An evidence-annotated DNS blocklist for LG webOS TV telemetry — the data your TV sends home about what you watch and do — plus ads and phone-home traffic. It is for LG TV owners who run a DNS blocker (Pi-hole, AdGuard Home, NextDNS) and want the TV to stop reporting home without breaking the apps they use.
Not affiliated with LG Electronics. LG is a trademark of LG Corp.
Built by watching a real LG G1's network traffic and DNS logs, cross-checked against public reports. Every entry notes what it blocks and the evidence behind it — observation, not speculation. Method and replication steps: docs/methodology.md.
| SAFE | STRICT | |
|---|---|---|
| Blocks | Telemetry, ads, and ACR (Automatic Content Recognition — the TV's "what are you watching" reporting) | Everything in SAFE, plus firmware OTA (over-the-air) updates, ThinQ cloud sync, and LG Channels |
| For | Almost everyone | Privacy-focused users who want the TV to fully stop talking to LG |
| Cost | Streaming apps, Content Store, and app updates keep working (verified on an LG G1) | Those services stop working on purpose |
What breaks in STRICT (read this):
| Feature | SAFE | STRICT |
|---|---|---|
| Netflix / Prime / HBO / YouTube | works | works |
| LG Content Store | works | may degrade (carve-out recipe) |
| Firmware OTA updates | works | blocked |
| ThinQ app / voice assistant cloud sync | works | blocked |
| LG Channels | works | blocked |
| LG account login | works | may fail |
Pick a tier above, then load the matching file into your blocker. Step-by-step walkthrough per blocker, with checks and uninstall steps: docs/install.md.
| Your blocker | SAFE | STRICT |
|---|---|---|
| Pi-hole (v6) | safe-domains.txt | strict-domains.txt |
| AdGuard Home | safe-adblock.txt | strict-adblock.txt |
| dnsmasq | safe-dnsmasq.txt | strict-dnsmasq.txt |
Rooted TV /etc/hosts |
safe-hosts.txt | strict-hosts.txt |
NextDNS has no custom list URLs, and its web UI denylist takes one domain per entry: add a zone anchor itself (lgtvcommon.com) for whole-family reach, or bulk-add a list file with scripts/nextdns_sync.py through the free API (install steps). Unbound cannot read the domains file as-is: it needs conversion to local-data entries (recipe). uBlock Origin is a browser extension: it can subscribe to the adblock file for your browser, but it does not cover your TV.
Checksums: SHA256SUMS. Not in Germany? The exact-name lists only cover the regions present — see the region FAQ and scripts/localize.py.
The regex files cover the audited two-letter region prefixes. Two optional extras for Pi-hole: safe-wildcard.txt and strict-wildcard.txt. The safe one covers all country versions of a server in one line (de., fr., jp., ...), wherever you are. The strict one goes further and blocks whole server families, including parts we have never seen. Add them to Pi-hole's Regex filters; as a normal blocklist they won't work. AdGuard Home can use them too (wrap each line in slashes); NextDNS can't do regex, so check the FAQ for the closest thing. They get regenerated with every list change; the # Updated: header shows the date of the file you are looking at, and the update table covers what refreshes by itself and what you re-paste by hand. Full details in the FAQ.
Rooted TV (webosbrew / Homebrew Channel): mirror the -hosts.txt entries into /etc/hosts; a webosbrew init.d hook (a boot-time script) can rewrite that file at every boot (it lives in RAM and resets on reboot — mechanism: webosbrew filesystem-overlays). Mirror src/safe.txt, or src/strict.txt for the full lockdown. Separately, examples/webos-hooks/ ships a boot hook that forces all TV DNS through your resolver and drops encrypted DNS (DoT/DoQ, port 853) — the fix for the hardcoded-resolver bypass in caveat 1. Rollback and caveats: hook README.
Clock stuck at 2021-01-01 after a power loss? Blocking LG's time-sync can leave a cold-booted TV unable to fix its clock, which breaks strict-TLS downloads (e.g. Homebrew Channel error (0)). examples/webos-hooks/04-sync-clock.sh sets the clock from an HTTP Date: header at boot — details in the hook README.
- LG hardcodes public resolvers. webOS daemons have been observed using
8.8.8.8/1.1.1.1directly, and can use encrypted DNS, so a DNS blocklist alone is not a guarantee. Redirect outbound port 53 to your resolver and block port 853 at your firewall; on a rooted TV the DNS-egress hook does it on-device. A hosts file alone is not enough either — some daemons ignore it and query the TV's built-in DNS resolver directly. - Exact names, not wildcards. Entries name specific hosts, so whole-family coverage depends on enumeration. Exceptions to the exact-name rule: the shipped
-adblock.txtlists match subdomains via||name^, the-dnsmasq.txtfiles match them withaddress=/name/0.0.0.0, and the optional-wildcard.txtregex files generalise the audited two-letter region prefixes. They work wherever regex rules are supported (Pi-hole, AdGuard Home); the strict one also blocks whole server families. If your TV talks to an LG domain that is not on the list, open a new-domain issue — that is exactly how the list grows.
- Which tier should I use? SAFE for almost everyone; STRICT if you want the TV to fully stop talking to LG.
- Will this break Netflix / Prime / HBO / YouTube? No — verified on an LG G1.
- My TV ignores my Pi-hole / AdGuard. Why? webOS has a built-in DNS resolver and hardcoded fallback DNS; fix it at the router, or use the rooted hook. To check that the resolver itself blocks the listed domains, run
scripts/check_blocking.py. - I'm not in Germany — do the lists work? STRICT's adblock and dnsmasq lists are region-complete; the exact-name lists can be adapted with
scripts/localize.py --region <cc>. - I want STRICT but keep the LG Content Store. See the carve-out recipe.
- Why doesn't SAFE block all of
lge.com? That would kill the Content Store, updates, and account login along with the telemetry.
Full list: docs/faq.md.
- Methodology — how the data was collected and how to replicate it, including a firmware-diff recipe: docs/methodology.md.
- Upstream tracker — where these domains were submitted to community blocklists: docs/upstream.md.
- Source of truth — annotated lists: src/safe.txt, src/strict.txt, src/zones.txt. The comments tell you what every entry does and the evidence behind it, e.g.
snu.lge.com # STRICT: firmware OTA check server. - Contributing — evidence rules and how to add a domain, edit
src/only (CI regenerates the lists): CONTRIBUTING.md (templates: new domain, breakage). - Join as a maintainer — LG runs dozens of webOS versions and regional endpoints; captures or query logs from a C-series, G-series, or other model are exactly what this needs. Open an issue or submit a PR.
Content and generated lists: CC BY 4.0. Scripts and workflows: MIT.