This is a good starting block-list: https://gist.github.com/wassname/78eeaaad299dc4cddd04e372f20...
This is a good starting block-list: https://gist.github.com/wassname/78eeaaad299dc4cddd04e372f20...
I use AdGuard Home, find it better then Pi-Hole, and it use DoT for queries (can do that with Pi-hole but you need to set up a proxy for that manually) so i just block anything in port 53 that the destination is not my internal DNS.
https://www.reddit.com/r/Roku/comments/602cnk/is_there_any_o...
It is not the ads server that is hardcoded. I doubt they will ever do that because that is hard to manage and does not escale.
So there will be traffic in port 53 that will be captured and redirected to my local dns server.
DoH is hard but most devices that i worrie about does not use it yet so i am not doing anything.
If this start becoming a problem either we will need to build a list of DoH server addresses to blacklist and this will be a cat and mouse game. Or you will need a https middlebox to look at what is in there to see if it is DoH and block or not, and that bring a whole lot of other problems.