to the LGPL. The site: "Our blocking hosts files ARE covered by the Gnu License." (https://www.hostsfile.org/hosts.html). FadeMind, who mirrors parts of it, writes "GPLv3+" | The version of the GPL is not stated clearly: GPL-2.0-only data cannot be mixed with the GPL-3.0 data of base.txt (the build refuses it), and LGPL is not an accepted id. File of 2018; its header says it was built with contributions of Airelle, whose own lists are CC BY-NC 3.0 according to FadeMind. The header was read at https://www.hostsfile.org/Downloads/hosts.txt |
A written answer of hostsfile.org on the licence ("GPL version 2 or later", or version 3) |
| add.2o7Net (FadeMind mirror of hostsfile.org) | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.2o7Net/hosts |
Hosts list | Three statements that do not agree: "GPLv3+" (README of https://github.com/FadeMind/hosts.extras, which has no LICENSE file), "LGPL as GPLv2" (the origin, line above), MIT (table of StevenBlack/hosts) | First added as fademind-2o7net on the word of the mirror, then taken out in review: the licence is not established at the origin. Frozen since 2023-11-30; 35 of its 2,030 names are new for base.txt |
The answer of hostsfile.org (line above). Then: format = "hosts", categories = ["tracking"], the licence it states |
| add.Risk (same mirror) | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Risk/hosts |
Malicious Lists | Same three statements | Same licence question. And a mix of adult sites, adware, advertising redirectors and old malware hosts (livejasmin.com, jsonip.com, online.sh.cn, enigmasoftware.com): no single category fits, and security is on for everybody. Frozen since 2022-09 |
The answer of hostsfile.org, and the owner choosing a category for it knowingly |
| add.Spam (same mirror) | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Spam/hosts |
Hosts list | Same three statements | Same licence question. 57 old names "seen in spam" (freeforums.org, otherinbox.com, addshoppers.com): not threats. Frozen since 2021-12 | same |
| frogeye first-party trackers | https://hostfiles.frogeye.fr/firstparty-trackers-hosts.txt |
Hosts list | A LICENSE file exists in https://git.frogeye.fr/geoffrey/eulaurarien; it could not be read (the forge refuses robots) | Licence not confirmed; download not tested | Open LICENSE in the repository: if MIT, GPL or alike, add it (format = "hosts", categories = ["tracking"]) |
| frogeye multi-party trackers | https://hostfiles.frogeye.fr/multiparty-trackers-hosts.txt |
Tracking & Telemetry List | same | same | same |
| Kees1958 top ads and trackers | https://raw.githubusercontent.com/Kees1958/W3C_annual_most_used_survey_blocklist/6b8c2411f22dda68b0b41757aeda10e50717a802/TOP_EU_US_Ads_Trackers_HOST |
Tracking & Telemetry List | No licence in the repository (no LICENSE file, nothing in the README). https://github.com/Kees1958/W3C_annual_most_used_survey_blocklist/ | Address pinned to a commit of 2021-05 ("HOST FILE VERSION WILL BE DISCONTINUED" in its header); the file no longer exists on the main branch | Nothing: the list is gone. Its successor has no licence either |
| WaLLy3K personal blocklist (Firebog) | https://v.firebog.net/hosts/static/w3kbl.txt |
Suspicious Lists | None stated (personal list of WaLLy3K; the MIT licence of his repository covers the site, the list is not in it). README of https://github.com/WaLLy3K/wally3k.github.io | Licence not stated; static file; the host refuses robots, not tested | Written permission of WaLLy3K |
