A Fluent-Design desktop application for managing the Windows hosts file โ part of the HOTS Tools family.
HOTS Hosts is a lightweight, feature-rich Windows application that lets you view, edit, and manage the system hosts file through a clean, modern GUI โ no more manually navigating to C:\Windows\System32\drivers\etc\ and fighting with Notepad permissions.
Version 2.0 was a ground-up rebuild: the interface moved from Tkinter to PySide6 with Fluent Design (QFluentWidgets), bringing a proper light/dark theme, custom accent colors, and a persistent side-navigation layout instead of pop-up dialogs.
Version 2.1 builds on that foundation with a hosts file lock, application blocking, DNS-over-HTTPS blocking in browsers, popular VPN client blocking, a password-protected uninstaller, and a significantly expanded Privacy module.
HOTS Hosts is the first release under HOTS Tools โ a small line of no-nonsense Windows utilities.
Built as a personal hobby project, released free under GPLv3.
Main window โ table view with live search and entry management
Parental Control โ category blocklists with Cloudflare Family DNS toggle
Privacy โ tiered telemetry controls with drift detection
Diagnostics โ "Check domains" scanning entries against public DNS
Diagnostics โ "Scan malware" heuristic engine flagging suspicious entries
- ๐ Real-time table view of all hosts entries โ active, disabled, and comments
- โ Add / Edit / Delete entries with a polished dialog
- โป Enable / Disable entries without deleting them (toggles the
#prefix) - ๐ Live search & filter across IP, hostname, and comment columns
- ๐ Bulk paste โ paste multiple
IP hostnamelines at once - ๐ Column sorting by any field
- ๐พ Auto-backup before every save โ rotating archive of the last 15 backups
- ๐ Backup Manager โ browse, restore, or delete any backup
- ๐ Diff preview โ see exact line-by-line changes before writing to disk
- โ Post-save verification โ confirms the file was written correctly
- ๐ 20 000 entry limit โ blocks saves that would freeze Windows DNS Client
- ๐ฅ Import any hosts-format
.txtfile - ๐ค Export to
.txt(hosts format) or.csv(with Status, IP, Hostname, Comment columns)
- ๐ Domain existence check โ queries Google/Cloudflare public DNS directly (in parallel, multi-threaded), bypassing the local hosts file; flags domains that no longer exist in DNS
- ๐ก Malware scanner โ a heuristic engine covering well over a dozen risk signals, including:
- Known system/payment domains redirected to a non-loopback IP
- Windows Update / antivirus update domains being blocked
- Entries redirecting to a public (non-private, non-loopback) IP
- Mass-redirect patterns (many domains pointing at the same IP)
- Hostnames that are raw IP addresses
- Cyrillic/Unicode homoglyph characters and zero-width characters hidden in a hostname
- Punycode (
xn--) hostnames - High-entropy, DGA-style hostnames (randomly-generated-looking labels)
- Typosquatting of well-known domains (fuzzy-matched against a known-safe list)
- Suspicious TLDs, unusually deep subdomains, and brand-impersonation / long-digit / long-label naming patterns
- Known-safe subdomains and CDNs are automatically whitelisted to cut down on false positives
- A per-entry ignore list so confirmed-safe results don't keep re-appearing in future scans
- ๐ก Built-in blocklist manager for 15 categories:
- ๐ฆ Twitter/X ยท ๐ธ Instagram ยท โถ YouTube ยท ๐ค Facebook ยท ๐ฌ WhatsApp
- ๐ต TikTok ยท ๐ฎ Twitch ยท ๐ป Snapchat ยท ๐ Pinterest ยท ๐ค Reddit
- ๐ Adult content ยท ๐น๏ธ Games ยท โ Torrent ยท ๐ Dating sites ยท ๐ฅ Random video chat
- Each category uses unique section tags โ categories never overwrite each other
- Toggle any category on/off with one click; DNS cache flushed automatically
- ๐ Cloudflare Family DNS โ one-click enforcement of DNS-level adult content blocking (1.1.1.3 / 1.0.0.3):
- Detects all active (operationally up) network interfaces natively via the Windows
iphlpapiAPI (GetAdaptersAddresses) โ nonetsh/PowerShell subprocess is spawned for detection, so it's instant and works identically regardless of Windows display language - Backs up original DNS settings per interface to
%APPDATA%\HOTS Hosts\dns_backup.jsonbefore switching - Restores previous DNS (or falls back to DHCP) when Parental Control is disabled
- State persists across HOTS sessions โ DNS remains protected even after the app is closed
- Detects all active (operationally up) network interfaces natively via the Windows
- ๐ Hosts file lock (new in 2.1) โ one click denies standard processes Write/Delete access to the hosts file (Windows ACL), so blocklists can't be edited or deleted from outside HOTS by a curious kid or by malware. Unlock any time a trusted program needs write access.
