Alien Privacy Box: network-wide DNS filtering you can see

The Alien Privacy Box is a maintained local DNS filter for homes and small businesses. Think of it as an internet address book with a blocklist. Devices on your network ask it where a domain lives. Allowed names get a normal answer. Listed advertising, tracking, telemetry and known-malicious names get a blocking response instead. That covers televisions, streaming boxes, speakers, appliances, phones and computers, including devices that cannot run a browser extension.

It will not make you anonymous or stop every tracker. It gives you one control point on your own network and a dashboard of what your devices ask for. Start with a suitability review.

What it is

At the centre is a maintained DNS policy that lives on your network, not in a browser. Depending on your equipment and the visibility you want, we run it on a dedicated filter such as Pi-hole, on a supported UniFi gateway, or as a designed combination of the two.

Pi-hole describes itself as a DNS sinkhole that blocks unwanted domains network-wide without installing software on every device (Pi-hole documentation). Its local dashboard shows which devices made requests, when, and whether each was allowed or blocked. See what Pi-hole blocks and what it misses.

What we configure

The final scope depends on your network and router. A deployment can include:

We document what was changed and how to bypass or restore DNS safely if the filter is unavailable.

What it can reduce

The filter blocks a connection only when all three are true:

  1. the device asks the local filter to resolve the domain;
  2. the domain is separately identifiable, with its own name rather than one shared with content you want; and
  3. the policy says that name should be blocked.

That covers a meaningful share of advertising, analytics and telemetry. It also exposes persistent background lookups worth investigating.

The Australian Signals Directorate describes protective DNS as a resolver designed to stop devices resolving known-malicious domains, which may stop malware receiving its instructions (ASD gateway security guidance). That is why we call maintained malicious-domain blocking an underrated early defence. It is a first layer only: it does not remove malware, and it only works while the device uses the protected resolver.

What it cannot stop

The Alien Privacy Box cannot reliably block:

Encrypted DNS inside an app can go around the local filter; Mozilla lists this as a risk for networks that rely on DNS filtering (Mozilla). Firewall rules (the rules on the doors between your network and the internet) can close some exits, but doing that well takes testing and maintenance.

Who it suits

The Alien Privacy Box may suit you if:

It is not the right product if:

Privacy inside the privacy system

DNS history is sensitive: the names your devices ask for can reveal your bank, health services, workplace and daily routine. So we set log retention deliberately; maximum logging is not the default. Any remote support access is documented with its authentication method, scope and end date.

You should know:

How a deployment runs

1. Suitability check

We review your router, how it hands out addresses (including IPv6), the devices that matter, how much outage you can tolerate and any business requirements.

2. Baseline

We list what must keep working (work logins, banking, streaming, gaming, smart-home control and software updates) so the installation is tested against real use.

3. Configure

The filter, network settings, device groups, administration access and recovery path are set up to the agreed scope.

4. Validate

We confirm the participating devices use the filter, test for obvious bypasses, run the baseline activities and fix false positives.

5. Handover

You receive the system map, support boundary, backup procedure, bypass steps and limitations, in plain English.

Optional add-ons

Unbound changes how allowed names are looked up: the filter does the full lookup itself instead of handing every question to one public resolver, reducing dependence on a single upstream provider. It does not make DNS anonymous. See Pi-hole and Unbound.

IoT isolation puts low-trust devices in a separate room on the network (a VLAN or guest network) so they cannot reach your laptops and storage. The room alone does not block a device's internet access or its vendor telemetry; that takes the filter and firewall rules too. See how to isolate IoT devices.

Home Assistant can bring supported device control and automation back onto your own network. A cloud-only device stays cloud-dependent.

Managed firewall policy enforces more rules on the doors between your networks and the internet, and adds configuration and support responsibility.

A supported UniFi gateway can combine DNS filtering, IoT zones, explicit outbound rules and IPS. IDS is an alarm that reports matching traffic; IPS can also stop it. CyberSecure is optional expanded threat intelligence on supported gateways: a subscription with documented cloud dependencies, not required for every UniFi protection. We confirm model support, current software, performance and Australian availability before proposing it. Where the hardware and maintenance arrangement fit, a properly configured UniFi gateway is the setup we recommend first. See our UniFi router security guide.

Frequently asked questions

Is this just a Raspberry Pi?

Hardware is only one component. The value is the network assessment, policy, configuration, testing, documentation, recovery path and agreed maintenance. The platform is chosen for your deployment.

Will it break websites or apps?

Any domain block can cause a false positive. We start conservatively, test the services you use and document how allowlisting works. There is no honest zero-breakage guarantee.

Can I see what my smart TV contacts?

You can see the DNS requests that reach the filter, by device and time. That does not reveal the contents of encrypted connections or prove what every domain is for.

Does it work away from home?

The base service protects devices while they use the configured network. Filtering a phone or laptop on mobile data needs a separate design, such as an approved secure tunnel; it is not automatic.

Does Alien IT keep my browsing history?

The deployment states its local log retention and any support access in writing. DNS logs stay on the system you control unless the agreed support or backup design says otherwise.

Do I need a separate Pi-hole if I already have UniFi?

Not necessarily. A supported gateway may provide the right filtering and enforcement on its own. Pi-hole still earns its place where richer DNS visibility, device groups or maintained-list flexibility justify a separate service. We work out which filter answers each device first, so two filters do not fight each other or muddle the logs.

Take back one control point

You cannot stop every company collecting data. You can stop giving every device at your place an unrestricted path to every destination. Call 02 9707 0999 or use the contact page to ask whether the Privacy Box fits.