| Joe Wein domain blacklist | https://www.joewein.net/dl/bl/dom-bl-base.txt |
Suspicious Lists | Not found. http://www.joewein.net/spam/bl-text.htm could not be read (https is redirected to http) | Terms unknown; no working https address | The terms of use read on the site, and written permission if they are silent |
| Kowabit (Firebog copy) | https://v.firebog.net/hosts/Kowabit.txt |
Suspicious Lists | Not found (origin: list.kwbt.de) | Licence unknown; the host refuses robots, not tested | Written permission of the author |
| mahakala | https://adblock.mahakala.is |
Suspicious Lists | Not found (site not reachable from here) | Licence unknown; not tested | Written permission of the author |
| Mandiant APT1 appendix D | https://bitbucket.org/ethanr/dns-blacklists/raw/8575c9f96e5b4a1308f2f12394abd86d0927a4a0/bad_lists/Mandiant_APT1_Report_Appendix_D.txt |
Malicious Lists | Not found (the data is an appendix of the Mandiant APT1 report of 2013; Bitbucket not reachable from here) | Address pinned to an old commit; data of 2013, never updated; licence unknown | Nothing useful: the indicators are 13 years old |
| tg12 PhishTank domains | https://raw.githubusercontent.com/tg12/pihole-phishtank-list/master/list/phish_domains.txt |
Malicious Lists | No licence in the repository; the data is PhishTank's (CC BY-SA 2.5 in the old terms, now under the Cisco terms). https://github.com/tg12/pihole-phishtank-list; https://phishtank.org/terms.php | Licence of the list unknown, and CC BY-SA 2.5 is not an accepted id | A LICENSE in the repository, or PhishTank's own feed under terms that fit |
Licence allows it — waiting for the owner's decision
The licence of every list of sections 3 to 9 allows a commercial product. What keeps each one out is a choice only the owner can make, a rule of the build he would have to change, or a test still to do.
3. In sources.toml, switched off: aggressive list in the default list
| List | Address | Group | Licence found, and where | Why not used | What would unlock it |
|---|---|---|---|---|---|
HaGeZi Multi PRO++ (hagezi-pro-plus) |
https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/pro.plus.txt (in sources.toml: wildcard/pro.plus-onlydomains.txt on GitHub, downloaded, read without a skipped line) |
(second list) Advertising Lists | GPL-3.0. LICENSE of https://github.com/hagezi/dns-blocklists | Its names would go to ads and tracking, so to base.txt, the list every Warda box blocks by default. HaGeZi writes in the header of the file: "This is the more aggressive sibling of Multi PRO. It might block a few legit domains by mistake, so it's best for experienced users. Ideally have an admin ready to unblock things that break." It holds almost all of hagezi-pro and about 16,700 names base.txt does not hold without it. First added switched on; switched off in review, as the other lists that may break something for every box (section 6) |
The owner accepting it for every box: remove enabled = false from its block and its name from the disabled set of scripts/test_build.py (test test_sources_and_owner_files). Or a category of its own, off by default, which Warda must know |
4. Licence outside the list of the build, or a mix the build refuses
scripts/build.py refuses a licence outside its list, and refuses to mix
CC BY 3.0 or CC BY-SA 3.0 data with the GPL data of ads.txt (HaGeZi).
Changing one of these rules is a decision of the owner.
