The short version

  • Every connection your network makes starts with a name lookup.
  • Pi-hole runs on a Raspberry Pi, a VM, or a Docker container on hardware you already own.
  • Once even a few employees are working from home or on the road, a LAN-only resolver misses them entirely.

01The cheapest privacy-clean lens on exactly which sites and services your network actually reaches

Every connection your network makes starts with a name lookup. Before a browser loads a page, before Teams or Slack phones home, before a device phones out to a cloud update server, it asks DNS: "What's the IP for this hostname?" That moment — the query — is all you need. Log it, and you have a near-complete record of which domains every device on your network has tried to reach, with no packet capture, no TLS interception, no content exposure whatsoever. It's the lightest-weight usage-visibility technique that exists, and it works across every protocol, not just HTTP.

Abstract amber-on-black visualisation of DNS lookups as points of light along branching paths on a dark grid
Pi-hole dashboard screenshot showing per-client query breakdown and top domains

02Pi-hole: Self-Hosted DNS Logging for the LAN

Pi-hole runs on a Raspberry Pi, a VM, or a Docker container on hardware you already own. Point your DHCP server at it as the DNS resolver, and every device's queries flow through it automatically — no agent to install anywhere. In its web dashboard you get per-client query logs, domain-level breakdowns, and a clear picture of top talkers in DNS terms: which clients are the noisiest, which domains are queried most, and which ad-tracking or telemetry domains are being hit across the estate.

The real value for usage monitoring sits in the Long-term Statistics and per-client views. You can see that a particular workstation resolved *.sharepoint.com 400 times this morning and stun.l.google.com continuously — a flag that a video call ran for hours. A spike in queries to an unfamiliar CDN hostname can surface shadow-IT: a SaaS app nobody told IT about. Pi-hole's blocking feature is optional; you can run it purely in passive logging mode if your goal is visibility, not filtering.

Privacy posture is strong: you're reading DNS metadata — hostname, timestamp, source device — not payload. You never see what was in the request. The appropriate guardrail is treating the query log as internal operational data, not as a tool for profiling individual staff behaviour, and documenting that policy clearly.

Limitation: Pi-hole only sees queries that hit your resolver. A device hard-coded to 8.8.8.8 or using DNS-over-HTTPS to its own cloud resolver bypasses it. Firewall rules that intercept or block port 53 and force DoH traffic through a single gateway close that gap; OPNsense and pfSense both have good guides for this.

03NextDNS: Cloud DNS That Follows Remote Users

Once even a few employees are working from home or on the road, a LAN-only resolver misses them entirely. NextDNS solves this by acting as a cloud resolver your devices or routers point to explicitly. Set up a profile, configure your devices or deploy a small client, and you get the same per-device query log — accessible in the NextDNS dashboard from anywhere — covering every network those devices are on.

For a small office with a hybrid or remote workforce, NextDNS offers something Pi-hole can't match without a VPN: unified, per-device visibility regardless of where the machine is sitting. Its analytics views show top domains, top devices, query categories, and blocked requests if filtering is enabled. It also speaks DNS-over-HTTPS and DNS-over-TLS natively, so query traffic itself is encrypted in transit, which matters for remote workers on untrusted Wi-Fi.

The trade-off is that query data moves to NextDNS's infrastructure — their privacy policy and data-retention settings are worth reading and configuring before deployment. They do offer a configurable log retention period down to one hour, and a no-log mode, giving you control over what's stored.

Abstract amber-on-black field of scattered points of light connected by faint lines
NextDNS analytics dashboard showing device list and query categories

04What DNS Visibility Tells You (and What It Doesn't)

DNS logs surface which domains were queried, how often, and by whom — enough to identify the heaviest-querying applications and clients, flag shadow IT, and audit which cloud services the estate depends on. They don't tell you how much data was transferred; for that, pair DNS visibility with NetFlow or SNMP polling from your router. Together, the two sources answer both "what were people reaching?" and "how hard were they hitting it?" — the core questions of any usage-monitoring deployment — without touching a single byte of content.

A Pi-hole log alongside a simple NetFlow analyser like ntopng, or even a pfSense traffic graph, gives a small-office IT admin a clear, defensible, privacy-respecting picture of internet usage at very low cost and complexity.

Simple diagram of devices routing through a DNS resolver with a firewall blocking bypass attempts
DNS traffic routed through Pi-hole or NextDNS, with port 53 bypass blocked at the firewall

05Tools & references mentioned