- ๐ซ Application blocking (new in 2.1) โ block specific programs (games, VPN clients, etc.) from launching at all:
- Image File Execution Options (IFEO) redirects the executable name to a non-existent path, so Windows refuses to start it โ silently, no error dialog
- Optional ACL deny on the exact
.exefile (Write + Delete + ExecuteFile) closes the simplest bypass (renaming the file), since NTFS permissions belong to the file object itself, not its current name - A built-in watchdog detects if a block was removed outside the app and warns you
- Scoped as a deterrent against casual/inexperienced bypass attempts (e.g. a teenager), not as protection against a technically sophisticated attacker copying the program elsewhere
- ๐ฅท Popular VPN client blocking (new in 2.1) โ one click blocks a curated list of 10 well-known VPN clients (NordVPN, ExpressVPN, ProtonVPN, and others), using the same IFEO + ACL mechanism as general Application blocking
- ๐ DNS-over-HTTPS blocking in browsers (new in 2.1) โ closes the DoH bypass (see "Known Limitations" below) at the source instead of relying on the user to disable it manually in each browser:
- Sets the same managed-browser Group Policy that organizations use via Group Policy โ Chrome, Edge and Brave get
DnsOverHttpsMode=off, Firefox gets itsDNSOverHTTPSpolicy disabled and locked - Written directly to
HKEY_LOCAL_MACHINE, so it can't be turned back on from inside the browser's own settings - A drift watchdog checks on launch whether a previously-enabled block was manually reversed (e.g. after a browser update) and lets you re-apply it with one click
- Per-browser toggle only shown for browsers actually installed on the machine
- Sets the same managed-browser Group Policy that organizations use via Group Policy โ Chrome, Edge and Brave get
โน๏ธ The telemetry/tracking-domain blocklist (previously listed as a 14th Parental Control category) now lives under Privacy, alongside the other telemetry tweaks โ see below.
Completely rebuilt from a single on/off switch into a tiered, granular control center covering 37 individual system tweaks, organized into four levels:
- Basic (13 tweaks) โ
AllowTelemetrypolicy,DiagTrackanddmwappushserviceservices, Windows experimentation/telemetry, advertising ID, Bing/search-box suggestions, tailored experiences, Consumer Features, Delivery Optimization P2P sharing, Windows Recall, feedback notifications, CEIP - Medium (12 tweaks) โ firewall rules blocking
CompatTelRunner.exe,devicecensus.exe,WerFault.exe, plus disabling 9 scheduled tasks (Compatibility Appraiser,ProgramDataUpdater,Consolidator,UsbCeip,QueueReporting,KernelCeipTask,Microsoft-Windows-DiskDiagnosticDataCollector,Siuf\DmClient,Siuf\DmClientOnScenarioDownload) - Advanced (5 tweaks) โ
WerSvc/PcaSvcservices, Activity Feed / Timeline, cross-device activity publishing and upload - Privacy+ (7 tweaks) โ
lfsvcgeolocation service,DisableLocationpolicy, implicit text/handwriting-input collection, personalization policy, cross-device clipboard, Find My Device
Each level shows "{active} of {total} active", and every individual tweak can be expanded, reviewed, and toggled on its own.