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| AdAway | https://adaway.org/hosts.txt |
Hosts list | CC BY 3.0. Header of https://raw.githubusercontent.com/AdAway/adaway.github.io/master/hosts.txt | ads.txt holds GPL-3.0 data: the build refuses CC BY 3.0 with it (--check fails). 18 of its 6,540 names are new for base.txt |
AdAway moving to CC BY 4.0, or the owner accepting this mix in combine_licences after legal advice |
| Liste FR + EasyList | https://easylist-downloads.adblockplus.org/liste_fr%2Beasylist.txt |
(second list) Advertising Lists | Liste FR: CC BY-SA 3.0; EasyList: GPL-3.0 or later / CC BY-SA 3.0 or later. Header of https://raw.githubusercontent.com/easylist/listefr/master/liste_fr.txt; https://easylist.to/pages/licence.html | Same refusal (CC BY-SA 3.0 with GPL), and the fault of the parser told in section 5 (measured: youtube.com and yahoo.com would be listed from Liste FR alone) |
The owner accepting the path CC BY-SA 3.0, then 4.0, then GPL-3.0 in combine_licences; and the parser fixed |
| SNAFU (RooneyMcNibNug) | https://raw.githubusercontent.com/RooneyMcNibNug/pihole-stuff/master/SNAFU.txt |
Suspicious Lists | WTFPL (header of the file) | WTFPL allows everything but is not in the accepted list; 75,000 names of one person (18,000 new for base.txt), false positives not known |
The owner adding WTFPL to licences of taxonomy.toml (where the accepted licences are listed) with its text in licenses/ |
| Dandelion Sprout's Anti-Malware hosts | https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt |
Malicious Lists | "Dandelicence" 1.4: use "with or without commercial purpose" allowed, with its own conditions (the list must stay reachable in 100 countries; no sale of the unchanged list as a limited paid product; requests of credit or removal from the projects it borrows from must be followed). https://github.com/DandelionSprout/adfilt/blob/master/LICENSE.md | Not an SPDX licence, not in the accepted list. It would add 9,200 names to security.txt |
The owner reading the Dandelicence and adding it to the accepted list, or written permission of the author |
5. The parser reads the list wrongly
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| EasyList | https://easylist.to/easylist/easylist.txt |
Advertising Lists | GPL-3.0 or later / CC BY-SA 3.0 or later: a commercial product is allowed. https://easylist.to/pages/licence.html | Only the parser keeps it out. It reads a cosmetic rule such as google.com##.ad as the domain google.com. Measured with the real file: ads.txt would list google.com, youtube.com, amazon.com, bing.com, yahoo.com, instagram.com, linkedin.com, reddit.com, twitch.tv, ebay.com, booking.com, discord.com (protect.txt saves google.com and bing.com among these twelve, not the others). The DNS part of EasyList is already used through adguard-dns |
The parser (Warda and scripts/build.py) ignoring the lines that hold ##, #@# or #?#; then https://raw.githubusercontent.com/easylist/easylist/gh-pages/easylist.txt, format = "adblock", licence = "GPL-3.0-or-later", categories = ["ads"] |
| EasyList (Firebog copy) | https://v.firebog.net/hosts/Easylist.txt |
Advertising Lists | That of EasyList | The host refuses robots: the file could not be downloaded, so its syntax was not checked. Firebog publishes its files for Pi-hole; if this one is a plain list of domains, the fault above does not apply to it | A download from the CI host and a look at its lines. Prefer the origin once the parser is fixed |
| EasyPrivacy | https://easylist.to/easylist/easyprivacy.txt |
Tracking & Telemetry List | Same as EasyList | Only the parser keeps it out: same fault (x.com would be listed). Its DNS part is already used through adguard-dns |
Same; then .../gh-pages/easyprivacy.txt, categories = ["tracking"] |
| EasyPrivacy (Firebog copy) | https://v.firebog.net/hosts/Easyprivacy.txt |
Tracking & Telemetry List | That of EasyPrivacy | Same as the Firebog copy of EasyList: not downloaded, syntax not checked | same |
