Alien Privacy Box: network-wide DNS filtering you can see
The Alien Privacy Box is a maintained local DNS filter for homes and small businesses. Think of it as an internet address book with a blocklist. Devices on your network ask it where a domain lives. Allowed names get a normal answer. Listed advertising, tracking, telemetry and known-malicious names get a blocking response instead. That covers televisions, streaming boxes, speakers, appliances, phones and computers, including devices that cannot run a browser extension.
It will not make you anonymous or stop every tracker. It gives you one control point on your own network and a dashboard of what your devices ask for. Start with a suitability review.
What it is
At the centre is a maintained DNS policy that lives on your network, not in a browser. Depending on your equipment and the visibility you want, we run it on a dedicated filter such as Pi-hole, on a supported UniFi gateway, or as a designed combination of the two.
Pi-hole describes itself as a DNS sinkhole that blocks unwanted domains network-wide without installing software on every device (Pi-hole documentation). Its local dashboard shows which devices made requests, when, and whether each was allowed or blocked. See what Pi-hole blocks and what it misses.
What we configure
The final scope depends on your network and router. A deployment can include:
- dedicated local DNS filtering
- conservative, reviewed blocklists
- named device groups with different policies
- a secured local dashboard
- custom allow and deny decisions
- router and DHCP configuration
- IPv4 and IPv6 coverage checks
- configuration backup and recovery notes
- a post-installation validation review
- optional Unbound recursive DNS
- UniFi content filtering and custom domain policy on a supported gateway
- optional UniFi IPS and CyberSecure on compatible deployments
- optional firewall enforcement where the network supports it
- optional IoT guest-network or VLAN design
We document what was changed and how to bypass or restore DNS safely if the filter is unavailable.
What it can reduce
The filter blocks a connection only when all three are true:
- the device asks the local filter to resolve the domain;
- the domain is separately identifiable, with its own name rather than one shared with content you want; and
- the policy says that name should be blocked.
That covers a meaningful share of advertising, analytics and telemetry. It also exposes persistent background lookups worth investigating.
The Australian Signals Directorate describes protective DNS as a resolver designed to stop devices resolving known-malicious domains, which may stop malware receiving its instructions (ASD gateway security guidance). That is why we call maintained malicious-domain blocking an underrated early defence. It is a first layer only: it does not remove malware, and it only works while the device uses the protected resolver.
What it cannot stop
The Alien Privacy Box cannot reliably block:
- advertising served from the same domain as the content you want
- first-party activity inside an account you choose to use
- direct connections to an IP address
- traffic sent over a separate mobile connection
- every encrypted-DNS or VPN path
- data a company already holds about you
- collection that happens entirely on the device
Encrypted DNS inside an app can go around the local filter; Mozilla lists this as a risk for networks that rely on DNS filtering (Mozilla). Firewall rules (the rules on the doors between your network and the internet) can close some exits, but doing that well takes testing and maintenance.
Who it suits
The Alien Privacy Box may suit you if:
- you have several connected devices and want one network-level control
- you want to see what your smart TV and IoT devices ask for
- you value a local dashboard and a policy you control
- you want someone responsible for setup, testing and documentation
- you accept that occasional allowlisting will be needed
It is not the right product if:
- your goal is complete anonymity
- you expect every advert to disappear
- your router cannot hand out a reliable local DNS setting and cannot be replaced or supplemented
- your network cannot tolerate depending on a local DNS service
- nobody will approve updates or support after installation
Privacy inside the privacy system
DNS history is sensitive: the names your devices ask for can reveal your bank, health services, workplace and daily routine. So we set log retention deliberately; maximum logging is not the default. Any remote support access is documented with its authentication method, scope and end date.
You should know:
- what query information is stored
- how long it is kept
- who can open the dashboard
- what is included in backups
- what we can see during support
How a deployment runs
1. Suitability check
We review your router, how it hands out addresses (including IPv6), the devices that matter, how much outage you can tolerate and any business requirements.
2. Baseline
We list what must keep working (work logins, banking, streaming, gaming, smart-home control and software updates) so the installation is tested against real use.
3. Configure
The filter, network settings, device groups, administration access and recovery path are set up to the agreed scope.
4. Validate
We confirm the participating devices use the filter, test for obvious bypasses, run the baseline activities and fix false positives.
5. Handover
You receive the system map, support boundary, backup procedure, bypass steps and limitations, in plain English.
Optional add-ons
Unbound changes how allowed names are looked up: the filter does the full lookup itself instead of handing every question to one public resolver, reducing dependence on a single upstream provider. It does not make DNS anonymous. See Pi-hole and Unbound.
IoT isolation puts low-trust devices in a separate room on the network (a VLAN or guest network) so they cannot reach your laptops and storage. The room alone does not block a device's internet access or its vendor telemetry; that takes the filter and firewall rules too. See how to isolate IoT devices.
Home Assistant can bring supported device control and automation back onto your own network. A cloud-only device stays cloud-dependent.
Managed firewall policy enforces more rules on the doors between your networks and the internet, and adds configuration and support responsibility.
A supported UniFi gateway can combine DNS filtering, IoT zones, explicit outbound rules and IPS. IDS is an alarm that reports matching traffic; IPS can also stop it. CyberSecure is optional expanded threat intelligence on supported gateways: a subscription with documented cloud dependencies, not required for every UniFi protection. We confirm model support, current software, performance and Australian availability before proposing it. Where the hardware and maintenance arrangement fit, a properly configured UniFi gateway is the setup we recommend first. See our UniFi router security guide.
Frequently asked questions
Is this just a Raspberry Pi?
Hardware is only one component. The value is the network assessment, policy, configuration, testing, documentation, recovery path and agreed maintenance. The platform is chosen for your deployment.
Will it break websites or apps?
Any domain block can cause a false positive. We start conservatively, test the services you use and document how allowlisting works. There is no honest zero-breakage guarantee.
Can I see what my smart TV contacts?
You can see the DNS requests that reach the filter, by device and time. That does not reveal the contents of encrypted connections or prove what every domain is for.
Does it work away from home?
The base service protects devices while they use the configured network. Filtering a phone or laptop on mobile data needs a separate design, such as an approved secure tunnel; it is not automatic.
Does Alien IT keep my browsing history?
The deployment states its local log retention and any support access in writing. DNS logs stay on the system you control unless the agreed support or backup design says otherwise.
Do I need a separate Pi-hole if I already have UniFi?
Not necessarily. A supported gateway may provide the right filtering and enforcement on its own. Pi-hole still earns its place where richer DNS visibility, device groups or maintained-list flexibility justify a separate service. We work out which filter answers each device first, so two filters do not fight each other or muddle the logs.
Take back one control point
You cannot stop every company collecting data. You can stop giving every device at your place an unrestricted path to every destination. Call 02 9707 0999 or use the contact page to ask whether the Privacy Box fits.