Standalone PowerShell script that blocks telemetry, analytics, and third-party tracking domains on Windows via the hosts file — with automatic backups, a strict whitelist, a dry-run preview, one-click restore, and an integrity checker so the block never silently drifts out of sync.
Nothing is guessed. A strict whitelist protects activation/licensing/update domains by exact match (never a substring match), every real change is backed up first, and the active block can be verified against the expected list at any time.
- Overview
- How it works
- What gets blocked
- What is never blocked (whitelist)
- Safety guarantees
- Prerequisites
- First run
- Menu reference
- Command-line parameters
- Files written by the script
- Multi-machine deployment
- Troubleshooting
Block-Telemetry_v5_2.ps1 edits one file only: the Windows hosts file (C:\Windows\System32\drivers\etc\hosts). It appends a clearly marked block of 0.0.0.0 <domain> entries for known telemetry, analytics, and tracking domains, so that DNS resolution for those domains fails locally — no traffic reaches them.
It does not touch the registry, does not stop any Windows service, does not install anything, and does not modify any file other than hosts (plus its own backups/logs/reports on the Desktop).
The script runs as an interactive menu — there is no one-shot "just clean it" command line invocation for the blocking action itself (only -SelfTest is a pure CLI flag). This is intentional: modifying hosts is a standing change (unlike a one-off cleanup), so the script keeps a human in the loop for applying, updating, and restoring it.
-
All changes live inside a single clearly delimited block in
hosts:# === BLOC TELEMETRIE - Ne pas modifier manuellement === # Généré le 18/08/2026 10:00:00 # Pour restaurer : relancer ce script et choisir option 5 # # -- Microsoft Telemetrie -- 0.0.0.0 vortex.data.microsoft.com 0.0.0.0 telecommand.telemetry.microsoft.com ... # === FIN BLOC TELEMETRIE ===Everything outside these two markers is left completely untouched — your own manual
hostsentries, entries from other tools, everything. -
Before any write to
hosts, a timestamped backup is created inHosts_Backups(see Files written by the script). If the backup fails, the script refuses to modifyhostsat all. -
Domains already present anywhere in your
hostsfile (added manually or by another tool) are detected and skipped rather than duplicated. -
Restoring removes only the content between the two markers — your original
hostsfile (and anything else added since) is preserved exactly as it was outside that block.
15 categories, 228 domains in total:
Microsoft Telemetry — 80 domains
Windows diagnostic data (DiagTrack / vortex / watson pipelines), Office/ARIA telemetry pipeline, Windows Defender cloud telemetry only (not local protection), MSN/Cortana/Bing ad and suggestion endpoints, Xbox/Game Bar telemetry, OneDrive telemetry (not sync), Teams telemetry (not communication).
Excluded on purpose: windowsupdate.com, update.microsoft.com, msftconnecttest.com (required for updates and connectivity detection).
Microsoft Copilot Telemetry — 10 domains
Usage data, query and context telemetry sent to Microsoft/Bing servers. Copilot itself is not blocked functionally on machines that use it — only the analytics endpoints.
Microsoft Edge Telemetry — 8 domains
Relevant even if Edge is uninstalled — WebView2 and Edge leftovers can still reach these endpoints.
Google Analytics / Tracking — 14 domains
Google Analytics, Tag Manager, DoubleClick, Google Ad Services.
Excluded on purpose: google.com, googleapis.com, gstatic.com (required by many web apps and authentication flows).
Adobe Analytics / Stats — 15 domains
Adobe Analytics/Omniture, Adobe Audience Manager, Adobe Dynamic Tag Manager, Adobe Marketing/Advertising Cloud.
Excluded on purpose: adobe.com, adobelogin.com, adobegenuine.com, lcs-cops.adobe.com (activation, licensing, functional endpoints).
Third-party tracking — 46 domains
None of these belong to a locally installed app — they're only loaded by websites or apps to track you across sessions: ScorecardResearch, Quantcast, Chartbeat, Facebook/Meta tracking, Amazon Ads, Twitter/X Ads, Hotjar, Mixpanel, Segment, Criteo, Taboola, Outbrain, Rubicon/Magnite, PubMatic, OpenX, Moat, Google AMP, LinkedIn Insight Tag.
Crash reports — 8 domains
Sentry.io, Bugsnag — send stack traces and system data on app crashes. Informative but intrusive; note this can reduce the quality of app bug fixes since developers lose that diagnostic data.
Spotify Telemetry — 6 domains
Excluded on purpose: *.spotify.com (streaming, login, API), *.scdn.co (music CDN), accounts.spotify.com, api.spotify.com.