- ๐ก Known telemetry domains โ a 5th, separate hosts-file blocklist toggle (the domain list formerly surfaced under Parental Control) sits beneath the four tweak levels
- ๐ฉน Drift detection โ if Windows resets a protected setting (e.g. after a major update), HOTS flags it with a warning and lets you re-apply it with one click
- ๐ System Restore integration โ create a Windows System Restore point with one click before applying changes, plus a one-click option to remove Windows' restore-point creation frequency limit if it's blocking you
- ๐ซ Block System Restore tool (new) โ prevents the Windows System Restore wizard (
rstrui.exe) from starting at all, closing a way to bypass parental controls (without this block, anyone with access to the PC could open System Restore and revert the whole system to before the blocks were set up). Restore points are still created automatically in the background, and you can still make one yourself from the button above even while this is active - ๐ Block your own domains (new) โ a free-text blocklist for anything not covered by the built-in categories: type in any domain (e.g.
example.com) and it's blocked at the hosts-file level, same as the Parental Control categories. The list is stored safely and survives a hosts file restore or uninstall - Saves the exact pre-change state before touching anything, so every level can be fully reverted
- Requires Administrator rights (UAC prompt on launch covers this)
- Intentionally scoped to the highest-impact, most reliable tweaks โ not a comprehensive privacy suite
- ๐ Light and Dark themes โ switch anytime in Options
- ๐จ 4 accent colors โ Gold, Red, Green, Blue
- ๐งญ Fluent Design navigation โ persistent side panel instead of pop-up dialogs
- ๐ Built-in update checker โ checks GitHub Releases and notifies you when a newer version of HOTS Hosts is available, with a direct link to download it
- ๐ 5 languages โ English (default), Polish, Franรงais, Deutsch, Espaรฑol โ switch in Options, saved across sessions
- ๐ Password protection โ optional SHA-256 hashed password, stored machine-wide in
HKEY_LOCAL_MACHINE(so it applies no matter which Windows account is used), required both to open the app and to uninstall it (the installer prompts for it before removing anything) - ๐ Raw text view โ edit the hosts file directly like Notepad, with syntax highlighting
- ๐ Geometry persistence โ remembers window size and position
- ๐ง File repair โ auto-fixes wildcard entries, removes duplicates and malformed lines
- ๐งน Restore default โ replaces current hosts with Microsoft's clean default (backup created first)
- ๐ Auto-elevation โ requests UAC Administrator rights on launch
- ๐ Single-instance guard โ launching HOTS Hosts while it's already running switches focus to the existing window instead of opening a duplicate
The Parental Control module blocks domains at the system level using the Windows hosts file, combined with Cloudflare Family DNS (1.1.1.3 / 1.0.0.3). This approach is effective but has inherent limitations you should be aware of:
Large platforms use hundreds of dynamically changing subdomains and CDN endpoints. A blocklist can never be 100% complete at any given moment.
- Built-in lists are updated with each HOTS release to keep up with infrastructure changes.
- You can add missing domains yourself โ either directly from the main table, or with the dedicated Block your own domains list under Privacy (see above), which survives a hosts file restore or uninstall.
Modern browsers (Chrome, Firefox, Edge, Brave) include a feature called Secure DNS / DNS-over-HTTPS (DoH). When enabled, the browser sends DNS queries directly to an external encrypted server, completely bypassing the system hosts file.
As of 2.1, HOTS Hosts closes this gap natively โ see DNS-over-HTTPS blocking in browsers under Parental Control above. It blocks DoH at the system policy level (the same mechanism organizations use via Group Policy), so there's no need to dig through each browser's settings manually, and it can't be silently turned back on from inside the browser.
The hosts file only affects the Windows PC it runs on. Phones, tablets, and traffic tunneled through a VPN service (i.e. once a device is actively connected to some VPN, wherever it is) will not be subject to these rules. This is separate from VPN client blocking (see Parental Control above), which stops specific VPN applications from launching on this PC in the first place โ it doesn't affect devices that aren't running HOTS.
- Download
HOTS_Hosts_setup.exefrom the Releases page - Double-click โ UAC will prompt for Administrator rights
- Follow the setup wizard. Done. No further setup required.
System requirements: Windows 10 or Windows 11, 64-bit. Windows 7/8/8.1 and 32-bit systems are not supported.
Since HOTS Hosts is a small independent project without a paid code-signing certificate, Windows SmartScreen may show a warning like "this app isn't commonly downloaded" the first few times it's downloaded. This is expected and does not mean the file is unsafe โ it simply means Microsoft hasn't yet built up a download reputation for it (this happens to every new, unsigned .exe, regardless of safety).
