Blocky is a DNS proxy and ad blocker for the local network, written in Go. It sits between client devices and upstream resolvers and filters queries using external ad and malware lists, with allowlists, regular expressions and per-group rules. It also offers custom answers for specific domains, conditional forwarding, caching with prefetching, DoH, DoT, DoQ and DoH3, its own DoH endpoint and DNSSEC validation of upstream resolvers. It provides Prometheus metrics, query logging to CSV or SQL, a REST API and a CLI. Configuration is in YAML; no database is needed.
Blocky is free open-source software under the Apache-2.0 licence and, according to the project page, is maintained in the developer's spare time. You host it yourself, as a single binary, a Docker image or a community-supported Helm chart, including on a Raspberry Pi or OpenWrt router. DNS queries and logs therefore stay on your own infrastructure, while your chosen upstream resolvers determine where forwarded queries end up. According to the project, Blocky collects no telemetry. No commercial vendor stands behind it.