# Blocklists and regex

**URL:** <https://discourse.pi-hole.net/t/blocklists-and-regex/36846>\
**Category:** Community Help\
**Created:** [August 7, 2020, 5:41pm UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846 "2020-08-07T17:41:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mimas](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/m/51bf81/32.png) [@Mimas](https://discourse.pi-hole.net/u/Mimas)\
**Post date:** [August 7, 2020, 5:41pm UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/1 "2020-08-07T17:41:31Z")

</div>

I'm trying to figure out the approach to take to block a large number of domains.

Is there any way of using regex in a blocklist? Basically what I am trying to accomplish is having a blocklist containing newly registered domains, this list gets updated once a day and I am trying to block any hostname from said domains.

Overall this list would be around 3 million domains for the past 30 days, using the api/sqlite to inject and remove every single domain (sort of) every day isn't really feasible I think. Or is there some way of having PiHole understand that the block list it downloads contains regex?

The other way I could do it would be to add every naked domain as well as www into the list, turning it into a 6 million hosts list, but then that only would capture those rather than any other subdomain that might show up which is not getting me all the way to the intended result.

---

<div class="post-metadata">

**Author:** ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)\
**Post date:** [August 8, 2020, 9:54pm UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/2 "2020-08-08T21:54:10Z")

</div>

> [@Mimas](#):
>
> Or is there some way of having PiHole understand that the block list it downloads contains regex?

No, that's not supported (yet)

> [@Load regexps from "host file"](https://discourse.pi-hole.net/t/load-regexps-from-host-file/25829):
>
> Hey Guys, I haven't used Pi-Hole in a little while as I have been experimenting with AdGuard Home. I have had a feature request or two from people whom have wanted to add individual domains to my [regexp list](https://github.com/mmotti/pihole-regex), but I have been trying to keep it as broad as possbile to avoid enforcing my personalised wildcard blocking onto everyone. There has been some chatter around first party trackers and needing to wildcard block those, which I may like to create a separate list for, but I don't really want t…

But if you create this list and know which entries are regex (using a flag or so) you could adapt your injection: Split the file in regex and non-regex. The non-regex file is imported as an **adlist** at once (run gravity afterwards). Only the regex file has to be injected line by line into the database.

 ![Bildschirmfoto zu 2020-08-08 23-52-19](https://discourse.pi-hole.net/uploads/default/original/3X/4/a/4aa374b7a98a46409d056340d7b6429095edfa74.png)

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [August 8, 2020, 10:02pm UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/3 "2020-08-08T22:02:03Z")

</div>

> [@Mimas](#):
>
> what I am trying to accomplish is having a blocklist containing newly registered domains

Why? What about newly registered domains makes them all block worthy?

---

<div class="post-metadata">

**Author:** ![Bucking\_Horn](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/bucking_horn/32/18719_2.png) [@Bucking\_Horn](https://discourse.pi-hole.net/u/Bucking_Horn)\
**Post date:** [August 8, 2020, 10:37pm UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/4 "2020-08-08T22:37:42Z")

</div>

This comparison may be flawed, but I can't imagine some high-profile bodyguard to have an easier job by requesting and storing information about every new-born baby world-wide, only to delete it once they reach pre-school age. None of those have ever met the target, most very likely never will, and how many of the few who do will pose an actual threat?

If you want to be that cautious, following a deny all policy, allowing access to known and verified domains only, may be both easier to implement and to maintain, and also more effective.

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [August 8, 2020, 10:38pm UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/5 "2020-08-08T22:38:03Z")

</div>

> [@jfb](#):
>
> Why? What about newly registered domains makes them all block worthy?

A common strategy is to not trust newly created domains.  
Some companies create and discard them (for example ad/tracking purposes) quicker than you can say dodadoda.  
Only when a domain exists for a bit longer can it be trusted ... just a little 😉  
Am not sure if its a valid/effective strategy though.

---

<div class="post-metadata">

**Author:** ![yubiuser](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/yubiuser/32/12100_2.png) [@yubiuser](https://discourse.pi-hole.net/u/yubiuser)\
**Post date:** [August 9, 2020, 5:13am UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/6 "2020-08-09T05:13:03Z")

</div>

For the OP.  
There is a feature request for what you want

> [@Option to block recently created domains (DGA)](https://discourse.pi-hole.net/t/option-to-block-recently-created-domains-dga/20700/21):
>
> I try to elaborate on my previous post: The whole WHOIS protocol lacks proper standardisation, e.g. it does not guide encoding at all -neither for queries nor for the requested content- which would be a prerequisite for internationalisation, many of the data are not required to be well-formed (e.g. data might be labeled differently by different providers or not have the same semantics tied to it), there is no standard for determining the authoritative WHOIS server for a given domain name, possi…

---

<div class="post-metadata">

**Author:** ![system](https://discourse.pi-hole.net/uploads/default/original/3X/7/c/7c8792f649eeb921c5d2b4c41564ffa873d9a2b8.png) [@system](https://discourse.pi-hole.net/u/system)\
**Post date:** [August 30, 2020, 5:13am UTC](https://discourse.pi-hole.net/t/blocklists-and-regex/36846/7 "2020-08-30T05:13:53Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
