Formats: plain CIDR/domain .txt, RouterOS import .rsc, machine .json · Selected RouterOS script generator · Health: status / status.json · Checksums: checksums.txt / checksums.json
Community-curated Antifilter prefixes from community.antifilter.download.
Community list; reviewed by Antifilter community, but still use as a broad routing list.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| https://community.antifilter.download/list/community.lst | url | 904 | ok | 2026-10-01T14:03:22Z | 1 | 14724 |
Community-curated Antifilter domains from community.antifilter.download/list/domains.lst.
FQDN/domain list. Good as an optional domain-based bypass source; not included in antifilter-plus CIDR aggregate.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| https://community.antifilter.download/list/domains.lst | url | 485 | ok | 2026-10-01T14:03:22Z | 1 | 7351 |
Telegram/Messenger prefixes from Telegram-related ASNs plus stable DC ranges.
Good fit for RouterOS policy routing; Antifilter community already contains the main Telegram IPv4 ranges too.
Meta/Facebook infrastructure. Instagram and Facebook are normally inside Meta/Facebook ASNs/CDNs.
Broad Meta/Facebook list; includes more than Instagram/Facebook only.
Broad Google infrastructure from AS15169 and Google Cloud/edge AS396982. AS36040 is intentionally kept in the separate YouTube CIDR list for a cleaner Google/YouTube split.
Very broad: includes Google services far beyond search/Gmail/Gemini. YouTube can still use general Google/CDN infrastructure, so this is a best-effort split rather than a perfect product boundary.
Practical YouTube/Google video CDN list from AS15169 + AS36040. This restores real YouTube playback paths while still excluding broad Google Cloud/edge AS396982 from the YouTube list.
Practical, not perfectly isolated: YouTube frequently uses Google core AS15169. This list can route some non-YouTube Google core services, but it does not include the broader Google Cloud/edge AS396982 set published in google.rsc.
Experimental narrow YouTube/Google video list from AS36040 only. Useful for testing minimal bypass, but can miss real YouTube playback paths served from Google core AS15169.
Experimental: less likely to route unrelated Google traffic, but known to miss some real YouTube/googlevideo/ytimg paths. Prefer youtube.rsc when playback stalls.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| AS36040 | ripe-asn | 142 | ok | 2026-10-01T14:03:26Z | 1 | 16661 |
Exact FQDN helper list for YouTube web, app/API, image and embed endpoints. Complements the narrower YouTube CIDR list.
Exact FQDN list only: RouterOS does not wildcard-match *.googlevideo.com, and clients using DoH/DoT or external DNS can bypass router-visible FQDN learning.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| generate_lists.py | local | 25 | local | 2026-10-01T14:03:22Z |
Exact FQDN list for Spotify web, API, playback control, images and CDN assets.
Exact FQDN list for RouterOS compatibility. The Akamai hostname is intentionally narrow to avoid routing unrelated CDN traffic.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| generate_lists.py | local | 20 | local | 2026-10-01T14:03:22Z |
X/Twitter infrastructure from Twitter/X ASNs.
May not cover every CDN edge used by X/Twitter outside its own ASN.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| AS13414 | ripe-asn | 29 | ok | 2026-10-01T14:03:26Z | 1 | 3869 |
Netflix/Open Connect infrastructure from Netflix ASNs.
Mainly Netflix/Open Connect; some app/API/CDN paths can still use third-party networks.
Di Labs aggregate CIDR list. Includes: antifilter-community, telegram, meta, google, narrower youtube CIDR, x-twitter and netflix.
Does not include domain/FQDN lists: antifilter-community-domains, youtube-domains, ai, openai, claude, gemini or custom-domains. Import them separately when rules reference those address-list names. Telegram CIDRs are inside antifilter-plus, but telegram.rsc is still useful when rules explicitly match address-list=telegram, for example router-originated Telegram Bot API/SOCKS traffic.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| list:antifilter-community | aggregate | 904 | derived | 2026-10-01T14:03:22Z | ||
| list:telegram | aggregate | 12 | derived | 2026-10-01T14:03:22Z | ||
| list:meta | aggregate | 115 | derived | 2026-10-01T14:03:22Z | ||
| list:google | aggregate | 720 | derived | 2026-10-01T14:03:22Z | ||
| list:youtube | aggregate | 141 | derived | 2026-10-01T14:03:22Z | ||
| list:x-twitter | aggregate | 13 | derived | 2026-10-01T14:03:22Z | ||
| list:netflix | aggregate | 23 | derived | 2026-10-01T14:03:22Z |
Domain/FQDN list for OpenAI and ChatGPT web/API services.
Domain/FQDN list: underlying IPs can be Google/Cloudflare/AWS/Azure and change frequently.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| generate_lists.py | local | 46 | local | 2026-10-01T14:03:22Z |
Domain/FQDN list for Anthropic and Claude web/API services.
