{
  "slug": "adguard",
  "category": "dns-resolvers",
  "name": "AdGuard",
  "description": "Public DNS resolver from AdGuard that blocks ads, trackers and malicious domains, with open-source server software and DoH, DoT, DoQ and DNSCrypt support.",
  "website": "https://adguard-dns.io",
  "source": "https://github.com/AdguardTeam/AdGuardDNS",
  "license": "AGPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "CY",
    "name": "Cyprus",
    "eyes": null,
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 63,
  "coverage": 100,
  "summary": "AdGuard scores 63 out of 100 (grade C) on the DNS resolvers criteria. It meets 5 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, Encrypted DNS and DNSSEC validation. It partly meets TLS configuration and no query logs. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in Cyprus: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade B and Mozilla HTTP Observatory grade F.",
  "url": "https://privacyratings.com/dns-resolvers/adguard/",
  "markdown": "https://privacyratings.com/dns-resolvers/adguard/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/AdguardTeam/AdGuardDNS/blob/master/COPYING",
      "note": "AGPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://adguard-dns.io/en/privacy.html",
      "note": "The policy states processed data is not shared with third parties, and the website loads no third-party analytics."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://adguard-dns.io/en/privacy.html",
      "note": "Funded by paid private DNS plans. The policy states personal data is not sold or shared."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=adguard-dns.io&hideResults=on",
      "note": "Grade B"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=adguard-dns.io",
      "note": "Grade F (5/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "encrypted_dns": {
      "title": "Encrypted DNS",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://adguard-dns.io/kb/public-dns/overview/",
      "note": "DoH, DoT, DoQ and DNSCrypt are supported."
    },
    "no_query_logs": {
      "title": "No query logs",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://adguard-dns.io/en/privacy.html",
      "note": "The policy states no personal data is processed for public DNS and only an anonymous domain list is kept for 24 hours. Not audited."
    },
    "dnssec_validation": {
      "title": "DNSSEC validation",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://dns.adguard-dns.com/resolve?name=dnssec-failed.org&type=A",
      "note": "A lookup of the deliberately broken dnssec-failed.org domain is rejected as DNSSEC bogus."
    }
  },
  "tests": {
    "ssllabs": "B",
    "observatory": "F",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T11:01:36.208Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}