I use pi hole in a lxc-container and dnsmasq on my host where wifi & ethetnet-clients got their ip-settings and pihole as dns-server (dns-forwarding is blocked by iptables).
Pihole uses host-dnsmasq where i have blocked additional domains (like facebook).
How do you block dns-forwarding by iptables?
Simply just drops ingoing/outgoing packets on port X?
I would like to achieve ads free youtube, facebook, spotify, and so in lan.
While abroad it would be nice surfing via 4G through my OpenVPN lxc-container. ( of course after covid19 calms down )
For spotify there is git called spotify-adblock-linux, but didn’t test it yet!
Yet another resource you could look into is ‘NextDNS’.
This is a professional service (which is free up to a certain amount of dns requests – which most home networks won’t go over). One needs to make an account on their page.
It works as an adblocker and it makes usage of https (so that your dns requests are encrypted for more privacy).