# Block certain sites

**URL:** <https://discourse.pi-hole.net/t/block-certain-sites/1701>\
**Category:** Closed or Out Of Scope\
**Created:** [February 12, 2017, 2:36pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701 "2017-02-12T14:36:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mattrebel](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/d2c977/32.png) [@mattrebel](https://discourse.pi-hole.net/u/mattrebel)\
**Post date:** [February 12, 2017, 2:36pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/1 "2017-02-12T14:36:41Z")

</div>

Dear pi-Hole team,

I’ve been looking into pi-Hole and love it so far, even told a friend of mine about it and and got him excited as well. But then he asked me if he could protect his kids from certain sites or subpages and I had to disappoint him. Would be brilliant if pi-Hole could do this for the entire network so he does not have to do this on every device.  
He would for instance like to block “[https://www.youtube.com/watch?v=J6\_3RH4DK1A”](https://www.youtube.com/watch?v=J6_3RH4DK1A%E2%80%9D), but not the entire youtube domain.

Request: Block a domain of subpages on the network.

Kind regards,  
Matt

---

<div class="post-metadata">

**Author:** ![spacemonkey](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/s/c77e96/32.png) [@spacemonkey](https://discourse.pi-hole.net/u/spacemonkey)\
**Post date:** [February 12, 2017, 7:20pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/2 "2017-02-12T19:20:41Z")

</div>

To _filter_ specific **URLs** you would need a transparent proxy server like Squid. Pi-Hole is a DNS resolver that _blocks_ whole **domains** and **sub-domains**.

---

<div class="post-metadata">

**Author:** ![jacob.salmela](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jacob.salmela/32/8_2.png) [@jacob.salmela](https://discourse.pi-hole.net/u/jacob.salmela)\
**Post date:** [February 12, 2017, 9:41pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/3 "2017-02-12T21:41:57Z")

</div>

> [@spacemonkey](#):
>
> Pi-Hole is a DNS resolver that blocks whole domains and sub-domains.

This is exactly right, _but_ see below...

> [@spacemonkey](#):
>
> To filter specific URLs you would need a transparent proxy server like Squid.

If Pi-hole was _solely_ a DNS server, than this would be correct. However, Pi-hole also includes a Web server, which can actually handle the URLs. Here is an example that I have been experimenting with assuming adserver-us.adtech.advertising.com is a blocked domain.

By default, if you `curl -I` this domain, you get a response like this:

```auto
HTTP/1.1 200 OK
X-Pi-hole: A black hole for Internet advertisements.
Content-type: text/html; charset=UTF-8
Date: Sun, 12 Feb 2017 21:30:14 GMT
Server: lighttpd/1.4.35

```

And if you go directly to this domain, you will end up at the Pi-hole block page, which is the expected behavior.

 ![](https://discourse.pi-hole.net/uploads/default/original/3X/9/1/9157b80b670b01be9538c9d6b99014be4ef935be.png)

If you go to a specific URL of that domain such as `adserver-us.adtech.advertising.com/pubapi/3.0/10126.1/3891134/0/0/ADTECH;v=2;cmd=bid;cors=yes;alias=300c;misc=08098983434`, you get the same results.

Now if you add the following to `lighttpd.conf`:

```auto
$HTTP["url"] =~ "^(/pubapi/).*" {
        url.redirect = ( "(.*)" => "192.168.1.200" )
}

```

If you `curl` _just_ the domain again, you get the expected result, but if you `curl` a full URL of the domain, you get this:

```auto
HTTP/1.1 301 Moved Permanently
Location: 192.168.1.100
Date: Sun, 12 Feb 2017 21:58:18 GMT
Server: lighttpd/1.4.35

```

This shows that the redirect directive is working on the URL level and not the domain level. It would be difficult to make a rule for every part of a URL or domain and to get it to go to the right place...but like I said, I have just been experimenting with it.

So this request is out of scope for now, if not impossible.

---

<div class="post-metadata">

**Author:** ![Mcat12](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/mcat12/32/20_2.png) [@Mcat12](https://discourse.pi-hole.net/u/Mcat12)\
**Post date:** [February 12, 2017, 10:26pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/4 "2017-02-12T22:26:53Z")

</div>

Also, it would require that the domain be blocked so that the request is forwarded to the Pi-hole's web server.

---

<div class="post-metadata">

**Author:** ![spacemonkey](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/s/c77e96/32.png) [@spacemonkey](https://discourse.pi-hole.net/u/spacemonkey)\
**Post date:** [February 13, 2017, 8:32am UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/5 "2017-02-13T08:32:42Z")

</div>

> [@Mcat12](#):
>
> Also, it would require that the domain be blocked so that the request is forwarded to the Pi-hole's web server.

I have seen this used in a dns blocker package in pfsense, that reveals in it's log page, the url part of the blocked request, which imho is a privacy concern. I use Pi-Hole for it's simplicity - it is a lean, mean machine so to speak. It has made my internet noticeably faster.

---

<div class="post-metadata">

**Author:** ![Mcat12](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/mcat12/32/20_2.png) [@Mcat12](https://discourse.pi-hole.net/u/Mcat12)\
**Post date:** [February 13, 2017, 12:04pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/6 "2017-02-13T12:04:51Z")

</div>

You can also disable lighttpd's access log if you're concerned about privacy, because that logs all server access including blocked pages.

---

<div class="post-metadata">

**Author:** ![telekrmor](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/telekrmor/32/357_2.png) [@telekrmor](https://discourse.pi-hole.net/u/telekrmor)\
**Post date:** [February 13, 2017, 2:27pm UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/7 "2017-02-13T14:27:05Z")

</div>

> [@Mcat12](#):
>
> Also, it would require that the domain be blocked so that the request is forwarded to the Pi-hole's web server.

Yeah, you would almost need a second Pi-hole to just forward it upstream. But again, it's totally experimental and theoretical--just fun to think about.

---

<div class="post-metadata">

**Author:** ![jacob.salmela](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jacob.salmela/32/8_2.png) [@jacob.salmela](https://discourse.pi-hole.net/u/jacob.salmela)\
**Post date:** [February 23, 2017, 2:35am UTC](https://discourse.pi-hole.net/t/block-certain-sites/1701/8 "2017-02-23T02:35:19Z")

</div>


