How to Set Up a DNS Server on a Raspberry Pi

A Raspberry Pi can provide faster, more private name resolution for a home or small office network. Instead of asking an internet provider’s DNS service to translate every domain name, devices can send requests to a local resolver running on the Pi.

This setup is useful for Australian households using NBN connections, shared workspaces in Sydney or Melbourne, and small businesses that want basic ad blocking, local hostnames, or greater visibility over network activity. The project is inexpensive, quiet, and suitable for a Raspberry Pi 3, 4, or 5 with a reliable power supply.

Option Best for Main advantage Main limitation
Pi-hole Homes and small offices DNS filtering and an easy dashboard Needs occasional blocklist maintenance
AdGuard Home User-friendly filtering Clear controls and privacy features Uses more resources than a minimal resolver
Unbound Private recursive DNS Queries authoritative servers directly More technical configuration
dnsmasq Simple local DNS and DHCP Lightweight and flexible Limited reporting and filtering
ISP or public DNS Basic connectivity No local hardware required Less control over privacy and filtering

Choose the hardware and operating system

Use a Raspberry Pi with Raspberry Pi OS Lite 64-bit, a quality microSD card, and a wired Ethernet connection. Wi-Fi can work, but Ethernet is preferable because the DNS server must remain reachable when several devices reconnect at once. A small UPS is worthwhile in areas affected by summer storms or brief power interruptions.

Download Raspberry Pi Imager, write the operating system to the card, and enable SSH during installation if you want to administer the device remotely. Give the Pi a memorable hostname, such as dns-pi, and connect it to the router before starting the software installation.

Avoid placing the device in direct sunlight or inside a closed cabinet. Australian indoor temperatures can become high during a Brisbane summer, so ventilation matters even though DNS services use little processing power.

Give the Raspberry Pi a stable address

A DNS server should have an address that does not change. The simplest approach is a DHCP reservation in the router: allow the router to assign the same address to the Pi’s network adapter every time. This is often safer than manually configuring network files on newer Raspberry Pi OS releases.

Sign in to the router, find the connected-device list, and reserve an address such as 192.168.1.10. Router menus vary between NBN providers and hardware brands, so the setting may be called “static lease”, “address reservation”, or “DHCP binding”.

After reconnecting, check the address with:

hostname -I
ip route

Record the Pi’s address and router address. You will need both when changing DHCP settings later.

Install a DNS service

Pi-hole is a practical choice for a first installation because it combines DNS forwarding, blocklists, statistics, and a web interface. Update the operating system first:

sudo apt update
sudo apt full-upgrade -y

Install Pi-hole using its official installer, then select the Ethernet interface, the reserved IP address, and upstream resolvers such as Quad9, Cloudflare, or your preferred provider. The installer displays an administrator password for the web console, so store it in a password manager.

For a smaller, less visual installation, dnsmasq can provide local records and forwarding. Unbound is a stronger choice when you want recursive resolution rather than forwarding requests to a public resolver. Do not run multiple services that compete for port 53 unless you understand which process should handle DNS queries.

Point the network at the new resolver

Once the service is running, open its dashboard or test it from another computer:

nslookup example.com 192.168.1.10

If the response includes the Pi’s address as the server, the query reached your local resolver. Next, change the router’s LAN or DHCP DNS setting to 192.168.1.10. Clients will receive the new setting when their DHCP leases renew, although restarting a device is sometimes quicker.

Some ISP routers supplied for NBN connections restrict DNS changes. In that case, disable the router’s DHCP service and use Pi-hole or another trusted device for DHCP, or place the ISP router in bridge mode with a separate router. Test carefully before changing this, because an incorrect DHCP configuration can disconnect every device in the home.

Add privacy, filtering, and local names

Pi-hole and AdGuard Home can block advertising, trackers, and known malicious domains for phones, televisions, tablets, and computers. Begin with the default lists, then add reputable sources gradually. Overly aggressive lists can break banking portals, shopping sites, streaming services, and work applications.

Create local DNS records for devices such as nas.home.arpa, printer.home.arpa, or camera.home.arpa. The .home.arpa domain is intended for private networks and avoids collisions with public websites. DNS filtering can also reduce unwanted traffic from smart televisions, while separate VLANs remain necessary for serious network isolation.

DNS will not improve every internet activity. It may make domain lookups feel quicker, but it cannot fix weak Wi-Fi, NBN congestion, or poor international routing. It also does not replace a firewall, endpoint protection, or safe password practices. Network-related services can sit alongside specialist content such as video phone guides without changing the role of the Pi-based resolver.

Keep the resolver secure and dependable

Never expose the Pi’s DNS service directly to the public internet by forwarding TCP or UDP port 53 from the router. An open resolver can be abused for amplification attacks. Restrict administration to the local network, use SSH keys where practical, and change default passwords immediately.

Keep Raspberry Pi OS and the DNS application updated:

sudo apt update
sudo apt upgrade -y

Review query logs for unusual activity, check available storage, and back up the service configuration. A spare microSD card or a second Pi can reduce downtime for a small office. If the Pi fails, temporarily restore the router’s original DNS settings so the household can continue browsing.

The dependable arrangement is simple: wired Raspberry Pi, reserved local address, a single well-configured DNS service, router DHCP pointing to that address, and no public exposure. Test with nslookup, document the settings, and keep a fallback resolver available for maintenance.