Set Up System‑Wide Ad Blocking on Android with Nebulo (No Root)

13 min read Step‑by‑step guide to install Nebulo, configure DNS‑based ad blocking, test the setup and troubleshoot common issues on any Android phone without rooting. September 28, 2026 04:00 How to Set Up System‑Wide Ad Blocking on Android Using Nebulo (No Root)

Before you start

Installing Nebulo does not require root, but it does need a stable internet connection and the ability to grant the app a VPN‑style permission. Make sure your device is charged to at least 50 % or keep it plugged in, and back up any custom DNS settings you may have configured previously (e.g., in Settings > Network & internet > Private DNS). This backup can be a simple screenshot – you’ll need it if you ever want to revert.

  1. Charge your phone (≥50 %).
  2. Connect to Wi‑Fi or ensure mobile data is active.
  3. Open Settings and note the current Private DNS mode (if any).
  4. Disable any third‑party VPN or DNS‑changing apps that may interfere.

Why DNS‑Based Ad Blocking Works

Most ads are served from a handful of well‑known domains (e.g., ads.google.com, doubleclick.net). A DNS resolver translates a domain name into an IP address before the traffic leaves your device. By pointing your DNS queries to a resolver that returns a “null” address for known ad domains, the request never reaches the ad server, and the ad never appears.

Unlike per‑app blockers that rely on accessibility services, DNS‑based blocking works for every network‑enabled app – browsers, games, streaming clients, and even system‑level webviews. The trade‑off is that it cannot block ads that are embedded directly in the app package (e.g., hard‑coded banner images). For the vast majority of users, the reduction in visible ads and data usage is worth the small chance of a few missed ads.

About Nebulo

Nebulo is a lightweight Android app that acts as a local VPN tunnel and forwards DNS queries to a resolver of your choice. It ships with a curated list of ad‑blocking DNS providers (including AdGuard DNS and NextDNS) and lets you add custom servers. Because it uses Android’s built‑in VPN API, it does not require root, and the system treats it like any other VPN – you’ll see a key icon in the status bar while it is active.

The app also offers per‑app whitelisting, IPv6 support, and a built‑in test page to verify that the blocker is functioning. All of these features make Nebulo a solid choice for a “set‑and‑forget” ad‑blocking solution.

Step 1 – Install Nebulo

  1. Open the Google Play Store (or an alternative trusted store such as F‑Droid if you prefer the open‑source version).
  2. Search for Nebulo – DNS over HTTPS, DNS over TLS and tap Install.
  3. Wait for the installation to finish (typical size ~6 MB).
  4. After installation, tap Open to launch the app.

When you launch Nebulo for the first time you will be greeted with a short welcome screen that explains the VPN permission. Tap Continue to proceed.

Step 2 – Grant the VPN Permission

  1. A system dialog appears: “Nebulo wants to set up a VPN connection”. This is the standard Android VPN API; it does not create a traditional VPN tunnel to a remote server.
  2. Tap OK. If you see a warning about “This app may see all your network traffic”, read it – Nebulo only intercepts DNS queries, not the actual data payload.
  3. After granting permission, Nebulo will start its local VPN service and you should see the key icon in the status bar.

If the key icon does not appear, go to Settings > Apps > Nebulo > Permissions and ensure the “VPN” permission is enabled. Some manufacturers (e.g., Xiaomi’s MIUI) hide this under “Special app access”.

Step 3 – Choose an Ad‑Blocking DNS Provider

Nebulo offers several pre‑configured servers. For most users the AdGuard DNS (Family protection) profile provides a good balance of ad‑blocking and privacy.

  1. In Nebulo’s main screen tap the Servers tab at the bottom.
  2. Tap the + button to add a new server.Select Pre‑configured from the list of source options.
  3. Scroll to AdGuard DNS (Family protection) and tap it.
  4. Leave the default port (853) and protocol (TLS) unless you have a specific reason to change them.
  5. Tap Save. The new server appears in the list.
  6. Tap the server name to make it the active profile. A toast will confirm “Server set”.

When the server is active, Nebulo will automatically start filtering DNS queries. You can verify the active server by looking at the status line at the top of the app – it should read something like “Connected to AdGuard DNS (Family)”.

Step 4 – Enable Global Ad Blocking

  1. Return to the Home tab.
  2. Toggle the main switch labeled Enable Nebulo to the ON position.
  3. The key icon re‑appears (if it had disappeared) and the status changes to “Running”.

At this point every DNS lookup on the device is routed through the selected resolver, and any domain on the resolver’s blocklist will resolve to 0.0.0.0 (or an IPv6 equivalent). Most browsers will instantly stop loading banner ads, and many free apps will lose their ad‑pop‑ups.

Step 5 – Whitelist Apps That Need Direct DNS

Some apps – especially banking or corporate VPN clients – perform DNS pinning or rely on custom DNS servers. If you notice a “Cannot connect” error after enabling Nebulo, try whitelisting the offending app.

