Hướng dẫn

DNS riêng tư với AdGuard Home và Unbound

Trung cấp20 phút đọcCập nhật 12 tháng 5, 2026
Câu trả lời ngắn

AdGuard Home lọc và phục vụ DNS-over-HTTPS; Unbound phía sau thực hiện đệ quy đầy đủ để không máy phân giải ngược dòng nào thấy truy vấn của bạn. Trên phiên bản $4, cặp này dùng dưới 200 MB RAM và thay thế nguồn dữ liệu hành vi giàu nhất về bạn — máy phân giải của ISP.

01 Cài Unbound làm máy phân giải đệ quy

Bind it to localhost on a non-standard port so AdGuard Home can take 53.

apt install -y unbound
cat >/etc/unbound/unbound.conf.d/local.conf <<'EOF'
server:
  interface: 127.0.0.1@5335
  do-ip6: yes
  prefetch: yes
  hide-identity: yes
  hide-version: yes
  qname-minimisation: yes
EOF
systemctl restart unbound

02 Cài đặt AdGuard Home

The installer sets up a systemd unit and a web interface on port 3000 for initial configuration.

curl -sSL https://raw.githubusercontent.com/AdguardTeam/AdGuardHome/master/scripts/install.sh | sh -s -- -v

03 Trỏ AdGuard vào Unbound

In Settings → DNS, set the upstream to 127.0.0.1:5335 and disable all other upstreams. Full recursion means no third party sees your queries at all.

04 Bật DNS-over-HTTPS

Get a certificate with Certbot, then enable DoH on 443 and DoT on 853 in the encryption settings. Clients then reach the resolver privately in transit as well as at rest.

certbot certonly --standalone -d dns.example.com

05 Khóa chặt nó lại

Restrict access by client IP, or require DoH with a secret path. An open resolver is recruited into DNS amplification attacks within days and will be null-routed.

Câu hỏi thường gặp

Cái này có tốt hơn máy phân giải công cộng không?

Riêng tư, có — không bên thứ ba nào thấy truy vấn của bạn với đệ quy đầy đủ. Máy phân giải công cộng nhanh hơn nhờ kích thước bộ nhớ đệm; đánh đổi tốc độ lấy khả năng hiển thị.

Chi phí chạy bao nhiêu?

$4 mỗi tháng. Đây là cải thiện quyền riêng tư rẻ nhất có ý nghĩa.