| HaGeZi most abused TLDs | https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/spam-tlds-adblock.txt |
(second list) Suspicious Lists | GPL-3.0. LICENSE of https://github.com/hagezi/dns-blocklists | It blocks whole top-level domains (||bid^); Warda and the build refuse a bare TLD on purpose: 120 of its 130 lines are dropped |
Blocking by TLD as a feature of Warda |
6. No category fits, or it may break something for every box
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| StevenBlack fakenews extension | https://raw.githubusercontent.com/StevenBlack/hosts/master/extensions/fakenews/hosts |
Other Lists | MIT (origin: marktron/fakenews). extensions/fakenews/update.json of StevenBlack/hosts; LICENSE of https://github.com/marktron/fakenews |
A list of opinion (sites judged to be fake news), marked paused in StevenBlack/hosts ("pause": true): no category of taxonomy.toml fits, and it must never go to security |
A category made for it by the owner (off by default), if he wants one |
| HaGeZi badware hoster | https://gitlab.com/hagezi/mirror/-/raw/main/dns-blocklists/adblock/hoster.txt |
(second list) Malicious Lists | GPL-3.0. LICENSE of https://github.com/hagezi/dns-blocklists | It blocks whole hosting providers: blogspot.com, weebly.com, glitch.me, godaddysites.com, myportfolio.com. HaGeZi itself warns in the header: "legit sites hosted there will get blocked too". No category fits | A category of its own, off by default (file wildcard/hoster-onlydomains.txt on GitHub, tested) |
| Matomo referrer spam list | https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt |
Suspicious Lists | CC0-1.0 (composer.json; "Public Domain" in the README). https://github.com/matomo-org/referrer-spam-list |
Made to clean web statistics, not to block: it holds hosting and service platforms used by spammers (ucoz.ru, resellerclub.com, nethouse.ru, adf.ly). In security it would cut them for everybody |
A category of its own, off by default |
| ad-wars | https://raw.githubusercontent.com/jdlingyu/ad-wars/master/hosts |
Hosts list | MIT (stated in the README only, no LICENSE file). README of https://github.com/jdlingyu/ad-wars | The file holds names its author marks as probable false positives (WeChat, Tencent Video, iQiyi), which cannot be left out; 86 of its 1,645 names are new for base.txt |
The owner accepting them (format = "hosts", categories = ["ads"], tested) |
| WindowsSpyBlocker spy | https://raw.githubusercontent.com/crazy-max/WindowsSpyBlocker/master/data/hosts/spy.txt |
Tracking & Telemetry List | MIT. LICENSE of https://github.com/crazy-max/WindowsSpyBlocker | Frozen since 2022-05. Written for blockers that match the exact name; Warda also blocks the subdomains, and the 130 names not yet in base.txt hold presence.teams.live.com (Teams), Teredo and IPv6 names of Microsoft, and nodes of a content network. Risk of breaking Windows for every box |
The owner accepting the risk (tested: format = "hosts", categories = ["tracking"]) |
7. Nothing to gain: the names are already in the lists
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| Perflyst Smart-TV | https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/SmartTV.txt |
Tracking & Telemetry List | MIT. LICENSE of https://github.com/Perflyst/PiHoleBlocklist | All but 3 of its 498 names are already in base.txt (The Block List Project tracking list holds them). It lists samsungcloudsolution.com and .net as exact names and leaves their update and clock subdomains out on purpose; Warda blocks the subdomains too |
Nothing to gain today |
| Perflyst Smart-TV (AdGuard copy) | https://adguardteam.github.io/HostlistsRegistry/assets/filter_7.txt |
(second list) Tracking & Telemetry List | MIT (the same list: "Perflyst and Dandelion Sprout's Smart-TV Blocklist" in filters.json of AdguardTeam/HostlistsRegistry) |
The same list as the line above | same |
