Ad blockers are often thought of as a convenience: fewer banners, fewer pop-ups, cleaner pages. They can also be a genuine layer of protection. US government agencies have pointed to ad blocking as a way to reduce exposure to malicious advertising, and the same tools can cut down on third-party tracking and make pages load faster. But not every blocker works the same way, and a badly chosen one can create the very privacy problem you were trying to avoid. This guide explains how ad blockers work, the main types, what changed for Chrome extensions, and what to check before you install one.
How ad blockers work
Almost every ad blocker works from lists of rules. When a page loads, it often asks other servers for scripts, images and tracking pixels. The blocker compares those requests, or the domain names behind them, against its lists and stops the ones that match known ad, tracking or malicious sources. Some blockers also hide page elements that are left behind once an ad is blocked, so you do not see empty boxes.
Where that check happens is what separates the different types. It can happen inside the browser, inside an app on your device, or at the network level when your device looks up a domain name. Each position has trade-offs in how much it can see, how much it can block, and how much you have to trust it.
The main types of ad blocker
Browser extensions
Extensions sit inside a single browser and can see and filter the pages you visit there. They are the most common type and usually the easiest to install and switch off for a particular site. AdGuard, for example, says its browser extensions are free and available for Chrome, Firefox, Safari, Edge and Opera, and notes that an extension works only within the browser it is installed in. Total Adblock offers extensions for Chrome, Edge, Safari and Opera, says it blocks intrusive ads, flashing banners, third-party cookies and hidden trackers, and states that a subscription is required for full access.
Device apps
A standalone app can filter traffic beyond one browser. AdGuard says its paid desktop and mobile apps block ads, trackers and phishing "in browsers and apps", which an extension cannot do. The trade-off is that a system-wide app needs deeper access to your device, so trust in the vendor matters even more.
DNS-level blocking
Every time your device visits a site it first looks up the domain name using DNS. A DNS blocker refuses to give a working address for domains on its blocklist, so the request never gets made. AdGuard describes its AdGuard DNS service as blocking ads and trackers "at the network level", and AdGuard Home as a network-based option that can run for a whole household. DNS blocking covers every app on the device or network, but it works on whole domains: it cannot remove an ad served from the same domain as the content you want.
Blocking built into a VPN
Several VPNs include a DNS-based blocker. Private Internet Access explains that its MACE feature returns a non-routable address for unwanted domains, so your browser cannot reach them, and says you must be connected to the VPN for MACE to work. PIA also says it does not edit the public lists it uses and therefore does not check for "acceptable" ads. CyberGhost says its Content Blocker blocks DNS requests for known domains associated with malware, trackers and ads. This approach is convenient if you already use a VPN, but it shares the limits of any DNS blocker and only works while the VPN is on.
Browsers with blocking built in
Some browsers block by default. Brave says its Shields feature blocks third-party ads and trackers on every page, blocks cross-site cookies, randomises some browser features to resist fingerprinting, and can warn about phishing and malware sites. Built-in blocking means one less add-on to trust, though you are tied to that browser's choices.
What Manifest V3 changed for Chrome extensions
Chrome extensions are built on a platform Google calls the manifest. Google's developer documentation describes Manifest V3 as the latest version, aimed at privacy, security and performance. The change that matters most for ad blockers is that Google deprecated the blocking version of the webRequest API, which let an extension inspect and stop each network request itself. Extensions are now expected to use the declarativeNetRequest API instead.
With declarativeNetRequest, the extension hands Chrome a set of rules and Chrome applies them. Google says this lets extensions "modify network requests without intercepting them and viewing their content, thus providing more privacy." The cost is flexibility. Rules are capped: Google's documentation says enabled static rulesets are guaranteed at least 30,000 rules, with up to 30,000 dynamic rules for "safe" actions such as block and allow, and no more than 1,000 regular-expression rules per extension. Manifest V3 also removes the ability for extensions to run remotely hosted code, so an extension can only execute code included in its package and reviewed by the Chrome Web Store.
