What was blocked
All tested domains by type. Coloured segments are blocked, grey is what got through.
Detected lists
Determined via domains that appear on exactly one list. “Working” means blocked – whether the list is added directly or a bigger tier covers it.
HaGeZi Multi tier
Other lists
| List | Purpose | Exclusive domains | Result |
|---|
To add a list: paste the URL into your DNS blocker (Technitium: Settings → Blocking → Block List URLs; Pi-hole: Adlists; AdGuard Home: Filters → DNS blocklists – see the Blocklists page for the right format). Content filters like gambling, social or NSFW are a matter of taste – “not active” is not a flaw there.
Check your own domain
For example one you just allowed or blocked. Whether a domain is on a list, the HaGeZi Blocklist Lookup will tell you.
How the test works
Your browser tries to load a resource from every domain. If the connection fails, your DNS server blocked it. If the domain answers, it passed. Requests run without cookies, nothing is executed or displayed. All test domains are real, currently visited HTTPS sites from the Chrome UX Report or well-known tracker endpoints – dead domains were filtered out beforehand.
- Control group: eight harmless domains that must be reachable. If they fail, something is wrong with your connection and the result is void.
- Badges: which lists contain the domain. “from PRO” means: on PRO, PRO++ and ULTIMATE, but not on Light or Normal. Outlined badges mark domains that sit on exactly one list – that is how the page detects your active lists.
- Dead hosts and picky servers: every failure is retried once and timed against your control group. A DNS block fails instantly. A host that answers but refuses the request – certificate, Cross-Origin-Resource-Policy, connection reset – fails slowly both times and counts as passed, because it is reachable. A dead domain fails slowly once and fast the second time (negative DNS cache) and is left out of the score as “unreachable”.
- Limits: a domain that dies faster than your DNS answers can still be mistaken for a block. A browser ad blocker skews the result. Ads served from the same domain as the content – YouTube, for example – cannot be blocked by DNS at all.
- Content filters: gambling, social networks, piracy, NSFW and VPN are not ads but taste or parental filters. “Passed” is only a problem there if you deliberately use those lists.
- NSFW: off by default because the page would connect to adult domains. Nothing is displayed.
- Malware test site:
malware.wicar.orgis a harmless test page by the WICAR project that sits on threat lists.
Questions, answered
Which DNS blockers does this test work with?
Any. Pi-hole, AdGuard Home, Technitium DNS, Blocky, NextDNS, ControlD, AdGuard DNS, a Fritz!Box filter or a browser extension – the test only looks at what your device can and cannot reach.
Why is my score near zero although I run Pi-hole, AdGuard Home or Technitium?
Because this device is not asking your DNS server. The usual culprits: iCloud Private Relay on iPhone, iPad and Mac (Settings → your name → iCloud → Private Relay, or Wi-Fi settings → “Limit IP Address Tracking”), “Secure DNS” in Chrome or Firefox, or a VPN. Turn it off for your home network and run the test again – the control group passing while everything else passes too is the tell-tale sign.
Many domains show “no answer” on my iPhone or Mac – why?
Safari and every iOS browser remember which sites support HTTP/3. If your blocker answers with 0.0.0.0, the browser tries a QUIC handshake against nothing and waits. The test falls back to a WebSocket probe to settle those, but the clean fix is on the blocker: let it answer NXDOMAIN instead of 0.0.0.0 (Technitium: Settings → Blocking → Blocking Type; Pi-hole: BLOCKINGMODE=NXDOMAIN; AdGuard Home: Blocking mode NXDOMAIN). Then blocked domains fail instantly on every platform.
Why is my score not 100 %?
The main score counts every ad and tracker domain on all HaGeZi tiers. HaGeZi PRO plus OISD lands around 80 % because the remaining domains are only blocked by PRO++ or ULTIMATE, and those tiers can break things. 100 % is neither necessary nor always desirable.
What is the difference between HaGeZi and OISD?
Both are curated DNS blocklists. HaGeZi comes in five tiers from Light to ULTIMATE plus many standalone lists; OISD is a single balanced list that aims for zero breakage. Many people run HaGeZi PRO together with OISD Big and the TIF threat list.
Why do content filters count separately?
Gambling, social networks, piracy, VPN and NSFW are opt-in lists. Blocking them is a choice, not a security feature, so they do not lower your main score.
Does the test send my data anywhere?
No. The page has no analytics and no external scripts. Your browser contacts the test domains directly, without cookies, exactly as it would when a website embeds them.
Which list should I add if something gets through?
The Detected lists table shows every list with its result. Lists that are “not active” come with the URL you can paste into your DNS blocker. For most homes HaGeZi PRO plus TIF is the sweet spot.
Is this a replacement for the d3ward Ad Block Tester?
Yes. The popular d3ward test at d3ward.github.io was archived in 2026 and is no longer maintained. This test does the same job with more than three times as many domains, current HaGeZi and OISD data, per-domain owner information and automatic list detection.
What about ads on YouTube, Twitch or Instagram?
Those ads come from the same domains as the videos. A DNS filter cannot separate them. You need a browser extension such as uBlock Origin for that.