Open beta: PryVPN and Plus are €0. Pro is out of stock.

HomeBlogPremium settings

Premium settings

DNS-level ad and tracker blocking on Plus: what it does and what it does not

One toggle, no browser extension, no traffic inspection. How server-side blocking answers advertising, tracking and malware domains — and its honest limits.

The short version. With “Ad blocking (DNS)” enabled, your Plus session resolves names through a filtering resolver inside the tunnel: known advertising, tracking and malware domains answer with an empty address, so the connection never starts. Nothing is inspected, nothing is logged, and if the filter is ever unhealthy the session silently falls back to plain DNS rather than breaking your browsing.

How it works: blocking before connecting

Every ad, tracker and malicious payload starts the same way: a DNS lookup. Block the lookup and there is nothing to download, no script to run, no pixel to fire. That ordering is the whole idea — the block happens before any connection exists, which is why it works in every app on the device at once instead of only inside one browser.

Technically it is simple on purpose. Flip the toggle in the PryVPN app and your session carries a flag; when the node sees it, your DNS goes to a filtering resolver that runs inside the tunnel. Blocked names resolve to an empty answer (0.0.0.0), everything else resolves normally. The toggle defaults to off, the flag lives only for the life of the session, and no per-user block log exists anywhere — the resolver keeps no query log by construction, so there is nothing to leak, subpoena or breach.

What gets blocked: ads, trackers, malware

Three maintained lists feed the filter:

  • Advertising domains — the hosts that serve banners, video pre-rolls and sponsored slots. Pages load visibly faster on slow networks because megabytes of creative never download.
  • Tracking domains — analytics beacons, fingerprinting endpoints and cross-site pixels. This is the privacy half: fewer third parties learning which pages you visit.
  • Malware domains — hosts flagged for distributing malicious payloads. It will not save you from yourself, but it removes one cheap infection vector: the drive-by domain.

The lists update on the server, so there is nothing to refresh on your devices. When a new tracker domain makes the rounds, every Plus session with the toggle on is covered without an app update.

Why Plus and not Free

Filtering resolvers cost CPU and memory on every lookup, on every session, forever — it is genuinely the most expensive per-user feature in the product after bandwidth itself. So it sits where the economics work: Plus and Pro. Free keeps the baseline every plan shares — tunnel-imposed DNS with no logging — while Plus adds the filter on top. If a Free session asks for filtering, the app says so plainly and points at Plus instead of pretending.

What it does not do: the honest limits

DNS blocking is powerful and narrow. Worth knowing exactly where the edges are:

  • It is not cosmetic. A browser extension can collapse the empty box where the ad was; DNS blocking leaves the space. Pages look slightly plainer. That is the price of working everywhere instead of in one browser.
  • It cannot see inside encryption. Nothing is decrypted or inspected — that is a privacy guarantee, and it means first-party tracking (the site itself watching you, logged in) is untouched. A VPN was never going to fix that; only separate accounts and habits do.
  • Apps with pinned resolvers can bypass it. A handful of apps ship their own hardcoded DNS and ignore the tunnel's. That is their choice working as coded, and no DNS-level control — ours or anyone's — reaches them.
  • It fails open, deliberately. If the filtering resolver is ever unhealthy, the session falls back to plain tunnel DNS rather than cutting you off. Availability beats purity: a privacy tool that breaks browsing trains people to turn it off, which is the worst outcome of all.

How to enable it

  1. Update the PryVPN app and open its settings on a Plus or Pro account.
  2. Turn on “Ad blocking (DNS)”. It is off by default — filtering changes what pages look like, and that should always be your call.
  3. Reconnect so the new session carries the flag. If the node cannot serve filtered DNS right now, the app tells you instead of failing silently.

Questions we hear

Does ad blocking see my traffic?
No. It sees DNS lookups — the same lookups any resolver must see to do its job — and answers some of them with an empty address. Payloads are never decrypted, pages are never inspected, and the resolver keeps no query log, so there is no record of what you asked for.
Why do some ads survive?
Three usual reasons: the ad is served from the site's own domain (first-party, indistinguishable from content at the DNS level), the app uses a hardcoded resolver that bypasses tunnel DNS, or the domain is too new for the lists. cosmetic leftovers are expected — DNS blocking removes the download, not always the empty frame.
Will it break websites or apps?
Rarely, and recoverably: a site that refuses to work when its tracker is unreachable can be handled by turning the toggle off for that session. Because the flag is per-session and defaults to off, you are never stuck — reconnect without it and everything resolves plainly.
Is this a replacement for a browser ad blocker?
It is a complement. Use both: DNS blocking covers every app on the device and costs no battery per page, while a browser blocker adds cosmetic filtering and script-level control inside the browser. They overlap on purpose.

Elena MarínProduct Writer

Elena writes the setup guides: apps, extensions, and every setting in the console, tested on real devices.

Reviewed by Mara Vidal · Updated 7 September 2026

Take a lane.

PryVPN and Plus are €0 during the beta. A profile takes one click.