Download AdHole

Free, no account, no ads. One installer for Windows, two archives for Linux (a PC, or a Raspberry Pi 4 or 5), one file for Android, and nothing else to install.

  • Version 1.5.8
  • 2026-09-25
  • Free
  • No account
  • No ads
  • Nothing to pay

Download

One program. Nothing else to install.

Windows, Linux or Android — a PC, a Raspberry Pi, a phone. No Java, .NET or Python to install. On a computer, installing requires administrator rights.

Windows

64-bit · x64

Download the installer

adhole-setup-1.5.8.exe · 9.8 MB

Version
1.5.8
Date
2026-09-25
Size
9.8 MB
SHA-256
38f4673ff670f236579b3bc06560ea07f147124ff2f2c9279c8d89eee153c6c5

Good to know

The installer isn’t signed. Windows shows “Windows protected your PC”: click “More info”, then “Run anyway”. Check the SHA-256 first, in PowerShell:

Get-FileHash .\adhole-setup-1.5.8.exe

The installer shows the terms of use, in English or French, before it changes anything. Please read them.

Firefox needs one extra setting: in about:config, set security.enterprise_roots.enabled to true.

Linux

systemd · amd64 · arm64

PC (amd64)

adhole-1.5.8-linux-amd64.tar.gz · 5.3 MB

Raspberry Pi 4 and 5 (arm64)

adhole-1.5.8-linux-arm64.tar.gz · 4.8 MB

Version
1.5.8
Date
2026-09-25
SHA-256 · amd64
92e29b66539b2c5162ea4a637130557baa8b465a3e9e0f532edd1c674009c5d8
SHA-256 · arm64
5c918b09dba256208edae567e60aeaa84580630fd71473b8e64ea3cef07edfd7

In a terminal opened in your desktop session:

tar xzf adhole-1.5.8-linux-amd64.tar.gzcd adhole-1.5.8-linux-amd64sudo ./adhole setup
  • On a Raspberry Pi, take the arm64 archive and replace amd64 with arm64.
  • setup shows where the terms of use are. Read them, then type yes to accept and install.
  • You need a distribution with systemd: Ubuntu, Debian, Fedora, Arch, Mint, Raspberry Pi OS… Without systemd, sudo ./adhole run runs AdHole in the foreground.
  • The proxy is set automatically under GNOME and KDE. On other desktops, set the proxy auto-configuration URL to http://127.0.0.1:8053/proxy.pac yourself.
  • If setup says certutil is missing, install libnss3-tools (Debian, Ubuntu, Mint) or nss-tools (Fedora), then run sudo adhole setup again.

Android

Android 8.0 or newer · APK

Download the APK

adhole-1.5.8.apk · 54.1 MB

Version
1.5.8
Date
2026-09-25
Size
54.1 MB
SHA-256
1f9649765b9d6bfb30b524c8264bb56a38254df93dd4ff59efd11094536d3ccd

Good to know

Not on Google Play: you install the file yourself. Android asks you once to allow your browser to install apps, then you open the file.

The app shows its terms of use the first time it opens, and starts filtering only once you accept them.

Domain names for every app; and, once you install its certificate, the pages in your browsers. Never inside other apps: the ads in the YouTube app stay, and a blocked rewarded ad pays no reward.

The same file installs on an Android TV box that accepts manual installs.

Installing on Android, step by step

Every file has a SHA-256 checksum, published in the SHA256SUMS file. On Linux: sha256sum -c SHA256SUMS --ignore-missing.

System requirements

What you need.

Windows
Windows 10 or 11, 64-bit (x64), and an administrator account or its password. AdHole has been tested on Windows 11.
Linux
A distribution with systemd (Ubuntu, Debian, Fedora, Arch, Mint, Raspberry Pi OS…) on a PC (amd64) or a 64-bit ARM board such as a Raspberry Pi 4 or 5, and sudo.
Android
Android 8.0 or newer, on a phone, a tablet, or a TV box that accepts manual installs. One file fits ARM processors, 32- and 64-bit, and 64-bit x86.
Your other devices
Your TV, console or phone installs nothing: set its DNS to the computer running AdHole. That computer then has to stay on.
Not offered
AdHole is not available for Mac, nor for 32-bit Windows.