The older platform is gone. Google's deprecation timeline says Manifest V2 extensions are now disabled for all Chrome users, cannot be turned back on, and have been removed from the Chrome Web Store. If you use Chrome, any extension you install today is a Manifest V3 extension. In practice that means a little less room for very large or highly customised filter lists, and in exchange, an extension that cannot see the contents of your requests just to block them.
Why security agencies mention ad blocking
Malicious advertising, or malvertising, is the use of malicious or hijacked ads to spread malware. CISA's guide on securing web browsers and defending against malvertising explains that such ads are inserted into legitimate ad networks and can trigger a forced redirect or load a malicious payload. Its recommendations include deploying ad-blocking software, which it says reduces the risk of malicious ads and redirects to phishing sites, speeds up page loading and reduces data collection by third parties. It also recommends protective DNS to stop lookups of known malvertising domains.
The FBI has issued a public service announcement warning that criminals buy search engine ads that impersonate real brands and lead to sites hosting ransomware or stealing logins. Among its tips: use an ad-blocking extension when performing internet searches, and type a business's web address directly rather than clicking an ad.
Neither agency presents ad blocking as a complete defence. It works best alongside an up-to-date browser and operating system, careful downloading, and a healthy suspicion of links that promise too much.
Privacy and speed benefits
Many web pages load third-party code alongside their own content: ad scripts, analytics and tracking pixels. Blocking the ones you do not need has two practical effects that CISA lists among the benefits of ad blocking: faster page loading, and less data collected about you by third parties. PIA makes a similar point about its own DNS approach, saying it may be faster and more memory efficient because the browser is no longer comparing each address against thousands of rules, and that on mobile it may help reduce battery drain depending on use. These are vendor and agency statements rather than guarantees, and the effect on any one site depends on how much third-party code it loads.
Downsides and what to check before you install
Broken pages
Blockers sometimes catch things a site needs, such as a login form, a comment box or a payment widget. Good blockers make it easy to pause blocking for a single site. If something stops working, try that before anything else.
Supporting the sites you value
Many publishers rely on advertising to pay for free content. Many blockers let you allow ads on specific sites, which is a fair way to support the ones you read regularly while keeping protection elsewhere.
Blockers that are themselves a risk
This is the point most people overlook. CISA's guide warns that ad-blocking browser extensions "operate with high levels of privilege" and can access all traffic between the browser and the network, which would let a malicious one collect data. It also notes that some extensions have accepted payment from advertisers to allowlist their ads. Before installing, check:
- Permissions. Google's Chrome Web Store help explains that the permission to read and change your data on all websites gives access to every page you visit, including your bank and social accounts. An ad blocker legitimately needs broad access, so the question is whether you trust the publisher with it.
- The publisher. Look for a named company, a real website, a privacy policy and a history of updates. Be wary of copycat names.
- The business model. Find out how the blocker makes money: a subscription, a paid upgrade, or allowing certain ads. If it is free with no clear model, ask why.
- Where it works. An extension covers one browser; a DNS or VPN blocker covers apps too but works on whole domains and, for VPN features, only while connected.
Free or paid?
Free blockers, and free built-in browser protection, cover the basics well for many people. AdGuard, for example, offers its browser extensions free and charges for apps that add features such as in-app blocking, DNS protection and a firewall. Paid products tend to add coverage across more devices and apps, extra features and support. VPN-bundled blockers make most sense if you already want a VPN for other reasons. Whichever you choose, read the vendor's own pricing and feature pages at the time you buy, because what is included changes.
Compare your options
Start with how you browse: one browser on one computer, or many devices and apps. Then choose the type that fits and check the publisher before you install. To see how Total Adblock, CyberGhost, Private Internet Access and AdGuard compare on features and coverage, see our ranking of the best ad blockers.