Brave Analytics — 7 domains
Mozilla / Firefox Telemetry — 9 domains
NVIDIA Telemetry — 9 domains
AMD Telemetry — 5 domains
Discord Telemetry — 3 domains
Steam / Valve Telemetry — 4 domains
GOG Galaxy Telemetry — 4 domains
Use menu option [1] at any time to print the complete, current list grouped by category, or [E] to export it to a text file.
71 domains are hard-coded into an absolute whitelist, checked by exact match only (never a substring/subdomain match — see the SelfTest section) — even if one somehow ended up in the telemetry list by mistake, it would never be written to hosts:
- Adobe activation, licensing, registration (
activate.adobe.com,genuine.adobe.com,lcs-cops.adobe.com...) - Microsoft Windows Update, activation, sign-in (
update.microsoft.com,login.microsoftonline.com,msftconnecttest.com...) - OneDrive sync, Xbox Live auth, Teams communication
- NextDNS (critical DNS service)
- Spotify streaming/auth/API,
scdn.coCDN - Brave and Mozilla/Firefox update & safe-browsing endpoints
- Steam platform and anti-cheat, NVIDIA/AMD driver updates
- Discord, GOG Galaxy, Visual Studio Code updates
- Epic Games (kept whitelisted as a zero-cost precaution even though not actively used, to avoid an accidental block if the list is reused or extended on another machine later)
| # | Guarantee |
|---|---|
| S1 | Automatic backup of hosts before any modification |
| S2 | Strict whitelist — no functional domain is ever blocked |
| S3 | Automatic backup rotation (last 10 kept) |
| S4 | Simulation mode (-DryRun from the menu) to preview without touching anything |
| S5 | Full built-in restore (single menu choice) |
| S6 | Unique marker in hosts to identify exactly what this script added |
| S7 | No registry changes, no services stopped, no drivers touched |
| S8 | Built-in "Update" option (restore + re-apply in one step) |
| S9 | Guaranteed UTF-8 without BOM encoding (compatible with PowerShell 5 and 7) |
| S10 | Duplicate check before writing (domains already present are skipped) |
| S11 | Conflict detection with other hosts-editing tools (CTT WinUtil, StevenBlack hosts, HostsMan, Spybot Anti-Beacon, MVPS Hosts...) |
| S12 | Active-block integrity check (expected domains vs. domains actually present) |
| S13 | Optional cleanup of external entries (outside this script's own block) |
- Windows 10 or 11.
- PowerShell 5.1 (built into Windows) or PowerShell 7+.
- Administrator rights. The script self-elevates if launched from a non-admin session (UAC prompt) — except for
-SelfTest, which runs read-only and does not require elevation. - Write access to
C:\Windows\System32\drivers\etc\hosts(standard on any admin session). - If the script is digitally signed (recommended in environments using
-ExecutionPolicy AllSigned/RemoteSigned): the signing certificate must be trusted on the target machine, otherwise PowerShell will refuse to run it.
-
Copy
Block-Telemetry_v5_2.ps1to the target machine. -
Open a PowerShell terminal (no need to run it as admin manually — the script self-elevates, except for step 3 below).
-
Run the logic self-test first — this is read-only, requires no admin rights, and does not touch
hosts:.\Block-Telemetry_v5_2.ps1 -SelfTest
Runs 7 checks: whitelist has no internal duplicates, no domain is both blocked and whitelisted, whitelist matching is exact (not by subdomain), the domain list builds without duplicates, the two markers are distinct, and both
Get-IntegrityStatus/Test-IsAlreadyBlockedrun without throwing. The script then exits without touching any files. -
Launch the script normally (it will prompt for elevation):
.\Block-Telemetry_v5_2.ps1 -
From the menu, preview what would happen without changing anything:
[4] Simuler sans modifier (DryRun)This prints every domain that would be added and every one skipped as a duplicate, exactly as option [2] would do for real, but writes nothing.
-
Optionally review the full domain list and the whitelist preview:
[1] Voir les domaines qui seront bloqués -
Apply the block for real:
[2] Appliquer le blocageThis creates a backup, writes the block to
hosts, flushes the DNS cache, and writes a JSON snapshot of the action. -
Confirm it's working: check option [A] (integrity) any time afterward, or from a different terminal:
Resolve-DnsName vortex-win.data.microsoft.com
should fail to resolve (or resolve to
0.0.0.0) once the block is active and the DNS cache has been flushed. -
To undo everything, use option [5] — this removes only this script's block, backing up the current state first, and leaves the rest of your
hostsfile untouched.