Domain/FQDN list: underlying IPs can be Cloudflare/AWS/GCP and change frequently.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| generate_lists.py | local | 6 | local | 2026-10-01T14:03:22Z |
Domain/FQDN list for Gemini web/Android, AI Studio and related Google AI APIs.
Product-specific Android Gemini RPC frontends are included; generic android.googleapis.com is excluded. Google IPs overlap with broad google/youtube CIDR lists.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| generate_lists.py | local | 23 | local | 2026-10-01T14:03:22Z |
Combined domain/FQDN list for AI web/API services. Generated RouterOS .rsc uses FQDN address-list entries, not fixed CIDR ownership.
Combined AI FQDN list. For per-vendor routing, use openai.rsc, claude.rsc and gemini.rsc.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| generate_lists.py | local | 75 | local | 2026-10-01T14:03:22Z |
Manual FQDN list managed by @di_labs_lists_bot for site-specific bypass routing.
Exact FQDN list. Add domains via @di_labs_lists_bot; RouterOS imports custom-domains.rsc on Maverick-MK every 12 hours.
| Source | Kind | Items | Status | Checked | Attempts | Bytes/Error |
|---|---|---|---|---|---|---|
| telegram-bot-manual | manual | 51 | local | 2026-10-01T14:03:22Z |
⚠️ Minimal recommended setup: import antifilter-plus as the main CIDR list, ai as FQDN list for ChatGPT/Claude/Gemini, and if the router itself needs Telegram Bot API/SOCKS, a separate telegram for chain=output.
/system backup save name=pre-di-labs-lists /export file=pre-di-labs-lists
/tool fetch url="https://lists.di-labs.org/antifilter-plus.rsc" dst-path=di-labs-antifilter-plus.rsc mode=https /import file-name=di-labs-antifilter-plus.rsc /tool fetch url="https://lists.di-labs.org/ai.rsc" dst-path=di-labs-ai.rsc mode=https /import file-name=di-labs-ai.rsc /tool fetch url="https://lists.di-labs.org/telegram.rsc" dst-path=di-labs-telegram.rsc mode=https /import file-name=di-labs-telegram.rsc
Replace 192.168.0.0/16 with your LAN network. Bypass_VPN must be a real FIB routing table with a working default route via VPN/WireGuard.
/routing table add name=Bypass_VPN fib comment="Di Labs: VPN policy table" /ip route add dst-address=0.0.0.0/0 gateway=<wg-or-vpn-interface> routing-table=Bypass_VPN comment="Di Labs: default via VPN" /ip firewall mangle add chain=prerouting src-address=192.168.0.0/16 dst-address-list=antifilter-plus connection-state=new action=mark-connection new-connection-mark=Conn_Bypass passthrough=yes comment="Di Labs: mark antifilter-plus" add chain=prerouting src-address=192.168.0.0/16 dst-address-list=ai connection-state=new action=mark-connection new-connection-mark=Conn_Bypass passthrough=yes comment="Di Labs: mark AI FQDN" add chain=prerouting src-address=192.168.0.0/16 connection-mark=Conn_Bypass action=mark-routing new-routing-mark=Bypass_VPN passthrough=no comment="Di Labs: route marked connections"
For fail-closed via routing rules, use lookup-only-in-table for your LAN/VLAN and verify the VPN table has an active route first.
/ip firewall mangle add chain=output protocol=tcp dst-address-list=telegram dst-port=443 action=mark-routing new-routing-mark=Bypass_VPN passthrough=no comment="Di Labs: route router Telegram HTTPS"
Use the Selected RouterOS script generator to build a custom updater for exactly the lists your mangle rules use. File routeros-install.rsc remains the minimal default helper. Both include on-error handling, temp file cleanup, and size checks.
/tool fetch url="https://lists.di-labs.org/routeros-install.rsc" dst-path=routeros-install.rsc mode=https /import file-name=routeros-install.rsc /system script run di-labs-update-lists /system scheduler add name=di-labs-update-lists interval=12h start-time=startup on-event="/system script run di-labs-update-lists"
/ip firewall address-list print count-only where list=antifilter-plus /ip firewall address-list print count-only where list=ai /ip firewall address-list print count-only where list=telegram /ip firewall mangle print stats where comment~"Di Labs"
.rsc files first build and verify a reserved di-stage-* candidate, then merge all desired entries into the canonical list, and only afterwards remove obsolete records with comment prefix di-labs-auto. Manual entries are preserved. IPv4 uses /ip firewall address-list; IPv6 is published separately as *-ipv6.rsc.
FQDN/AI caveat: RouterOS resolves FQDN address-list entries via its own DNS. If clients use DoH/DoT, Secure DNS, or external DNS directly, ai/custom-domains may not resolve. Force DNS through the router, block DoT tcp/udp 853, manage browser DoH policies, or use a CIDR/proxy-client approach.