Windows

Install on Windows.

The installer follows the language of Windows: French on a Windows in French, English everywhere else.

  1. Download the installer.

    Take adhole-setup-1.5.8.exe from the Windows card above. Your browser may say the file isn’t commonly downloaded: choose to keep it.

  2. Check its SHA-256.

    Before running it, make sure it’s the file we publish: check the file, it takes one command.

  3. Run it, past the SmartScreen warning.

    Windows shows “Windows protected your PC”: click “More info”, then “Run anyway”. The installer isn’t signed: here is why.

  4. Allow it to make changes.

    Windows asks whether to allow an app from an unknown publisher to make changes, with “Publisher: Unknown”: click “Yes”. Installing requires administrator rights.

  5. Read and accept the terms of use.

    The installer shows the terms of use before it changes anything: accept them to continue. It then shows “Read before installing”, a summary of what AdHole changes on your computer.

  6. Install, then open AdHole.

    Tick “Create a desktop shortcut” if you want one, then install. At the end, leave “Open AdHole” ticked: the dashboard opens. The icon near the clock appears the next time you sign in.

What the installer changes

  • AdHole’s root certificate, in the Windows certificate store (used by Chrome and Edge).
  • Ports 53 and 67 opened in the firewall, for the local network only.
  • The “adhole” Windows service: it starts with the computer and restarts after a failure.
  • The proxy configuration script, for your account.
  • Your network card’s DNS pointed at AdHole, with your router as a fallback.
  • The icon near the clock and the Start menu shortcuts.
  • AdHole’s folder in the command path: adhole works in any command prompt opened after installation.

Good to know

Firefox has its own certificate store. Type about:config in the address bar, search for security.enterprise_roots.enabled and set it to true. Or import C:\ProgramData\adhole\ca\adhole-ca.crt in Settings → Privacy & Security → Certificates → View Certificates → Authorities.

Page and YouTube filtering applies to the Windows account AdHole was installed from. The DNS filter covers the whole computer.

Linux

Install on Linux.

Use a terminal opened in your desktop session: that session holds the proxy setting and Chrome’s and Firefox’s certificate stores.

  1. Download the archive.

    adhole-1.5.8-linux-amd64.tar.gz for a PC, adhole-1.5.8-linux-arm64.tar.gz for a Raspberry Pi 4 or 5, or another 64-bit ARM board. Then check its SHA-256.

  2. Unpack it and run setup.

    In the folder where the archive is. On a Raspberry Pi, replace amd64 with arm64.

    tar xzf adhole-1.5.8-linux-amd64.tar.gzcd adhole-1.5.8-linux-amd64sudo ./adhole setup
  3. Read and accept the terms of use.

    setup shows the notice and where the terms of use are. Read them, then type yes to accept and install.

  4. Open the dashboard.

    “AdHole” in your applications menu, or adhole ui.

What setup changes

  • A systemd service, restarted automatically.
  • The certificate in the system store, and in Chrome’s and Firefox’s stores when certutil is present.
  • Port 53 freed (systemd-resolved’s local listener is turned off) and DNS pointed at AdHole, with your router behind it.
  • The proxy setting, under GNOME and KDE.
  • ufw or firewalld rules, if either is active.
  • “AdHole” in the applications menu, and the adhole command.

Good to know

  • If setup says certutil is missing, install libnss3-tools (Debian, Ubuntu, Mint) or nss-tools (Fedora), then run sudo adhole setup again.
  • On a desktop other than GNOME or KDE, set the proxy auto-configuration URL to http://127.0.0.1:8053/proxy.pac yourself.
  • Without systemd, sudo ./adhole run runs AdHole in the foreground.
  • On a Raspberry Pi without a screen, installed over SSH, no proxy is set: AdHole serves as the DNS filter for your home.
  • Don’t want AdHole to decrypt your pages? sudo ./adhole setup -no-proxy installs the DNS filter only: pages and YouTube are then not filtered, until the next update, which installs the certificate and sets the proxy.
  • Stop: sudo adhole arreter. Start again: sudo adhole demarrer. The two words are French for stop and start.

