Network-Wide Ad & Malware Blocking

A free, self-hosted DNS filtering appliance for home users, families, and small businesses. Like Pi-hole, but as a hardened, pre-configured virtual appliance — import the OVA, point your router, and every device is protected. No account required, no cloud dependency.

  • Blocks ads, malware, phishing & trackers at the DNS level
  • Protects every device on your network — no per-device setup
  • Runs as a hardened OVA on VMware, VirtualBox, or Proxmox
  • Web dashboard for real-time monitoring and blocklist management
  • 100% free and open — no cloud dependency, no account, no data collection

DNS Filtering for Your Entire Network

Traditional ad blockers work per-device and per-browser. VeloGuardian DNS operates at the network level — configure it once as your network's DNS server, and every device is protected automatically. Smart TVs, IoT devices, phones, laptops — everything.

When a device on your network makes a DNS request, VeloGuardian checks it against continuously updated blocklists. Malicious domains, ad networks, trackers, and phishing sites are blocked before the connection is ever made. Legitimate traffic passes through untouched.

Who It's For

Home Users

Block ads, trackers, and malware on every device — laptops, phones, smart TVs, IoT — without installing anything on each one. Faster browsing, less bandwidth waste.

Parents & Families

Use category-based blocking as a parental control — block adult content, gambling, or social media across the whole network. Kids can't bypass it by switching browsers or using incognito mode.

Small Businesses

Protect your office network from phishing and malware without enterprise pricing. Deploy on existing virtualization infrastructure and manage via the web dashboard — no IT department required.


Built for Security, Designed for Simplicity

Ad & Tracker Blocking

Block intrusive ads, tracking pixels, and analytics domains across every device. Faster page loads, less bandwidth waste, and no more targeted advertising.

Malware & Phishing Protection

Prevent connections to known malicious domains before they happen. Continuously updated threat intelligence blocklists stop malware callbacks, phishing lures, and command-and-control servers.

Hardened Virtual Appliance

Purpose-built OVA with a minimal attack surface. No unnecessary services, locked-down OS, automatic security updates. Treat it as a network appliance, not a general-purpose VM.

Web Dashboard

Monitor queries in real time, manage blocklists, view per-device statistics, and configure allowlists/denylists — all from a clean browser-based interface.

Console CLI

Initial network configuration (IP, gateway, DNS upstream) through a lightweight console interface. SSH access available for advanced administration.

Completely Free, No Account

No subscriptions, no telemetry, no cloud dependency. VeloGuardian DNS runs entirely on your hardware. Your DNS data never leaves your network.

How It Compares

VeloGuardian DNS vs the most popular DNS filtering solutions for home and small business use.

Feature VeloGuardian DNS Pi-hole AdGuard Home NextDNS Cloudflare 1.1.1.1
Self-hosted Yes (OVA appliance) Yes (manual install) Yes (manual install) No (cloud) No (cloud)
Setup complexity Import OVA & boot Linux CLI install Binary + config Sign up & configure Change DNS settings
Hardened OS included Yes No (BYO OS) No (BYO OS) N/A (cloud) N/A (cloud)
Custom blocklists Yes Yes Yes Yes Limited
Category-based filtering Yes Via blocklists Yes Yes Families only
Parental controls Yes Manual config Yes Yes Basic
Web dashboard Yes Yes Yes Yes No
Data stays on your network Yes Yes Yes No No
Account required No No No Yes No
Price Free Free Free Free tier / $19.90/yr Free

Read the full comparison article →


Get Protected in 3 Steps

1

Download & Deploy

Download the OVA file and import it into your hypervisor — VMware, VirtualBox, or Proxmox. Boot the VM and follow the console wizard to set a static IP on your network.

2

Configure Your Network

Point your router's DNS setting to the VeloGuardian DNS appliance IP. Every device on your network will automatically route DNS queries through the filter. No per-device configuration needed.

3

Monitor & Customize

Open the web dashboard from any browser on your network. View blocked queries in real time, add custom allow/deny rules, enable or disable blocklist categories, and check per-device activity.

System Requirements

Hypervisor

  • VMware Workstation / ESXi 6.5+
  • VirtualBox 6.0+
  • Proxmox VE 7.0+

Minimum Resources

  • 1 vCPU
  • 1 GB RAM
  • 8 GB disk
  • 1 network adapter (bridged mode)

Works With VeloGuardian VPN

Already using VeloGuardian VPN? Install the optional VPN plugin to route your VPN tunnels through VeloGuardian DNS — combining encrypted traffic with network-wide filtering. The plugin is free and takes minutes to configure.

Learn More About VeloGuardian VPN

Learn More About DNS Filtering


Common Questions

Yes, completely. There are no paid tiers, no feature gates, and no account required. The appliance runs entirely on your hardware with no cloud dependency.

VeloGuardian DNS ships with curated blocklists for ads, trackers, malware, and phishing domains. You can add custom blocklists, create your own allow/deny rules, and toggle categories on or off from the web dashboard.

Blocklists update automatically on a daily schedule. System security updates are applied through the built-in update mechanism in the web dashboard.

No. DNS filtering adds negligible latency — typically under 1ms. Blocked queries actually resolve faster because the connection is never made. Most users report faster browsing due to eliminated ad and tracker requests.

Yes. You can configure VeloGuardian DNS as your primary DNS and set your existing DNS (e.g., Cloudflare, Google) as the upstream resolver. Queries that pass filtering are forwarded to your chosen upstream provider.

Yes. Because filtering happens at the DNS level, every device on your network is protected automatically — including devices that don't support traditional ad blockers like smart TVs, game consoles, and IoT devices.

No. VeloGuardian DNS and GoGuardian are completely unrelated products from different companies. GoGuardian is a paid, cloud-based content filtering platform designed for K-12 school Chromebook management. VeloGuardian DNS is a free, self-hosted DNS filtering appliance for home users, families, and small businesses that runs on your own hardware with no cloud dependency.

Both are self-hosted DNS filters, but VeloGuardian DNS is distributed as a hardened OVA virtual appliance — import it into VMware, VirtualBox, or Proxmox and it's ready to go. Pi-hole requires manual installation on a Linux system or Raspberry Pi, including OS setup, dependency management, and configuration. VeloGuardian DNS includes a locked-down OS, automatic security updates, and a pre-configured web dashboard out of the box.

Yes. The web dashboard gives you full control over filtering. You can enable or disable entire blocklist categories (ads, trackers, malware, adult content), add custom blocklists by URL, create per-domain allow and deny rules, and view real-time query logs to fine-tune your configuration.

No. VeloGuardian DNS is designed specifically for home users, families, and small businesses. It requires minimal resources (1 vCPU, 1 GB RAM, 8 GB disk) and is free with no enterprise licensing, no per-seat pricing, and no sales process. Just download the OVA and deploy it on any hypervisor.

Yes. VeloGuardian DNS supports category-based blocking, which allows you to block adult content, gambling, social media, or other categories across every device on your network. Because it operates at the DNS level, children cannot bypass it by switching browsers or using private/incognito mode. You can also create custom rules to block or allow specific domains.

Protect Your Network Today

Download VeloGuardian DNS and start blocking ads, malware, and trackers in minutes. Free forever, no account required.

Download OVA View Features