Premium settings
DNS-level ad and tracker blocking on Plus: what it does and what it does not
One toggle, no browser extension, no traffic inspection. How server-side blocking answers advertising, tracking and malware domains — and its honest limits.
The short version. With “Ad blocking (DNS)” enabled, your Plus session resolves names through a filtering resolver inside the tunnel: known advertising, tracking and malware domains answer with an empty address, so the connection never starts. Nothing is inspected, nothing is logged, and if the filter is ever unhealthy the session silently falls back to plain DNS rather than breaking your browsing.
How it works: blocking before connecting
Every ad, tracker and malicious payload starts the same way: a DNS lookup. Block the lookup and there is nothing to download, no script to run, no pixel to fire. That ordering is the whole idea — the block happens before any connection exists, which is why it works in every app on the device at once instead of only inside one browser.
Technically it is simple on purpose. Flip the toggle in the PryVPN app and your session carries a flag; when the node sees it, your DNS goes to a filtering resolver that runs inside the tunnel. Blocked names resolve to an empty answer (0.0.0.0), everything else resolves normally. The toggle defaults to off, the flag lives only for the life of the session, and no per-user block log exists anywhere — the resolver keeps no query log by construction, so there is nothing to leak, subpoena or breach.
What gets blocked: ads, trackers, malware
Three maintained lists feed the filter:
- Advertising domains — the hosts that serve banners, video pre-rolls and sponsored slots. Pages load visibly faster on slow networks because megabytes of creative never download.
- Tracking domains — analytics beacons, fingerprinting endpoints and cross-site pixels. This is the privacy half: fewer third parties learning which pages you visit.
- Malware domains — hosts flagged for distributing malicious payloads. It will not save you from yourself, but it removes one cheap infection vector: the drive-by domain.
The lists update on the server, so there is nothing to refresh on your devices. When a new tracker domain makes the rounds, every Plus session with the toggle on is covered without an app update.
Why Plus and not Free
Filtering resolvers cost CPU and memory on every lookup, on every session, forever — it is genuinely the most expensive per-user feature in the product after bandwidth itself. So it sits where the economics work: Plus and Pro. Free keeps the baseline every plan shares — tunnel-imposed DNS with no logging — while Plus adds the filter on top. If a Free session asks for filtering, the app says so plainly and points at Plus instead of pretending.
What it does not do: the honest limits
DNS blocking is powerful and narrow. Worth knowing exactly where the edges are:
- It is not cosmetic. A browser extension can collapse the empty box where the ad was; DNS blocking leaves the space. Pages look slightly plainer. That is the price of working everywhere instead of in one browser.
- It cannot see inside encryption. Nothing is decrypted or inspected — that is a privacy guarantee, and it means first-party tracking (the site itself watching you, logged in) is untouched. A VPN was never going to fix that; only separate accounts and habits do.
- Apps with pinned resolvers can bypass it. A handful of apps ship their own hardcoded DNS and ignore the tunnel's. That is their choice working as coded, and no DNS-level control — ours or anyone's — reaches them.
- It fails open, deliberately. If the filtering resolver is ever unhealthy, the session falls back to plain tunnel DNS rather than cutting you off. Availability beats purity: a privacy tool that breaks browsing trains people to turn it off, which is the worst outcome of all.
How to enable it
- Update the PryVPN app and open its settings on a Plus or Pro account.
- Turn on “Ad blocking (DNS)”. It is off by default — filtering changes what pages look like, and that should always be your call.
- Reconnect so the new session carries the flag. If the node cannot serve filtered DNS right now, the app tells you instead of failing silently.
Questions we hear
Does ad blocking see my traffic?
Why do some ads survive?
Will it break websites or apps?
Is this a replacement for a browser ad blocker?
Reviewed by Mara Vidal · Updated 7 September 2026