Overview
Maintained by twoone3, AdGuardHome for Root brings the full capabilities of the enterprise-grade AdGuard Home DNS sinkhole directly to rooted Android devices.
Standard mobile ad blockers typically establish a dummy local VPN tunnel via Android’s VpnService API to intercept DNS queries. This approach introduces battery consumption overhead, adds network latency, and prevents users from connecting to genuine VPNs or proxy clients simultaneously. AdGuardHome for Root eliminates this limitation by running an authentic compiled AdGuard Home daemon locally and redirecting system DNS via native Linux iptables rules.
Technical Architecture & How It Works
Standalone DNS Daemon & Firewall Redirection
AdGuardHome for Root sets up a fully self-contained networking architecture inside /data/adb/agh/:
- Native Binary Daemon: Runs the official compiled ARM Linux binary of AdGuard Home as a persistent background service managed by
service.sh. - Iptables Port Redirection: When
enable_iptables=trueis set insettings.conf, the module executes firewall rules to redirect outgoing DNS requests on port 53 (UDP and TCP) directly to AdGuard Home’s internal listener on port5591. - Loop Prevention & GID Bypass: The daemon process runs under a dedicated
net_rawgroup ID, allowing its own upstream queries (to encrypted DNS resolvers like Cloudflare or Quad9) to exit without looping back into the local redirect chain. - Fail-Safe Listener Timeout: During device startup,
service.shwaits up to 120 seconds for the DNS daemon to bind its listening socket. If the daemon fails to start, iptables rules are automatically skipped, ensuring the phone retains working internet connectivity rather than experiencing a total DNS blackout.
Installation & Setup
1. Disable Private DNS
Before installing, ensure Android’s native DNS-over-TLS client is disabled:
- Go to Settings > Network & Internet > Private DNS.
- Select Off.
2. Flash Module
- Download the latest release from the official repository.
- Flash the module in Magisk, KernelSU, or APatch.
- Reboot the device.
3. Access Web Dashboard
Once the device boots, open any mobile browser and navigate to:
http://127.0.0.1:3000
Log in using the default administrative credentials:
- Username:
root - Password:
root
Configuration & Practical Usage
Module Settings (settings.conf)
Fine-tune daemon behavior in /data/adb/agh/settings.conf:
- Disable Built-in Iptables: If you only wish to use AdGuard Home as a local server without redirecting device traffic, set
enable_iptables=false. - IPv6 DNS Blocking: Set
block_ipv6_dns=trueto force IPv6 DNS queries to resolve through IPv4 filtering rules. - Bypass Addresses: Append specific IP addresses to
ignore_dest_listorignore_src_listto bypass AdGuard Home filtering.
Filter Rules
By default, the module bundles AWAvenue-Ads-Rule, an optimized mobile ad-blocking list designed for minimal RAM footprint and low false positives. Additional community blocklists can be subscribed to directly through the WebUI at http://127.0.0.1:3000/#filters.
Troubleshooting & Common Issues
- Total Loss of Internet / DNS Resolution: Confirm that
Private DNSis completely disabled in system settings. If DNS resolution fails, inspect/data/adb/agh/bin/agh.pidto check if the daemon is alive, or review error output in the AdGuard Home query logs. - Port Conflict with Other DNS Daemons: If another module or local service is already listening on port 53 or 3000, modify
redir_portand web bind ports inside/data/adb/agh/AdGuardHome.yaml.
Frequently Asked Questions
Why must I turn off Android's 'Private DNS' setting?
Android's built-in Private DNS feature routes DNS requests over encrypted TLS (DoT) via port 853 directly to upstream providers. This completely bypasses standard port 53 UDP/TCP iptables redirection. Turning Private DNS Off allows AdGuard Home to capture and filter all device queries locally.
What are the default login credentials for the WebUI?
When accessing the management dashboard at http://127.0.0.1:3000 for the first time, both the default username and password are set to root / root.
