The short version
- Every connection your network makes starts with a name lookup.
- Pi-hole runs on a Raspberry Pi, a VM, or a Docker container on hardware you already own.
- Once even a few employees are working from home or on the road, a LAN-only resolver misses them entirely.
01The cheapest privacy-clean lens on exactly which sites and services your network actually reaches
Every connection your network makes starts with a name lookup. Before a browser loads a page, before Teams or Slack phones home, before a device phones out to a cloud update server, it asks DNS: "What's the IP for this hostname?" That moment — the query — is all you need. Log it, and you have a near-complete record of which domains every device on your network has tried to reach, with no packet capture, no TLS interception, no content exposure whatsoever. It's the lightest-weight usage-visibility technique that exists, and it works across every protocol, not just HTTP.

02Pi-hole: Self-Hosted DNS Logging for the LAN
Pi-hole runs on a Raspberry Pi, a VM, or a Docker container on hardware you already own. Point your DHCP server at it as the DNS resolver, and every device's queries flow through it automatically — no agent to install anywhere. In its web dashboard you get per-client query logs, domain-level breakdowns, and a clear picture of top talkers in DNS terms: which clients are the noisiest, which domains are queried most, and which ad-tracking or telemetry domains are being hit across the estate.
The real value for usage monitoring sits in the Long-term Statistics and per-client views. You can see that a particular workstation resolved *.sharepoint.com 400 times this morning and stun.l.google.com continuously — a flag that a video call ran for hours. A spike in queries to an unfamiliar CDN hostname can surface shadow-IT: a SaaS app nobody told IT about. Pi-hole's blocking feature is optional; you can run it purely in passive logging mode if your goal is visibility, not filtering.
Privacy posture is strong: you're reading DNS metadata — hostname, timestamp, source device — not payload. You never see what was in the request. The appropriate guardrail is treating the query log as internal operational data, not as a tool for profiling individual staff behaviour, and documenting that policy clearly.
Limitation: Pi-hole only sees queries that hit your resolver. A device hard-coded to 8.8.8.8 or using DNS-over-HTTPS to its own cloud resolver bypasses it. Firewall rules that intercept or block port 53 and force DoH traffic through a single gateway close that gap; OPNsense and pfSense both have good guides for this.
03NextDNS: Cloud DNS That Follows Remote Users
Once even a few employees are working from home or on the road, a LAN-only resolver misses them entirely. NextDNS solves this by acting as a cloud resolver your devices or routers point to explicitly. Set up a profile, configure your devices or deploy a small client, and you get the same per-device query log — accessible in the NextDNS dashboard from anywhere — covering every network those devices are on.
For a small office with a hybrid or remote workforce, NextDNS offers something Pi-hole can't match without a VPN: unified, per-device visibility regardless of where the machine is sitting. Its analytics views show top domains, top devices, query categories, and blocked requests if filtering is enabled. It also speaks DNS-over-HTTPS and DNS-over-TLS natively, so query traffic itself is encrypted in transit, which matters for remote workers on untrusted Wi-Fi.
The trade-off is that query data moves to NextDNS's infrastructure — their privacy policy and data-retention settings are worth reading and configuring before deployment. They do offer a configurable log retention period down to one hour, and a no-log mode, giving you control over what's stored.

04What DNS Visibility Tells You (and What It Doesn't)
DNS logs surface which domains were queried, how often, and by whom — enough to identify the heaviest-querying applications and clients, flag shadow IT, and audit which cloud services the estate depends on. They don't tell you how much data was transferred; for that, pair DNS visibility with NetFlow or SNMP polling from your router. Together, the two sources answer both "what were people reaching?" and "how hard were they hitting it?" — the core questions of any usage-monitoring deployment — without touching a single byte of content.
A Pi-hole log alongside a simple NetFlow analyser like ntopng, or even a pfSense traffic graph, gives a small-office IT admin a clear, defensible, privacy-respecting picture of internet usage at very low cost and complexity.