| Option | Action |
|---|---|
[1] |
Print the full list of domains that would be blocked, grouped by category, plus a preview of the whitelist |
[2] |
Apply the block for real (backup → write → flush DNS → JSON snapshot). If a block is already active, offers to update instead |
[3] |
Update the list (restore, then re-apply) — use after pulling a newer version of the script with additional domains |
[4] |
Dry-run: simulate option [2] without writing anything |
[5] |
Restore — remove this script's block only, original hosts content preserved |
[6] |
List available backups (timestamp, filename, size) with manual-restore instructions |
[7] |
Flush the DNS cache manually (ipconfig /flushdns) |
[8] |
Generate an HTML report |
[9] |
Detect conflicts with other hosts-editing tools, and optionally clean up entries outside this script's own block |
[A] |
Check integrity of the active block (expected domains vs. domains actually present — flags anything missing or extra) |
[E] |
Export the current active domain list to a .txt file on the Desktop |
[Q] |
Quit |
The menu header always shows the current status at a glance: whether a block is active, how many domains, when it was applied, and a compact integrity indicator (reusing the same check as option [A]) so drift is visible without digging into the menu.
| Parameter | Description |
|---|---|
-SelfTest |
Runs the 7 read-only logic checks described in First run and exits. No admin rights required, no files touched. |
Every other action (apply, update, dry-run, restore, reports, exports) is menu-driven — there are intentionally no equivalent CLI switches, since these are standing changes to a system file rather than one-off maintenance tasks.
| File / folder | Content |
|---|---|
%SystemRoot%\System32\drivers\etc\hosts |
The only file actually modified — telemetry-blocking entries appended inside the marked block |
%USERPROFILE%\Desktop\Hosts_Backups\hosts_backup_<timestamp> |
Full copy of hosts taken before every real write (rotated automatically, last 10 kept) |
%USERPROFILE%\Desktop\Block-Telemetry_Log.txt |
Plain-text action log (append-only) |
%USERPROFILE%\Desktop\Rapports_Maintenance\Block-Telemetry\Block-Telemetry_<timestamp>.json |
JSON snapshot written after every real action (Apply / Update / Restore) — action type, domain counts, per-category breakdown |
%USERPROFILE%\Desktop\Block-Telemetry_Export_<timestamp>.txt |
Only created via menu option [E] — plain-text export of the active domain list |
HTML report (menu option [8]) |
Visual report, generated on demand |
Nothing is written outside these locations. -DryRun (menu option [4]) and -SelfTest write no files at all — no backup, no log, no JSON snapshot.
The script is self-contained (no external dependencies). For a multi-machine rollout:
-
Distribute the
.ps1file to each target machine. -
Trust the signing certificate if a strict execution policy is enforced (
-ExecutionPolicy AllSigned/RemoteSigned), otherwise PowerShell refuses to run it. -
Run
-SelfTestfirst on each machine — it needs no admin rights and touches nothing, so it's safe to run before deciding whether to proceed. -
Because this script is interactive by design (menu-driven, no CLI flag to apply the block), it is not a drop-in candidate for a silent scheduled task the way a cleanup script would be. For unattended multi-machine deployment, consider either:
- running it once interactively per machine during provisioning/imaging, or
- extracting the domain list (
$TelemetryDomains/$AbsoluteWhitelist) into a separate non-interactive script tailored to your deployment pipeline if a fully silent rollout is required.
-
Backups, logs, and JSON snapshots are written to the profile of the user running the script — local to each machine, not centralized automatically.
A site or app stopped working after applying the block
First check option [9] (conflict detection) to rule out another tool having modified hosts. If the issue is really caused by this script, the safest fix is option [5] (Restore) to fully undo the block, then report which domain seems to be causing the problem — legitimate functional domains should already be in the whitelist, so this would point to a domain that needs to be moved there.
Option [A] reports missing or extra domains
"Missing" means a domain from the current script's list isn't present in the active block — usually because the script was updated with new domains since the block was last applied. Use option [3] (Update) to resync. "Extra" means something is in the block that the current script's list doesn't expect — could be a manual edit or a newer/older version mismatch; option [3] also resolves this by rebuilding the block from scratch.
The block doesn't seem to take effect right away
The script flushes the DNS cache automatically after every real change (or via option [7] manually), but some applications cache DNS resolutions internally on top of the OS cache — a full restart of the application (or occasionally the machine) may be needed for it to pick up the change.
-SelfTest reports a FAIL
All 7 checks are internal consistency checks on the domain/whitelist lists themselves (duplicates, contradictions, exact-match logic) — a FAIL here means the domain lists were edited in a way that introduced an inconsistency, not a system-level problem. Read the check's Detail output for the specific domain or count involved.
Restoring didn't fully clean up my hosts file
Restore only removes what's between this script's own markers. If entries were added outside that block (manually, or by another tool), they are intentionally left alone — use option [9] to detect and optionally clean up those external entries separately.
Block-Telemetry — hosts-file based, no registry changes, no services stopped, nothing installed.