mrkeyoor.com_
Tue 06 Oct 04:12 UTC
Self-Hostedevaluationupdated 06 Oct 2026

esp32-c3-adblock review

ESP32-C3 Adblock is a network DNS blocker that stores domain hashes in flash on a small ESP32 board, then answers blocked lookups with 0.0.0.0. It gives you Pi-hole-style filtering without a Raspberry Pi or a board with PSRAM, though you still have to flash it and point clients or an existing resolver at it.

Verdict

ESP32-C3 Adblock fits a roughly 100,000-entry default DNS list onto a 4 MB board without PSRAM, but its administration stays on plain HTTP. Use it for a small trusted network when the tiny hardware and flash-hash design are the point. Choose Pi-hole or AdGuard Home when you need encrypted DNS, deeper policy controls, or a release process you can validate without physical hardware.

We ran it

Screenshot of esp32-c3-adblock (github.com/M-Abozaid/esp32-c3-adblock)

Answers from our run

Did you run esp32-c3-adblock yourself?

No. Its code is C++, and it carries no manifest our lab installs from, and no Dockerfile, so there was nothing standard to install, build or test. This review is written from the repository's own documentation.

Who should not use esp32-c3-adblock?

Networks that require encrypted administration: the README says the dashboard uses plain HTTP on port 80, so Basic Auth credentials can be read by someone already sniffing the LAN.

What are the alternatives to esp32-c3-adblock?

Pi-hole, AdGuard Home, ESP32 AdBlocker. ESP32-C3 Adblock fits a roughly 100,000-entry default DNS list onto a 4 MB board without PSRAM, but its administration stays on plain HTTP.

Setup2/5Needs hardware, current PlatformIO, two uploads, and DNS changes
Docs4/5Candid setup, flash, filter, and security limits
Community4/51,371 stars and active issues and pull requests in October 2026
Maturity2/5Fresh project with no versioned firmware release or lab run

Who it’s for

Home-lab users who want DNS filtering on an ESP32-C3 and are comfortable flashing firmware with PlatformIO.
Embedded developers interested in fitting a large domain list into 4 MB of flash without PSRAM.
Small trusted networks where manual DNS configuration and a plain-HTTP dashboard are acceptable.
Tinkerers who prefer a tiny dedicated appliance over keeping a Linux host running.

Who it’s NOT for

Networks that require encrypted administration: the README says the dashboard uses plain HTTP on port 80, so Basic Auth credentials can be read by someone already sniffing the LAN.
People who expect every ad-block rule to work: regex, wildcards, modifiers, and cosmetic rules are skipped because the device stores domain hashes.
Buyers who want the 537,000-domain list and firmware OTA together: the 4 MB flash layout caps the dual-slot OTA configuration at roughly 250,000 domains.
Homes expecting automatic router integration: the device does not act as a DHCP server, so you must point clients at it or place it behind an existing resolver.
Anyone who wants a verified one-command software install: our sandbox could not run this C++ firmware project, and the repository has no Dockerfile.

Setup reality

We did not run commit 1947383 in our sandbox. The harness has no supported C++ ecosystem for this project, and the repository has no Dockerfile, so we have no install, build, test, package, timing, or audit result to report.

The documented path needs an ESP32-C3 board, a current PlatformIO install, a generated blocklist, and two USB uploads. You must copy secrets.example.h, replace the public dashboard and OTA passwords, then tell clients or another resolver to use the board for DNS.

After the first flash, firmware and blocklists can update over WiFi. The dashboard is plain HTTP on port 80, its setup access point is open during provisioning, and the 4 MB flash layout forces a choice between firmware OTA and the largest blocklist.

A 40-bit flash table is the reason to choose it

ESP32-C3 Adblock turns each domain into a 40-bit FNV-1a hash, stores the sorted five-byte values in flash, and uses binary search for each DNS question. A match returns 0.0.0.0, while a miss goes to an upstream resolver. That layout avoids keeping full domain strings in RAM, which is what makes the project plausible on an ESP32-C3 with no PSRAM.

The README says 141,000 domains occupy about 0.67 MB of flash and use roughly 50 KB of RAM. It also reports zero hash collisions at that list size, while a 537,000-domain list produced one collision. A collision here means an unrelated domain could be blocked. That is a small but concrete price for squeezing the list into 40 bits per entry.