| Perflyst Android tracking | https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/android-tracking.txt |
Tracking & Telemetry List | MIT. Same LICENSE | All but 2 of its 80 names are already in base.txt |
Nothing to gain today |
| Perflyst Amazon Fire TV | https://raw.githubusercontent.com/Perflyst/PiHoleBlocklist/master/AmazonFireTV.txt |
Tracking & Telemetry List | MIT. Same LICENSE | All but 2 of its 16 names are already in base.txt; the 2 others are the push notifications of the Amazon devices (device-messaging-na.amazon.com) |
Nothing to gain today |
| chadmayfield porn top 1M | https://raw.githubusercontent.com/chadmayfield/my-pihole-blocklists/master/lists/pi_blocklist_porn_top1m.list |
Other Lists | GPL-3.0. LICENSE of https://github.com/chadmayfield/my-pihole-blocklists | Made from the UT1 adult folder and the old Alexa ranking: all but 9 of its 11,868 names are already in adult.txt, and the 9 others are false positives (urbandictionary.com, torrid.com, nipissingu.ca, iwantmyname.com, perezhilton.com…) |
Nothing to gain |
| BarbBlock | https://paulgb.github.io/BarbBlock/blacklists/hosts-file.txt |
Hosts list | MIT. LICENSE of https://github.com/paulgb/BarbBlock | Frozen since 2019-05; all but 5 of its 544 names are already in base.txt |
Nothing to gain (tested at https://raw.githubusercontent.com/paulgb/BarbBlock/master/blacklists/hosts-file.txt) |
| UncheckyAds (FadeMind) | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/UncheckyAds/hosts |
Hosts list | MIT according to the README of https://github.com/FadeMind/hosts.extras and the table of StevenBlack/hosts (the repository has no LICENSE file) | 9 names, all already in base.txt |
Nothing to gain |
| The Block List Project redirect | https://blocklistproject.github.io/Lists/alt-version/redirect-nl.txt |
Redirect List | Unlicense. LICENSE of https://github.com/blocklistproject/Lists | All but 62 of its 108,685 names are already in bypass.txt (the UT1 folder redirector of ut1 holds them), and the 62 others are not proxies (the link shortener rebrand.ly among them). The group Redirect List stays empty |
Nothing to gain; a category for link shorteners if the owner wants one |
8. Too big for the budget, or frozen
security.txt holds 1.22 million names for a budget of 1.5 million
(max_domains, taxonomy.toml).
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| The Block List Project abuse | https://blocklistproject.github.io/Lists/alt-version/abuse-nl.txt |
Abuse List | Unlicense. LICENSE of https://github.com/blocklistproject/Lists | 435,119 names, 255,000 of them new for security.txt: 1.48 million, no room left for the daily growth of the other lists. Last changed 2026-07-06 |
A higher max_domains for security, chosen by the owner (the block is the one of blp-fraud with abuse-nl.txt) |
| HaGeZi TIF (full) | https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/tif.txt |
(second list) Malicious Lists | GPL-3.0. LICENSE of https://github.com/hagezi/dns-blocklists | The full Threat Intelligence Feeds: 2.37 million names, over the budget alone. The medium version is the core of security.txt (hagezi-tif-medium) |
A budget of about 3 million for security, and boxes with the memory for it |
| Jarelllama scam blocklist | https://raw.githubusercontent.com/jarelllama/Scam-Blocklist/main/lists/wildcard_domains/scams.txt |
Malicious Lists | GPL-3.0. LICENSE.md of https://github.com/jarelllama/Scam-Blocklist | Frozen since 2025-03-20 (header of the file); 468,729 names, 448,000 new: over the budget, for scam domains that live a few weeks | Nothing: HaGeZi TIF took over the live part |
| TR-PhishingList (Horus) | https://raw.githubusercontent.com/HorusTeknoloji/TR-PhishingList/master/url-lists.txt |
Malicious Lists | MIT. LICENSE of https://github.com/HorusTeknoloji/TR-PhishingList | 826,114 names (763,000 new): over the budget; its README says "List type: Aggressive. False-Positive Ratio is high" | Nothing advised |
