Di Labs Lists

📋 17 lists 📊 4,448 entries ⏱ Updated: 2026-10-01T14:03:22Z UTC

Formats: plain CIDR/domain .txt, RouterOS import .rsc, machine .json · Selected RouterOS script generator · Health: status / status.json · Checksums: checksums.txt / checksums.json

🌐 Antifilter community

904

cidr ok

Community-curated Antifilter prefixes from community.antifilter.download.

Community list; reviewed by Antifilter community, but still use as a broad routing list.

Sources: url ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
https://community.antifilter.download/list/community.lsturl904ok2026-10-01T14:03:22Z114724

⭐ Antifilter community domains

485

domain ok

Community-curated Antifilter domains from community.antifilter.download/list/domains.lst.

FQDN/domain list. Good as an optional domain-based bypass source; not included in antifilter-plus CIDR aggregate.

Sources: url ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
https://community.antifilter.download/list/domains.lsturl485ok2026-10-01T14:03:22Z17351

🌐 Telegram

12

cidr ok

Telegram/Messenger prefixes from Telegram-related ASNs plus stable DC ranges.

Good fit for RouterOS policy routing; Antifilter community already contains the main Telegram IPv4 ranges too.

Sources: ripe-asn ×4 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS62041ripe-asn25ok2026-10-01T14:03:22Z13428
AS44907ripe-asn3ok2026-10-01T14:03:23Z1986
AS59930ripe-asn3ok2026-10-01T14:03:23Z1988
AS62014ripe-asn8ok2026-10-01T14:03:23Z11538

🌐 Meta / Facebook / Instagram / WhatsApp

115

cidr ok

Meta/Facebook infrastructure. Instagram and Facebook are normally inside Meta/Facebook ASNs/CDNs.

Broad Meta/Facebook list; includes more than Instagram/Facebook only.

Sources: ripe-asn ×2 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS32934ripe-asn569ok2026-10-01T14:03:23Z166444
AS63293ripe-asn174ok2026-10-01T14:03:23Z121171

🌐 Google / Google Cloud

720

cidr ok

Broad Google infrastructure from AS15169 and Google Cloud/edge AS396982. AS36040 is intentionally kept in the separate YouTube CIDR list for a cleaner Google/YouTube split.

Very broad: includes Google services far beyond search/Gmail/Gemini. YouTube can still use general Google/CDN infrastructure, so this is a best-effort split rather than a perfect product boundary.

Sources: ripe-asn ×2 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS15169ripe-asn1410ok2026-10-01T14:03:25Z1157602
AS396982ripe-asn3898ok2026-10-01T14:03:24Z1432501

🌐 YouTube / Google video CDN

141

cidr ok

Practical YouTube/Google video CDN list from AS15169 + AS36040. This restores real YouTube playback paths while still excluding broad Google Cloud/edge AS396982 from the YouTube list.

Practical, not perfectly isolated: YouTube frequently uses Google core AS15169. This list can route some non-YouTube Google core services, but it does not include the broader Google Cloud/edge AS396982 set published in google.rsc.

Sources: ripe-asn ×2 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS15169ripe-asn1410ok2026-10-01T14:03:25Z1157602
AS36040ripe-asn142ok2026-10-01T14:03:26Z116661

🌐 YouTube narrow / AS36040 only

70

cidr ok

Experimental narrow YouTube/Google video list from AS36040 only. Useful for testing minimal bypass, but can miss real YouTube playback paths served from Google core AS15169.

Experimental: less likely to route unrelated Google traffic, but known to miss some real YouTube/googlevideo/ytimg paths. Prefer youtube.rsc when playback stalls.

Sources: ripe-asn ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS36040ripe-asn142ok2026-10-01T14:03:26Z116661

⭐ YouTube domains

25

domain ok

Exact FQDN helper list for YouTube web, app/API, image and embed endpoints. Complements the narrower YouTube CIDR list.

Exact FQDN list only: RouterOS does not wildcard-match *.googlevideo.com, and clients using DoH/DoT or external DNS can bypass router-visible FQDN learning.

Sources: local ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
generate_lists.pylocal25local2026-10-01T14:03:22Z

⭐ Spotify domains

20

domain ok

Exact FQDN list for Spotify web, API, playback control, images and CDN assets.

Exact FQDN list for RouterOS compatibility. The Akamai hostname is intentionally narrow to avoid routing unrelated CDN traffic.

Sources: local ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
generate_lists.pylocal20local2026-10-01T14:03:22Z

🌐 X / Twitter

13

cidr ok

X/Twitter infrastructure from Twitter/X ASNs.

May not cover every CDN edge used by X/Twitter outside its own ASN.

Sources: ripe-asn ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS13414ripe-asn29ok2026-10-01T14:03:26Z13869

🌐 Netflix

23

cidr ok

Netflix/Open Connect infrastructure from Netflix ASNs.

Mainly Netflix/Open Connect; some app/API/CDN paths can still use third-party networks.

Sources: ripe-asn ×3 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
AS2906ripe-asn526ok2026-10-01T14:03:26Z161051
AS40027ripe-asn40ok2026-10-01T14:03:27Z15543
AS55095ripe-asn52ok2026-10-01T14:03:27Z16634

🌐 Antifilter Plus

1719

cidr ok

Di Labs aggregate CIDR list. Includes: antifilter-community, telegram, meta, google, narrower youtube CIDR, x-twitter and netflix.

