A 40-bit flash table is the reason to choose it
ESP32-C3 Adblock turns each domain into a 40-bit FNV-1a hash, stores the sorted five-byte values in flash, and uses binary search for each DNS question. A match returns 0.0.0.0, while a miss goes to an upstream resolver. That layout avoids keeping full domain strings in RAM, which is what makes the project plausible on an ESP32-C3 with no PSRAM.
The README says 141,000 domains occupy about 0.67 MB of flash and use roughly 50 KB of RAM. It also reports zero hash collisions at that list size, while a 537,000-domain list produced one collision. A collision here means an unrelated domain could be blocked. That is a small but concrete price for squeezing the list into 40 bits per entry.
A 4 MB board still takes deliberate setup
The documented target is a C3 SuperMini with 4 MB of flash, powered from a stable USB source. Setup uses current PlatformIO, because the README says older distribution packages such as version 4.3.4 fail. You copy the secrets template, generate blocklist.bin, upload the firmware, upload the LittleFS image, and then find the board at c3adblock.local or through the serial monitor.
ESP32-C3 Adblock needs two nondefault passwords before it belongs on a network: one for dashboard changes and one for OTA. WiFi credentials can instead be entered through the captive portal. Clients do not discover the blocker through DHCP, because that feature remains an unchecked item in the README. You must set the C3 as their DNS server or place it as a secondary resolver behind one you already operate.
What happened when we ran it
The lab record for commit 1947383 contains no install, build, test, package, timing, or vulnerability result. Our runner does not support this C++ firmware ecosystem, and the repository supplies no Dockerfile that would give it a supported container path. This is an untested review on our side, not a successful compile or a failed firmware test.
commit 1947383 does include GitHub workflows that compile the C3 and classic ESP32 environments on pushes and pull requests. Another workflow rebuilds the default blocklist every Monday and checks its file size before replacing the release asset. Those files show the maintainer's intended checks, but they do not substitute for our own result on a physical board or prove long-running DNS reliability.
Domain hashes leave whole classes of filter rules out
The blocklist builder accepts hosts files, plain domain lists, and basic AdGuard-style block and exception lines. It stops if a remote source cannot be downloaded unless you pass the explicit allow-missing option. Parent matching means blocking one domain also blocks its subdomains, while an exception only removes the exact entry and cannot rescue a subdomain beneath a blocked parent.
ESP32-C3 Adblock skips regex rules, wildcard rules, $ modifiers, and cosmetic ## filters because a sorted 40-bit domain table cannot represent them. DNS blocking also cannot remove page elements after a site loads them from an allowed domain. The tradeoff is easier to accept for tracker and ad hostnames than for users expecting the full behavior of a browser extension or AdGuard's rule engine.
Port 80 management assumes a trusted LAN
The dashboard protects state-changing routes with HTTP Basic Auth and an X-Requested-With header, while network OTA uses its own password. Read-only dashboard and statistics pages remain open. The extra header blocks simple cross-site requests after a browser has cached credentials, and custom domain names are HTML-escaped. Those are sensible controls for a device serving its interface on port 80.
ESP32-C3 Adblock does not encrypt that management traffic. The README states that someone able to sniff the LAN can recover the Basic Auth credentials, and the C3-AdBlock-XXXX setup access point is open while you provision WiFi. Keep administration off guest or hostile wireless segments, change both placeholder passwords before flashing, and treat the board as a trusted-LAN appliance rather than an internet-facing service.
The October 4 push is fresh, but firmware has no versioned release
GitHub showed 1,371 stars, 121 forks, and 9 open issues and pull requests on October 6, 2026. The open queue contained 4 issues and 5 pull requests, including proposed DNS reliability and security follow-up changes. The repository was pushed on October 4, and an older report about DNS requests failing after hours of runtime was closed that day. Maintenance is current, though the project is only months old.
The sole GitHub release is a blocklist tag updated on October 4 with one blocklist.bin asset. It gives installed devices a stable update URL, but it is not a numbered firmware release with immutable binaries and notes. ESP32-C3 Adblock is an appealing embedded design to build and inspect. For the DNS path of a whole home, pin a commit, keep a fallback resolver, and test failures on your own hardware before depending on it.
