# Find which Android app is causing so many DNS requests

**URL:** https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448
**Category:** Help
**Created:** [August 10, 2017, 10:15pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448 "2017-08-10T22:15:21Z")
**Posts on this page:** 17
**Page:** 1

<div class="post-metadata">

### Author: ![Davey](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/davey/32/100_2.png) [@Davey](https://discourse.pi-hole.net/u/Davey)
#### Post date: [August 10, 2017, 10:15pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/1 "2017-08-10T22:15:21Z")

</div>

My Pi Hole is saying my Android phone is causing over 3000 DNS requests for google ad services each day, I've uninstalled just about every app I can think of since it started but the problem persists

Is there any way to find out which app is causing the requests? I don't think Pi Hole could do it, but was wondering if anyone could think of any other method?

It doesn't seem to be causing any network issues, but battery life has definitely taken a hit lately, not sure if this is the cause

 ![](https://discourse.pi-hole.net/uploads/default/original/3X/d/a/daee1f88019e925f4e17f6fda08f588a54866792.png)

---

<div class="post-metadata">

### Author: ![firestorrrm](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/f/edb3f5/32.png) [@firestorrrm](https://discourse.pi-hole.net/u/firestorrrm)
#### Post date: [August 10, 2017, 10:57pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/2 "2017-08-10T22:57:59Z")

</div>

Click on `192.168.1.120`. It should bring you to a filtered query log with requests only from that device. From there, look and see what's there. If you still don't know, post some of the queries here.

---

<div class="post-metadata">

### Author: ![Anudeep](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/anudeep/32/194_2.png) [@Anudeep](https://discourse.pi-hole.net/u/Anudeep)
#### Post date: [August 11, 2017, 1:43am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/3 "2017-08-11T01:43:45Z")

</div>

Use [this](https://play.google.com/store/apps/details?id=eu.faircode.netguard&hl=en&referrer=utm_source%3Dgoogle%26utm_medium%3Dorganic%26utm_term%3Dnetguard&pcampaignid=APPU_1_LQuNWd-UDYjzvgTci6_YAw) app to monitor which app is making lots of DNS queries

---

<div class="post-metadata">

### Author: ![Davey](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/davey/32/100_2.png) [@Davey](https://discourse.pi-hole.net/u/Davey)
#### Post date: [August 11, 2017, 7:10am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/4 "2017-08-11T07:10:55Z")

</div>

Thanks yea that's what I mean, it only shows

ssl.google-analytics.com \<\<\< main culprit

www.googleadservices.com \<\<\< next worst

Which could be from any app

---

<div class="post-metadata">

### Author: ![Davey](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/davey/32/100_2.png) [@Davey](https://discourse.pi-hole.net/u/Davey)
#### Post date: [August 11, 2017, 7:11am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/5 "2017-08-11T07:11:26Z")

</div>

Thanks for the firewall app suggestion, I`ll install that today and see what it logs

---

<div class="post-metadata">

### Author: ![Anudeep](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/anudeep/32/194_2.png) [@Anudeep](https://discourse.pi-hole.net/u/Anudeep)
#### Post date: [August 11, 2017, 4:13pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/6 "2017-08-11T16:13:00Z")

</div>

@Davey did you find out which app was making those queries?

---

<div class="post-metadata">

### Author: ![Davey](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/davey/32/100_2.png) [@Davey](https://discourse.pi-hole.net/u/Davey)
#### Post date: [August 11, 2017, 5:16pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/7 "2017-08-11T17:16:55Z")

</div>

Unfortunately not, the firewall app didn't show anything helpful, pihole tail log shows a lot of requests to amazonaws and samsung cloud, but still no closer to working out what is causing it

Samsung cloud has always been enabled to backup / sync certain data I selected and has never caused this, so not sure it's that causing it (Galaxy S7)

