# Tpc.googlesyndication.com and googleads.g.doubleclick.net getting through

**URL:** <https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838>\
**Category:** Help\
**Created:** [August 7, 2020, 1:43pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838 "2020-08-07T13:43:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krowi](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/fbc32d/32.png) [@Krowi](https://discourse.pi-hole.net/u/Krowi)\
**Post date:** [August 7, 2020, 1:43pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/1 "2020-08-07T13:43:04Z")

</div>

## Expected Behaviour:

Pihole blocks tpc.googlesyndication.com and googleads.g.doubleclick.net getting through

## Actual Behaviour:

tpc.googlesyndication.com and googleads.g.doubleclick.net getting through

## Debug Token:

[https://tricorder.pi-hole.net/jlze6994r8](https://tricorder.pi-hole.net/jlze6994r8)

I've installe pi-hole today and for some reason, tpc.googlesyndication.com and googleads.g.doubleclick.net are getting through. The site I test is [https://www.demorgen.be/](https://www.demorgen.be/).

Something I noticed is that these ads are all loaded inside an amp-img.

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [August 7, 2020, 2:40pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/2 "2020-08-07T14:40:11Z")

</div>

A few thoughts:

1. You are using block lists that are questionable.

```auto
https://dbl.oisd.nl/
https://dbl.oisd.nl/light/

```

The list maintainer selectively whitelists domains and does not publicize the domains they choose to whitelist. Domains that you would expect to be blocked are not always blocked. I would ditch these lists and select from more reputable lists here: [https://wally3k.github.io](https://wally3k.github.io)

1. Of the two questionable blocklists, only the second one is enabled. Let's check that list to see if it contains the two domains; and find it does.

```auto
pihole -q tpc.googlesyndication.com
 Match found in https://dbl.oisd.nl/light/:
   tpc.googlesyndication.com 
   tpc.googlesyndication.com.proxy.c9w.net

```

```auto
pihole -q googleads.g.doubleclick.net
Match found in **https://dbl.oisd.nl/light/** :
googleads.g.doubleclick.net

```

1. The regex you have crafted are incorrect:

You have `.*googlesyndication.*` , which does not block `tpc.googlesyndication.com`

Add `googlesyndication.com` as a wildcard blacklist entry, and Pi-hole will convert that to the following regex which does block that domain.

`(\.|^)googlesyndication\.com$`

1. If the browser you are using is able to load these domains, then the DNS queries for that browser are not going to Pi-hole. This can be caused by a few things:

- The browser is using a DNS other than the DNS provided by the client OS (i.e. DNS over HTTPS).

- The client is not using Pi-hole for DNS resolution.

From the client command prompt or terminal (and not via ssh into the Pi terminal), what are the outputs of the following:

`nslookup pi.hole`

`nslookup tpc.googlesyndication.com 192.168.178.13`

---

<div class="post-metadata">

**Author:** ![Krowi](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/fbc32d/32.png) [@Krowi](https://discourse.pi-hole.net/u/Krowi)\
**Post date:** [August 7, 2020, 3:00pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/3 "2020-08-07T15:00:45Z")

</div>

> [@jfb](#):
>
> nslookup tpc.googlesyndication.com 192.168.178.13

1. I've removed the block list and moved to [https://adaway.org/hosts.txt](https://adaway.org/hosts.txt)
2. I've ran your test and this returned:

```auto
pihole -q tpc.googlesyndication.com
Match found in regex blacklist
  (\.|^)googlesyndication\.com$
Match found in https://adaway.org/hosts.txt:
  tpc.googlesyndication.com

```

```auto
pihole -q googleads.g.doubleclick.net
Match found in https://adaway.org/hosts.txt:
  googleads.g.doubleclick.net

```

1. I've removed the regex as suggested and match is confirmed in 2.
2. `nslookup pi.hole` returns this the following:

```auto
Server: raspberrypi
Address: 2a02:578:857c:e00:6bee:313f:5c48:e6c6

Name: pi.hole
Addresses: 2a02:578:857c:e00:6bee:313f:5c48:e6c6
          192.168.178.13

```

`nslookup tpc.googlesyndication.com 192.168.178.13` gives this:

```auto
Server: raspberrypi
Address: 192.168.178.13

Name: tpc.googlesyndication.com
Addresses: ::
          0.0.0.0

```

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [August 7, 2020, 3:18pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/4 "2020-08-07T15:18:41Z")

</div>

This confirms that Pi-hole is blocking that domain and the client is using Pi-hole for DNS.

Either the browser is using an alternate DNS, or the ads are coming from other domains.

> [@How do I determine what domain an ad is coming from?](https://discourse.pi-hole.net/t/how-do-i-determine-what-domain-an-ad-is-coming-from/1522):
>
> Block ads or fix broken sites This FAQ is written in the context of finding out how to block an ad that isn't blocked automatically, but the same steps can be used to troubleshoot issues with sites that don't function properly. An example is that sometimes certain payment gateways try to collect metrics on the sale, but these domains are blocked by Pi-hole, so the payment cannot be processed. Also, some links send you through several referrers and if one of them is blocked, you may land on a b…

---

<div class="post-metadata">

**Author:** ![Krowi](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/k/fbc32d/32.png) [@Krowi](https://discourse.pi-hole.net/u/Krowi)\
**Post date:** [August 10, 2020, 6:15am UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/5 "2020-08-10T06:15:15Z")

</div>

It somehow got fixed by restarting the troubled pc. It was a company pc which was running under a VPN before. Restarting removed the VPN and now adds are gone. Not sure if it will return after enabling the VPN but now I probably know the cause at least.

---

<div class="post-metadata">

**Author:** ![jfb](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/jfb/32/4332_2.png) [@jfb](https://discourse.pi-hole.net/u/jfb)\
**Post date:** [August 10, 2020, 2:48pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/6 "2020-08-10T14:48:25Z")

</div>

> [@Krowi](#):
>
> Not sure if it will return after enabling the VPN

It will. When a client device is on a VPN service, the DNS for that device moves to the DNS of the VPN service as well, to prevent DNS traffic outside the VPN tunnel.

---

<div class="post-metadata">

**Author:** ![system](https://discourse.pi-hole.net/uploads/default/original/3X/7/c/7c8792f649eeb921c5d2b4c41564ffa873d9a2b8.png) [@system](https://discourse.pi-hole.net/u/system)\
**Post date:** [August 31, 2020, 2:48pm UTC](https://discourse.pi-hole.net/t/tpc-googlesyndication-com-and-googleads-g-doubleclick-net-getting-through/36838/7 "2020-08-31T14:48:29Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
