Bundled rule lists
ClearDeck ships 452,521 ad, tracker and malware rules inside the app. A fresh install works with no list downloads at all.
- 452,521 entries
- 12 MB
- v202610090326
The five function modules
They split by what can actually be decided: hosts a hostname settles, and hosts that need the full address.
| Module | Layer | Entries | What it covers |
|---|---|---|---|
| Ad blocking | Domain | 81,143 | ad hosts, blocked for every app |
| Tracker blocking | Domain | 121,037 | tracking and analytics hosts, blocked for every app |
| Deep ad blocking | URL | 1,597 | ad slots that need the full path — requires deep inspection |
| Deep tracker blocking | URL | 9,538 | tracking links that need the full path — requires deep inspection |
| Malicious site blocking | Domain | 239,206 | malicious and phishing hosts, from a feed that carries no ads |
| Total | 452,521 | 12 MB (combined size of the rule files in the package) | |
Where the lists come from
All of them are public community lists, taken per purpose. Attribution and licences are on the licences page.
| Source | Used for |
|---|---|
| EasyList | ads |
| EasyList Ad Servers | ads |
| 217heidai/adblockfilters | ads |
| AWAvenue Ads Rule | ads · trackers |
| EasyPrivacy | trackers |
| AdGuard Tracking Protection | trackers |
| Hagezi Threat Intelligence Feeds (TIF, mini) | malware |
One hostname belongs to exactly one module
When the lists are generated, each hostname is assigned to exactly one module, with malware taking priority. That is what makes the blocked-breakdown donut meaningful — a domain is never counted twice, and never jumps between modules because it appears in two source lists.
The domain layer and the deep layer stack rather than replace each other: deep rules need deep inspection switched on and the certificate installed, and when they are not, the domain layer keeps working as before.
Offline, and the build never touches the network
Add your own lists
When the bundled ones are not enough, import your own: `.yaml`, `.txt` and `.mrs` are supported, with the kind detected on import (domain list, IP list, mixed list, or full URL matching) and the action (block or allow) shown before you commit. The per-file ceiling is 32 MB.
The limitations, stated
- False positives happen
- These are community-maintained lists and any of them can over-block. When an app "mysteriously cannot connect", check its access record and exclude it with an allow rule before concluding the app is broken.
- Domain grouping is approximate
- Grouping destinations by registrable domain uses a fixed table of common suffixes rather than the full Public Suffix List, so an unusual suffix can group imperfectly.
- The malware list carries no ads
- The threat feed itself contains no ad or tracker hosts, and that is guaranteed by construction: a hostname is assigned to one module only, with malware first. So turning "malicious site blocking" off cannot leak ads back in.
Get notified when ClearDeck launches
We are finishing the first release. Leave an email and we will tell you when it is ready — once, and nothing else.
Signups will open shortly.
Only used to tell you about the launch. No newsletter, no sharing.