  1. Tap the Whitelist icon (a plus sign inside a circle) in the top‑right corner of the Home screen.
  2. You’ll see a list of installed apps. Scroll to the app that is failing (e.g., your banking app) and toggle the switch next to it.
  3. Return to the Home screen; the app will now bypass Nebulo’s DNS while the rest of the system remains protected.

Whitelisting is per‑app, not per‑process, so the app will always use the system DNS (usually your carrier’s) while Nebulo stays active for everything else.

Step 6 – Verify the Blocker Is Working

The easiest way to confirm that DNS‑based blocking is active is to visit a test page that lists known ad domains. Nebulo includes a built‑in test, but you can also use external sites.

  1. In Nebulo, tap the Test button (looks like a magnifying glass) on the Home tab.
  2. The app opens a WebView that loads https://adguard-dns.io/test/. The page will report “All tests passed” if the DNS resolver is correctly blocking ads.
  3. Alternatively, open Chrome and navigate to https://www.blockads.fivefilters.org/. The page will attempt to load a series of known ad scripts; a clean result means Nebulo is doing its job.

If you still see ads, double‑check that the active server is the one you added in Step 3 and that the main switch is ON. Some browsers cache DNS entries; clear the browser cache or restart the app to force a fresh lookup.

Advanced Options – Custom Blocklists and DNS‑Over‑HTTPS

Nebulo allows you to point to any DNS‑over‑TLS (DoT) or DNS‑over‑HTTPS (DoH) endpoint. If you prefer a self‑hosted resolver (e.g., Pi‑hole) or a privacy‑focused service like Quad9, you can add it manually.

  1. Tap Servers → + → Custom.
  2. Enter a name (e.g., “My Pi‑hole”).
  3. For DoH, set the URL field to something like https://dns.quad9.net/dns-query. For DoT, use the host name (e.g., dns.quad9.net) and port 853.
  4. Optionally enable Blocklists under the server’s settings and paste a URL to a public hosts file (e.g., https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts).
  5. Save and select the custom server.

Custom blocklists are plain‑text files with one domain per line. Nebulo merges them with the built‑in list, so you can add niche ad providers that the default list might miss.

Troubleshooting

1. No internet after enabling Nebulo

  • Cause: Some carriers block DNS‑over‑TLS on their network.
  • Fix: Switch the server protocol to DNS‑over‑HTTPS (DoH) or use a plain DNS (port 53) from a trusted provider.
  • Check: In Nebulo’s server settings, toggle “Use DoH” and enter a fallback DNS such as 8.8.8.8.

2. Certain apps still show ads

  • Reason: The app may use hard‑coded IP addresses or a built‑in ad SDK that bypasses DNS.
  • Work‑around: Install an app‑level blocker (e.g., Blokada) for that specific app, or consider a firewall solution like NetGuard.

3. VPN key icon disappears after a reboot

  • Cause: Android does not automatically restart VPN‑style apps.
  • Solution: Open Nebulo and toggle the main switch back ON. To automate, enable Start on boot in Nebulo’s Settings → Advanced.

4. DNS leaks – ads appear only on Wi‑Fi

  • Explanation: Some devices have a separate “Wi‑Fi only” DNS setting that overrides the VPN.
  • Fix: Go to Settings > Network & internet > Wi‑Fi > Tap your network > Advanced > IP settings → Static. Ensure the DNS fields are empty or set to the same provider you use in Nebulo.

When to Disable Nebulo

While Nebulo is safe for everyday use, there are scenarios where you may want to turn it off temporarily:

  • Connecting to a corporate VPN that requires its own DNS resolution.
  • Using a hotspot that forces a specific DNS server (some public Wi‑Fi networks block DoT/DoH).
  • Troubleshooting a network‑related issue – disabling Nebulo isolates whether the problem is DNS‑based.

To disable, simply toggle the main switch off. The key icon disappears, and your device returns to the system‑default DNS configuration.

Summary and best‑practice checklist

  • Install Nebulo from a trusted source (Google Play or F‑Droid).
  • Grant the VPN permission – Nebulo only intercepts DNS, not data.
  • Select a reputable ad‑blocking DNS server (AdGuard Family is a good default).
  • Enable the global switch and verify with the built‑in test page.
  • Whitelist any app that breaks after enabling Nebulo.
  • Optional: add custom blocklists or point to a self‑hosted resolver for extra control.
  • Periodically revisit the server list – blocklists are updated upstream.
  • Use the troubleshooting section if you lose connectivity or see DNS leaks.

By following these steps you’ll enjoy a cleaner, faster Android experience without the need to root or flash custom ROMs. Nebulo runs in the background with minimal battery impact, and because it relies on DNS rather than deep packet inspection, it respects the privacy of your actual traffic while still keeping those unwanted ads at bay.

User Comments (0)

Add Comment
We'll never share your email with anyone else.