A 4 MB board still takes deliberate setup

The documented target is a C3 SuperMini with 4 MB of flash, powered from a stable USB source. Setup uses current PlatformIO, because the README says older distribution packages such as version 4.3.4 fail. You copy the secrets template, generate blocklist.bin, upload the firmware, upload the LittleFS image, and then find the board at c3adblock.local or through the serial monitor.

ESP32-C3 Adblock needs two nondefault passwords before it belongs on a network: one for dashboard changes and one for OTA. WiFi credentials can instead be entered through the captive portal. Clients do not discover the blocker through DHCP, because that feature remains an unchecked item in the README. You must set the C3 as their DNS server or place it as a secondary resolver behind one you already operate.

What happened when we ran it

The lab record for commit 1947383 contains no install, build, test, package, timing, or vulnerability result. Our runner does not support this C++ firmware ecosystem, and the repository supplies no Dockerfile that would give it a supported container path. This is an untested review on our side, not a successful compile or a failed firmware test.

commit 1947383 does include GitHub workflows that compile the C3 and classic ESP32 environments on pushes and pull requests. Another workflow rebuilds the default blocklist every Monday and checks its file size before replacing the release asset. Those files show the maintainer's intended checks, but they do not substitute for our own result on a physical board or prove long-running DNS reliability.

Domain hashes leave whole classes of filter rules out

The blocklist builder accepts hosts files, plain domain lists, and basic AdGuard-style block and exception lines. It stops if a remote source cannot be downloaded unless you pass the explicit allow-missing option. Parent matching means blocking one domain also blocks its subdomains, while an exception only removes the exact entry and cannot rescue a subdomain beneath a blocked parent.

ESP32-C3 Adblock skips regex rules, wildcard rules, $ modifiers, and cosmetic ## filters because a sorted 40-bit domain table cannot represent them. DNS blocking also cannot remove page elements after a site loads them from an allowed domain. The tradeoff is easier to accept for tracker and ad hostnames than for users expecting the full behavior of a browser extension or AdGuard's rule engine.

Port 80 management assumes a trusted LAN

The dashboard protects state-changing routes with HTTP Basic Auth and an X-Requested-With header, while network OTA uses its own password. Read-only dashboard and statistics pages remain open. The extra header blocks simple cross-site requests after a browser has cached credentials, and custom domain names are HTML-escaped. Those are sensible controls for a device serving its interface on port 80.

ESP32-C3 Adblock does not encrypt that management traffic. The README states that someone able to sniff the LAN can recover the Basic Auth credentials, and the C3-AdBlock-XXXX setup access point is open while you provision WiFi. Keep administration off guest or hostile wireless segments, change both placeholder passwords before flashing, and treat the board as a trusted-LAN appliance rather than an internet-facing service.

The October 4 push is fresh, but firmware has no versioned release

GitHub showed 1,371 stars, 121 forks, and 9 open issues and pull requests on October 6, 2026. The open queue contained 4 issues and 5 pull requests, including proposed DNS reliability and security follow-up changes. The repository was pushed on October 4, and an older report about DNS requests failing after hours of runtime was closed that day. Maintenance is current, though the project is only months old.

The sole GitHub release is a blocklist tag updated on October 4 with one blocklist.bin asset. It gives installed devices a stable update URL, but it is not a numbered firmware release with immutable binaries and notes. ESP32-C3 Adblock is an appealing embedded design to build and inspect. For the DNS path of a whole home, pin a commit, keep a fallback resolver, and test failures on your own hardware before depending on it.

Alternatives

ProjectWhat it isPick it when
Pi-holeA Linux-based DNS sinkhole with a mature web interface and wider deployment options.pick this instead when you can run Linux and want an established network blocker rather than embedded firmware.
AdGuard Home gh↗A self-hosted DNS filtering server with encrypted DNS support and broad client controls.pick this instead when policy controls and standard server deployment matter more than using a tiny board.
ESP32 AdBlockerAn ESP32 DNS sinkhole that keeps its blocklist in PSRAM and includes web management.pick this instead when your ESP32 has 4 MB or 8 MB of PSRAM and you want its broader board and network options.

What people are saying

  1. [github-trending] M-Abozaid/esp32-c3-adblock

Sources

  1. ESP32-C3 Adblock repository and README
  2. Weekly blocklist release
  3. Open flash lookup optimization issue
  4. Closed long-running DNS resolution issue
  5. Security hardening pull request

More self-hosted reviews

bindery · ALVR · hysteria · skillbox · vm2api · FounderOS-DEMO · the whole board →