`Aug 11 17:15:38 dnsmasq[27281]: query[A] okee79p5ag.execute-api.us-west-2.amazonaws.com from 192.168.1.120
Aug 11 17:15:38 dnsmasq[27281]: forwarded okee79p5ag.execute-api.us-west-2.amazonaws.com to 4.2.2.2
Aug 11 17:15:38 dnsmasq[27281]: forwarded okee79p5ag.execute-api.us-west-2.amazonaws.com to 4.2.2.1
Aug 11 17:15:38 dnsmasq[27281]: forwarded okee79p5ag.execute-api.us-west-2.amazonaws.com to 208.67.220.220
Aug 11 17:15:38 dnsmasq[27281]: forwarded okee79p5ag.execute-api.us-west-2.amazonaws.com to 208.67.222.222
Aug 11 17:15:38 dnsmasq[27281]: forwarded okee79p5ag.execute-api.us-west-2.amazonaws.com to 8.8.4.4
Aug 11 17:15:38 dnsmasq[27281]: forwarded okee79p5ag.execute-api.us-west-2.amazonaws.com to 8.8.8.8
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.178
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.46
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.251
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.14
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.140
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.56
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.202
Aug 11 17:15:38 dnsmasq[27281]: reply okee79p5ag.execute-api.us-west-2.amazonaws.com is 54.230.79.183
Aug 11 17:15:40 dnsmasq[27281]: query[A] stock.todayweather.co from 192.168.1.120
Aug 11 17:15:40 dnsmasq[27281]: forwarded stock.todayweather.co to 4.2.2.2
Aug 11 17:15:40 dnsmasq[27281]: reply stock.todayweather.co is 104.236.89.221
Aug 11 17:15:44 dnsmasq[27281]: query[A] api.samsungcloud.com from 192.168.1.120
Aug 11 17:15:44 dnsmasq[27281]: cached api.samsungcloud.com is <CNAME>
Aug 11 17:15:44 dnsmasq[27281]: forwarded api.samsungcloud.com to 4.2.2.2
Aug 11 17:15:44 dnsmasq[27281]: reply api.samsungcloud.com is <CNAME>
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.211.49.4
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.213.189.48
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.211.222.35
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.213.36.61
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.211.4.15
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.211.2.124
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 52.211.164.168
Aug 11 17:15:44 dnsmasq[27281]: reply scloud-p2ew1-ext.elb.samsungcloud.com is 54.171.255.0`

---

<div class="post-metadata">

### Author: ![dosch](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dosch/32/784_2.png) [@dosch](https://discourse.pi-hole.net/u/dosch)
#### Post date: [October 3, 2018, 3:16pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/8 "2018-10-03T15:16:04Z")

</div>

> [@Anudeep](#):
>
> Use [this](https://play.google.com/store/apps/details?id=eu.faircode.netguard&hl=en&referrer=utm_source%3Dgoogle%26utm_medium%3Dorganic%26utm_term%3Dnetguard&pcampaignid=APPU_1_LQuNWd-UDYjzvgTci6_YAw) app to monitor which app is making lots of DNS queries

hey, I blocked **all traffic** (including all system apps) on my Android phone using Netguard.  
Still, every second a request is made (and blocked) to ssl.google-analytics.com

 ![18](https://discourse.pi-hole.net/uploads/default/original/2X/4/47a90728464aa0a43d5f8f97a442b7ff0aee13db.png)

I am sure this is my phone, because the requests stop when I disable WiFi on the phone or turn it off completely.

Anyone another idea how I can figure out what is causing this insane amount of requests?

![pihole%20animation](https://discourse.pi-hole.net/uploads/default/original/2X/3/3d482d326820b78feefd39fb81088f75ea24282a.gif)

---

<div class="post-metadata">

### Author: ![Jeroen1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/j/47e85d/32.png) [@Jeroen1](https://discourse.pi-hole.net/u/Jeroen1)
#### Post date: [October 3, 2018, 5:47pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/9 "2018-10-03T17:47:30Z")

</div>

Some hints on google search  
partly disabling google services (like playstore and music) can cause this huge amount of quesries to ssl.google-analytics.com

That does not help much, but try to disable (some) blocklists for a while ans see if it gets any better.