| developerdan ads and tracking extended | https://www.github.developerdan.com/hosts/lists/ads-and-tracking-extended.txt |
Tracking & Telemetry List | Apache-2.0. LICENSE of https://github.com/lightswitch05/hosts | Repository archived on 2024-05-17; list frozen since 2023-11-17 (429,286 names, 14 MB, 130,000 new for base.txt); host not tested |
The owner accepting a frozen list (GitHub copy tested: https://raw.githubusercontent.com/lightswitch05/hosts/master/docs/lists/ads-and-tracking-extended.txt) |
| DigitalSide latest domains | https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt |
Malicious Lists | MIT text in LICENSE of https://github.com/davidonzo/Threat-Intel, but its copyright line names another company (the web template) and the list itself names no licence: to confirm with the author | The GitHub copy of the list has not changed since 2024-10-18 (133 names); the address of the site could not be tested | A test of the address showing a recent date, and the licence of the list confirmed |
| UT1 cryptojacking (Firebog copy) | https://v.firebog.net/hosts/Prigent-Crypto.txt |
Malicious Lists | CC BY-SA 4.0 (origin: UT1, folder cryptojacking). https://dsi.ut-capitole.fr/blacklists/ |
The archive of UT1 is already downloaded; this folder is left out on purpose (sources.toml, README). With the GitHub mirror of UT1 it adds 15 names |
One line in [source.map] of ut1: cryptojacking = ["security"] |
| UT1 malware (Firebog copy) | https://v.firebog.net/hosts/Prigent-Malware.txt |
Malicious Lists | CC BY-SA 4.0 (origin: UT1, folder malware). Same page |
Same; a test of the repository checks that it stays out. With the mirror it adds 261 names | malware = ["security"] in the map, and the line of scripts/test_build.py that forbids it removed |
| UT1 adult (Firebog copy) | https://v.firebog.net/hosts/Prigent-Adult.txt |
Other Lists | CC BY-SA 4.0 (origin: UT1, folder adult). Same page |
5 million loose names, left out on purpose; adult.txt already holds 950,000 names |
Nothing advised |
9. Download that could not be tested
The hosts below are not reachable from where this work was done. The
blocks are ready: test the address, then paste the block under the header
of its group in sources.toml.
| List | Address | Group | Licence found, and where | Why not added | What would unlock it |
|---|---|---|---|---|---|
| CyberHost malware | https://lists.cyberhost.uk/malware.txt |
Malicious Lists | CC BY-SA 4.0. https://cyberhost.uk/malware-blocklist/ | Not tested. The page does not name the feeds the list is made from | A successful download |
| NoTrack blocklist | https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-blocklist.txt |
Tracking & Telemetry List | GPL-3.0 ("GNU GPLv3" on the page of the project). https://gitlab.com/quidsup/notrack-blocklists | Not tested (the name of the file may have changed: the repository also shows a file malware.list); date of its last update not known |
A successful download |
| NoTrack malware | https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt |
Malicious Lists | GPL-3.0. Same page | Not tested | A successful download |
[[source]]
name = "cyberhost-malware"
group = "Malicious Lists"
url = "https://lists.cyberhost.uk/malware.txt"
format = "domains"
licence = "CC-BY-SA-4.0"
homepage = "https://cyberhost.uk/malware-blocklist/"
author = "CyberHost"
categories = ["security"]
[[source]]
name = "notrack-blocklist"
group = "Tracking & Telemetry List"
url = "https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-blocklist.txt"
format = "domains"
licence = "GPL-3.0-only"
homepage = "https://gitlab.com/quidsup/notrack-blocklists"
author = "QuidsUp"
categories = ["tracking"]
[[source]]
name = "notrack-malware"
group = "Malicious Lists"
url = "https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt"
format = "domains"
licence = "GPL-3.0-only"
homepage = "https://gitlab.com/quidsup/notrack-blocklists"
author = "QuidsUp"
categories = ["security"]
Already in sources.toml
Nothing to add for these 14 addresses.