Android

Install on Android.

The app isn’t on Google Play. You take the file from the Android card above and open it on the phone itself.

  1. Download the APK.

    Take adhole-1.5.8.apk from the Android card, on the phone. Your browser warns that this kind of file can harm your device: that message appears for every file of this kind, and you choose to keep it.

  2. Allow that browser to install apps.

    Open the download. Android answers that the browser isn’t allowed to install apps: tap “Settings”, then turn on “Allow from this source”. The permission is given to that one app, and you can take it back afterwards.

  3. Install, past Android’s warnings.

    On a phone with Google services, Play Protect may offer to scan the app or advise against it: that is what it says about any app that doesn’t come from a store. Check the SHA-256 instead, then install.

  4. Accept the terms, then the prompt.

    The app shows its terms of use the first time it opens. It then asks Android for the connection it needs, and filtering starts.

What the app does on the phone

  • Filters domain names on the device, for every app, on Wi-Fi and on mobile data, with the same lists as the computer version.
  • Holds a local VPN that leads nowhere outside the phone: traffic goes through it, on the device, then leaves for its destination. No server of the publisher’s, no hidden IP address.
  • Cleans up the pages opened in your browsers — ad slots hidden, cookie banners refused, ads taken off YouTube videos — once you have turned page cleaning on and installed its certificate, from its settings.
  • Never opens other apps, nor the sites left encrypted: those connections are relayed as they are. With no certificate, or the setting off, no page is opened and no browser shows an error.
  • Keeps a notification up while it filters: Android requires it of an app that holds that connection all the time.
  • Never installs an update by itself. In About, “Check for updates” tells you whether a newer version exists; you download it, Android installs it.

Installing on Android, step by step

SHA-256

Check the file before you run it.

Every file has a SHA-256 checksum, published in the SHA256SUMS file and shown in the cards above. If yours matches, your file is the one we publish, byte for byte.

On Windows

Open PowerShell from the Start menu and paste this command. It reads the installer in your Downloads folder: change the path if you saved it elsewhere.

Get-FileHash "$env:USERPROFILE\Downloads\adhole-setup-1.5.8.exe" -Algorithm SHA256

The “Hash” line must match the value in the Windows card. PowerShell writes it in capitals: the letters are the same.

On Linux

Download SHA256SUMS into the folder where the archive is, then run:

sha256sum -c SHA256SUMS --ignore-missing

The line for your archive must end with “OK”.

If the checksums differ, don’t run the file. Delete it and download it again from this page.

SmartScreen

“Windows protected your PC”: why, and what to do.

AdHole’s installer isn’t signed with a publisher certificate, a cost this free software hasn’t taken on. So Windows warns that it doesn’t recognise the program, and its permission prompt shows “Publisher: Unknown”.

The warning doesn’t mean the file is dangerous, nor that it’s safe: it means Windows can’t vouch for it. To make sure your file is the one we publish, compare its SHA-256 checksum with the published one. If you’re not comfortable with that, don’t install it.

The warning, window by window

Uninstall

Uninstall it at any time.

Windows: Settings → Apps → Installed apps → AdHole → Uninstall. The uninstaller then offers to delete the data folder: accept unless you plan to reinstall, since that folder holds the certificate’s private key.

Linux: sudo adhole teardown, then sudo rm -rf /var/lib/adhole to delete the data folder.

Uninstalling removes the certificate, the proxy, the DNS setting, the firewall rules and the service. On Windows, it also takes AdHole’s folder out of the command path.

Release notes

What’s in this version.

Version 1.5.8, published on 2026-09-25. The release notes list what it contains and what changed.

Installing means accepting the terms of use. What the program does with data: the privacy notice.

Read the release notes