---

<div class="post-metadata">

### Author: ![Valiceemo](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/valiceemo/32/2825_2.png) [@Valiceemo](https://discourse.pi-hole.net/u/Valiceemo)
#### Post date: [October 3, 2018, 6:22pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/10 "2018-10-03T18:22:18Z")

</div>

Also interested in this  
I have many queries from an Android device to `profile.localytics.com`  
And I'm struggling to find the app making the requests with any monitor type app

---

<div class="post-metadata">

### Author: ![dosch](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dosch/32/784_2.png) [@dosch](https://discourse.pi-hole.net/u/dosch)
#### Post date: [October 3, 2018, 7:59pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/11 "2018-10-03T19:59:11Z")

</div>

ah. I have LineageOS with only a very minimal amount of google services installed.  
Still would be interesting to find what process exactly is making these calls (and kill it with fire)

---

<div class="post-metadata">

### Author: ![Jeroen1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/j/47e85d/32.png) [@Jeroen1](https://discourse.pi-hole.net/u/Jeroen1)
#### Post date: [October 4, 2018, 6:22am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/12 "2018-10-04T06:22:42Z")

</div>

In my last post I mentioned “partly disabling”.  
With this I ment blocking by pihole.

From what I read on a Google search:

Blocking Google services might cause these requests to analytics.

With pihole disabled (pihole settings) can anyone verify if these queries become less?

---

<div class="post-metadata">

### Author: ![dosch](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dosch/32/784_2.png) [@dosch](https://discourse.pi-hole.net/u/dosch)
#### Post date: [October 4, 2018, 9:35am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/13 "2018-10-04T09:35:40Z")

</div>

![18](https://discourse.pi-hole.net/uploads/default/original/2X/e/ebdc1b9b561c52da86277e0487cd3e18f7d5218e.png)

It looks like the requests are less...

Still, this is only half satisfying of course:

1. we still do not know what process is causing this.
2. allowing google to spy on me because they were nagging so much that I disabled blocking also does not feel right

---

<div class="post-metadata">

### Author: ![Jeroen1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/j/47e85d/32.png) [@Jeroen1](https://discourse.pi-hole.net/u/Jeroen1)
#### Post date: [October 6, 2018, 10:32am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/14 "2018-10-06T10:32:43Z")

</div>

Agree, but my knowledge of android is limited.  
Perhaps you can root is and play around with the host file?

---

<div class="post-metadata">

### Author: ![Jeroen1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/j/47e85d/32.png) [@Jeroen1](https://discourse.pi-hole.net/u/Jeroen1)
#### Post date: [October 6, 2018, 12:47pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/16 "2018-10-06T12:47:46Z")

</div>

Hi,

For a simple system engineer: You say you know the cause, Is there a solution we can implement on the pihole?

---

<div class="post-metadata">

### Author: ![Jeroen1](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/j/47e85d/32.png) [@Jeroen1](https://discourse.pi-hole.net/u/Jeroen1)
#### Post date: [October 6, 2018, 5:16pm UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/18 "2018-10-06T17:16:43Z")

</div>

Hi msattet,

Thanks for this workaround.

The initial question seems unanswered though.

Or are you indicating that blocking on netguatd will stop the massive amount of DNS requests?

---

<div class="post-metadata">

### Author: ![Munchkinguy](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/munchkinguy/32/8475_2.png) [@Munchkinguy](https://discourse.pi-hole.net/u/Munchkinguy)
#### Post date: [June 18, 2019, 5:01am UTC](https://discourse.pi-hole.net/t/find-which-android-app-is-causing-so-many-dns-requests/4448/20 "2019-06-18T05:01:56Z")

</div>

I also had an app that was contacting Localytics every minute. I used the [Exodus](https://exodus-privacy.eu.org/en/) app to look through each of my apps to find out what trackers they were using. Turns out the culprit was the MyRogers app which is provided by my mobile service provider to track my data and airtime usage. It was pretty useful but now I've disabled it.