| Address | Group | Already there as |
|---|---|---|
https://blocklistproject.github.io/Lists/alt-version/drugs-nl.txt |
Drugs List | blp-drugs |
https://blocklistproject.github.io/Lists/alt-version/fraud-nl.txt |
Fraud List | blp-fraud |
https://blocklistproject.github.io/Lists/alt-version/malware-nl.txt |
Malware List | blp-malware, disabled for the budget |
https://blocklistproject.github.io/Lists/alt-version/phishing-nl.txt |
Phishing List | blp-phishing |
https://blocklistproject.github.io/Lists/alt-version/ransomware-nl.txt |
Ransomware List | blp-ransomware |
https://blocklistproject.github.io/Lists/alt-version/scam-nl.txt |
Scam List | blp-scam |
https://blocklistproject.github.io/Lists/alt-version/tracking-nl.txt |
Tracking & Telemetry List | blp-tracking |
https://blocklistproject.github.io/Lists/alt-version/gambling-nl.txt |
Gambling List | blp-gambling |
https://blocklistproject.github.io/Lists/alt-version/porn-nl.txt |
Porn List | blp-porn |
https://blocklistproject.github.io/Lists/alt-version/ads-nl.txt |
Advertising Lists | blp-ads |
https://raw.githubusercontent.com/blocklistproject/Lists/master/crypto.txt |
(second list) Malicious Lists | blp-crypto (the same names, in the hosts syntax) |
https://raw.githubusercontent.com/AssoEchap/stalkerware-indicators/master/generated/hosts |
Malicious Lists | echap-stalkerware (filed under Malware List) |
https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/gambling.txt |
(second list) Gambling List | hagezi-gambling (the same list, "onlydomains" file) |
https://v.firebog.net/hosts/Prigent-Ads.txt |
Tracking & Telemetry List | ut1, folder publicite (category ads) |
Added
The 9 addresses added and used, each under the address of its origin on
raw.githubusercontent.com, downloaded with the User-Agent of the build.
The licence is the one read at the publisher on 2026-10-02.
| Address of the owner | Group | Source in sources.toml |
Licence, and where it was read | Notes |
|---|---|---|---|---|
https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADhosts.txt |
Hosts list | kadhosts (the repository is now FiltersHeroes/KADhosts) |
CC BY-SA 4.0: LICENSE of the repository and "License: CC BY-SA 4.0" in the header of the file | 40,212 names, to security |
https://raw.githubusercontent.com/bigdargon/hostsVN/master/hosts |
Hosts list | hostsvn |
MIT: LICENSE of the repository | 18,438 names; 628 that no other source of base.txt holds |
https://big.oisd.nl |
(second list) Hosts list | oisd-big (file domainswild2_big.txt of sjhgvr/oisd) |
GPL-3.0: LICENSE of the repository; "GNU General Public License v3.0" in the FAQ of oisd.nl | 244,717 names; 145,000 that no other source of base.txt holds: the biggest addition to the default list. See the note on the lists made from other lists |
https://v.firebog.net/hosts/AdguardDNS.txt |
Advertising Lists | adguard-dns (filter_1.txt of AdguardTeam/HostlistsRegistry) |
GPL-3.0: LICENSE of AdguardTeam/AdGuardSDNSFilter |
176,551 names; its 179 exceptions (@@) apply to itself only |
https://v.firebog.net/hosts/Admiral.txt |
Advertising Lists | lanik-admiral (getadmiral-domains.txt of LanikSJ/ubo-filters) |
MIT: LICENSE of the repository and header of the file | 1,629 names, all already held by other sources of base.txt today |
https://raw.githubusercontent.com/anudeepND/blacklist/master/adservers.txt |
Advertising Lists | anudeep-adservers |
MIT: LICENSE of the repository | 42,358 names; 4 that no other source of base.txt holds. Last changed 2025-12 |
https://raw.githubusercontent.com/Spam404/lists/master/main-blacklist.txt |
Malicious Lists | spam404 |
CC BY-SA 4.0: LICENSE.md/LICENSE.md of the repository ("License: CC BY-SA", "Copyright © 2021 Spam404") |
8,140 names, to security. Last changed 2025-09 |
https://adguardteam.github.io/HostlistsRegistry/assets/filter_50.txt |
(second list) Malicious Lists | ublock-badware (the same file on raw.githubusercontent.com) |
GPL-3.0: LICENSE of uBlockOrigin/uAssets |
2,828 names, to security |
https://raw.githubusercontent.com/anudeepND/blacklist/master/facebook.txt |
Other Lists | anudeep-facebook |
MIT: LICENSE of the repository | 3,996 names, to social only. Not changed since 2022-04 |
Added but switched off, for the owner to decide: hagezi-pro-plus (for
https://cdn.jsdelivr.net/gh/hagezi/dns-blocklists@latest/adblock/pro.plus.txt),
section 3.