To proceed:
- If you see a screen titled "Windows protected your PC", click More info, then click Run anyway
- If you see the Edge/browser download warning shown above, click the "โฆ" (more actions) menu next to the downloaded file โ Keep โ Show more โ Keep anyway
If you'd rather verify the file yourself first, you can always build it from source instead โ see Option B below โ or inspect the full source code in this repository.
Requirements: Python 3.10+, PySide6, PySide6-Fluent-Widgets
pip install PySide6 "PySide6-Fluent-Widgets[full]"git clone https://github.com/darsono6/HOTS.git
cd HOTS
pythonw -m hosts_editor
โ ๏ธ Must be run as Administrator โ the hosts file is write-protected by Windows.
icon.ico # Windows Explorer/shortcut icon
hosts_editor_launcher.pyw # Single-instance guard + admin elevation entry point (build target)
hosts_editor/
โโโ __main__.py # Entry point โ UAC elevation, password prompt, language init
โโโ app.py # Main window (Fluent navigation shell)
โโโ core.py # Data logic โ parse, save, import/export, DNS, parental control
โโโ core_antispy.py # Privacy engine โ services, firewall rules, tasks, registry tweaks, hosts file lock
โโโ core_appblock.py # Application blocking โ IFEO redirection + ACL deny on target executables, VPN client bundle
โโโ core_doh.py # DNS-over-HTTPS blocking โ per-browser Group Policy enforcement + drift watchdog
โโโ core_restore.py # System Restore point creation & frequency-limit removal
โโโ bg_tasks.py # Background worker thread registry โ joined on app quit to avoid Qt teardown races
โโโ constants.py # Theme colors, accent presets, paths, settings load/save
โโโ widgets_qt.py # Reusable Qt/Fluent UI components โ buttons, dialogs, pages
โโโ dns_utils.py # DNS management โ native interface lookup, Cloudflare Family DNS orchestration
โโโ i18n.py # Multilingual string system (EN / PL / FR / DE / ES)
โโโ logo.png / logo.ico / logoS.png / logo1.png
โโโ blocklists/ # Plain-text domain lists for Parental Control & telemetry blocking
โ โโโ adult.txt
โ โโโ telemetry.txt
โ โโโ youtube.txt
โ โโโ ...
โโโ dialogs/
โโโ entry_dialog.py # Add / Edit entry form
โโโ diff_dialog.py # Diff preview before save
โโโ backup_page.py # Backup Manager
โโโ diagnostics_page.py # Domain check & malware scan
โโโ parental_page.py # Parental Control panel โ categories, hosts file lock, app blocking
โโโ privacy_page.py # Privacy / telemetry control center โ restore point tools, custom domains, tiered tweaks
โโโ custom_domains_dialog.py # Editor for the "Block your own domains" free-text list
โโโ _doh_card.py # DNS-over-HTTPS blocking card (per-browser toggles + watchdog)
โโโ export_dialog.py # Export to .txt / .csv
โโโ language_dialog.py # Language selection
โโโ accent_dialog.py # Accent color picker
โโโ support_page.py # Support / donate window
โโโ about_page.py # About & update checker
โโโ password_dialog.py # Set / verify startup password
โโโ _*.py # Shared/internal helpers for the pages above
The interface language can be changed in the Options โ Language panel.
The selected language is saved to %APPDATA%\HOTS Hosts\settings.json and applied on the next launch โ including the startup password prompt.
| Code | Language |
|---|---|
en |
English (default) |
pl |
Polski |
fr |
Franรงais |
de |
Deutsch |
es |
Espaรฑol |
All UI strings, dialogs, error messages, column headers, and system comments (e.g. Parental Control entries in the hosts file) are fully translated.
HOTS Hosts is provided in good faith but without any warranty. The author is not responsible for any damage, data loss, system issues, or other consequences resulting from the use of this application. Modifying the hosts file affects system-level network resolution โ use with care. You use this software at your own risk.
If HOTS Hosts saves you time or you simply want to say thanks:
Website: hotstools.com
PayPal: paypal.me/darsonodark
Support: hots.support@gmail.com
No registration required. Any amount is appreciated.
GNU General Public License v3.0 ยฉ 2026 Darsono