Back to blog
Explainers·5 min read

DNS Filtering on Cellular: Why Standard Home Network Filters Stop at Your Front Door

By Casper's Cloak Security Team

In its standard home installation, Pi-hole runs as a DNS server on your local network. Devices that use that DNS server get ad and tracker blocking — but only while they're on that home network. The moment a device switches to cellular or joins a different Wi-Fi network, it is no longer routing DNS queries through your home Pi-hole.

If you've set up Pi-hole and noticed that your iPhone still loads ads on cellular, or that your protection disappears the moment you leave home, you're seeing a known characteristic of a home-network-bound DNS filter in its standard configuration.

How Pi-hole's filtering works in a standard home installation — and where it ends

In its standard home installation, Pi-hole runs as a DNS server on your local network. Devices configured to use that DNS server send their DNS queries to Pi-hole, which can block known ad and tracker domains before a connection is made. This works reliably for devices that are on your home network and pointed at your home Pi-hole.

But in this configuration, it protects the home network, not the device wherever it goes. Your Pi-hole is at home; your phone is not.

What about advanced Pi-hole setups?

Some technically experienced users extend Pi-hole beyond the home network — for example, by exposing it via DNS-over-HTTPS, or by tunneling back to their home network over WireGuard. Pi-hole 6 introduced native DNS-over-HTTPS support, which makes this somewhat more accessible than it used to be.

These approaches can work, but they require a publicly accessible server or a self-managed VPN endpoint, dynamic DNS or a static IP address, open ports, and ongoing maintenance — and they still depend on your home internet connection being up and reachable. For the majority of Pi-hole users who haven't taken on that infrastructure, and who set up Pi-hole through the standard home installation path, the mobile experience is simply unprotected.

The gap we're describing is for that standard home installation scenario — not an absolute statement about every possible Pi-hole deployment.

The gap is bigger than it looks in practice

People use their phones away from home constantly: commuting, traveling, working from a café, connecting from an office. A filter that only works in the standard home network configuration covers only the time a device is on that home network.

This is especially relevant for iPhone users who set up Pi-hole to block ads system-wide. The system-wide blocking works at home. Away from the home network, the phone is outside that standard Pi-hole setup.

What it takes to make filtering follow you — without the infrastructure overhead

For DNS-level ad and tracker blocking to work on cellular and on Wi-Fi networks outside the home — without self-managing a public-facing server — the filtering layer has to travel with the device.

On iOS, a VPN-style Network Extension can route DNS queries through an encrypted tunnel that stays connected across network changes, so filtering can apply whether the device is on home Wi-Fi, cellular, or a public hotspot.

Casper's Cloak: DNS-level blocking that travels with you

Casper's Cloak is built around this problem. It applies DNS-level ad and tracker blocking through managed server-side Pi-hole and Unbound over DNS-over-TLS, with traffic routed through an encrypted WireGuard tunnel — so your device's DNS queries are filtered regardless of which network you're on. Casper also reconnects intelligently after network changes.

One thing to know about the architecture: Casper's DNS-level ad and tracker blocking runs server-side on Casper's managed VPN exit servers. When the WireGuard tunnel is connected, filtering applies across your apps on any network. If the tunnel drops, Casper's active kill switch stops traffic until the connection is re-established — and the reconnection logic handles network transitions automatically. This is a different trade-off from a local DNS resolver, and it's worth understanding before you choose.

Beyond ad and tracker blocking, Casper adds:

  • AI-driven threat detection that analyzes network connections in real time for phishing and malware domains
  • An active kill switch that stops traffic if anything goes wrong
  • Profile Auto-Switching so you can configure different rules for home, cellular, hotel Wi-Fi, and other network contexts
  • Network Blocking Detection that spots captive portals and DPI in real time

For users who want to keep their home Pi-hole

If you already run Pi-hole at home and want to keep it — for custom blocklists, local query logs, or full control over your home network — Casper isn't asking you to replace it. Think of Casper as the mobile layer your home Pi-hole can't cover: no second server to run, no port forwarding, no dynamic DNS. Your home network stays protected by your Pi-hole; your phone stays protected by Casper wherever it goes.

For users who want filtering on cellular without managing a public-facing server, Casper's Cloak is designed to cover exactly that gap — on iPhone, Android, and Mac.

See current plans at casperscloak.com/subscriptions. Available on iPhone, Android, and Mac — no server to maintain.