if you have an extra raspberry pi laying around you can install an ad blocker for your entire network with pi-hole.
Oh, you don't have a DNS cache on your LAN? Strongly recommended for performance reasons, if not privacy as well. I don't remember what actual measurements I ended up with, but latency realmy hurts!
I run dnscrypt-proxy locally, encrypting (TLS) all my DNS traffic between me and OpenDNS, also giving me the option for my system resolver to give NXDOMAIN for any names on a local blacklist.
It was remarkably easy to setup, just install the package.
$ cat /etc/dnscrypt-proxy/blacklist
fbcdn.net
facebook.com
google-analytics.com
www.google-analytics.com[1]: https://two-wrongs.com/secure-dns-on-a-laptop-with-debian.ht...