Does not include domain/FQDN lists: antifilter-community-domains, youtube-domains, ai, openai, claude, gemini or custom-domains. Import them separately when rules reference those address-list names. Telegram CIDRs are inside antifilter-plus, but telegram.rsc is still useful when rules explicitly match address-list=telegram, for example router-originated Telegram Bot API/SOCKS traffic.

Sources: aggregate ×7 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
list:antifilter-communityaggregate904derived2026-10-01T14:03:22Z
list:telegramaggregate12derived2026-10-01T14:03:22Z
list:metaaggregate115derived2026-10-01T14:03:22Z
list:googleaggregate720derived2026-10-01T14:03:22Z
list:youtubeaggregate141derived2026-10-01T14:03:22Z
list:x-twitteraggregate13derived2026-10-01T14:03:22Z
list:netflixaggregate23derived2026-10-01T14:03:22Z

⭐ OpenAI / ChatGPT domains

46

domain ok

Domain/FQDN list for OpenAI and ChatGPT web/API services.

Domain/FQDN list: underlying IPs can be Google/Cloudflare/AWS/Azure and change frequently.

Sources: local ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
generate_lists.pylocal46local2026-10-01T14:03:22Z

⭐ Anthropic / Claude domains

6

domain ok

Domain/FQDN list for Anthropic and Claude web/API services.

Domain/FQDN list: underlying IPs can be Cloudflare/AWS/GCP and change frequently.

Sources: local ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
generate_lists.pylocal6local2026-10-01T14:03:22Z

⭐ Google Gemini domains

23

domain ok

Domain/FQDN list for Gemini web/Android, AI Studio and related Google AI APIs.

Product-specific Android Gemini RPC frontends are included; generic android.googleapis.com is excluded. Google IPs overlap with broad google/youtube CIDR lists.

Sources: local ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
generate_lists.pylocal23local2026-10-01T14:03:22Z

⭐ AI services domains: Gemini / ChatGPT / Claude

75

domain ok

Combined domain/FQDN list for AI web/API services. Generated RouterOS .rsc uses FQDN address-list entries, not fixed CIDR ownership.

Combined AI FQDN list. For per-vendor routing, use openai.rsc, claude.rsc and gemini.rsc.

Sources: local ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
generate_lists.pylocal75local2026-10-01T14:03:22Z

⭐ Custom domains

51

domain ok

Manual FQDN list managed by @di_labs_lists_bot for site-specific bypass routing.

Exact FQDN list. Add domains via @di_labs_lists_bot; RouterOS imports custom-domains.rsc on Maverick-MK every 12 hours.

Sources: manual ×1 · status: ok
SourceKindItemsStatusCheckedAttemptsBytes/Error
telegram-bot-manualmanual51local2026-10-01T14:03:22Z
🔍 No matching lists found
RouterOS Fast Start

⚠️ Minimal recommended setup: import antifilter-plus as the main CIDR list, ai as FQDN list for ChatGPT/Claude/Gemini, and if the router itself needs Telegram Bot API/SOCKS, a separate telegram for chain=output.

1. Backup before changes

/system backup save name=pre-di-labs-lists
/export file=pre-di-labs-lists

2. Import lists (one-time)

/tool fetch url="https://lists.di-labs.org/antifilter-plus.rsc" dst-path=di-labs-antifilter-plus.rsc mode=https
/import file-name=di-labs-antifilter-plus.rsc
/tool fetch url="https://lists.di-labs.org/ai.rsc" dst-path=di-labs-ai.rsc mode=https
/import file-name=di-labs-ai.rsc
/tool fetch url="https://lists.di-labs.org/telegram.rsc" dst-path=di-labs-telegram.rsc mode=https
/import file-name=di-labs-telegram.rsc

3. Policy routing example

Replace 192.168.0.0/16 with your LAN network. Bypass_VPN must be a real FIB routing table with a working default route via VPN/WireGuard.

/routing table
add name=Bypass_VPN fib comment="Di Labs: VPN policy table"
/ip route
add dst-address=0.0.0.0/0 gateway=<wg-or-vpn-interface> routing-table=Bypass_VPN comment="Di Labs: default via VPN"
/ip firewall mangle
add chain=prerouting src-address=192.168.0.0/16 dst-address-list=antifilter-plus connection-state=new action=mark-connection new-connection-mark=Conn_Bypass passthrough=yes comment="Di Labs: mark antifilter-plus"
add chain=prerouting src-address=192.168.0.0/16 dst-address-list=ai connection-state=new action=mark-connection new-connection-mark=Conn_Bypass passthrough=yes comment="Di Labs: mark AI FQDN"
add chain=prerouting src-address=192.168.0.0/16 connection-mark=Conn_Bypass action=mark-routing new-routing-mark=Bypass_VPN passthrough=no comment="Di Labs: route marked connections"

For fail-closed via routing rules, use lookup-only-in-table for your LAN/VLAN and verify the VPN table has an active route first.

4. Router-originated Telegram via VPN

/ip firewall mangle
add chain=output protocol=tcp dst-address-list=telegram dst-port=443 action=mark-routing new-routing-mark=Bypass_VPN passthrough=no comment="Di Labs: route router Telegram HTTPS"

5. Auto-update

Use the Selected RouterOS script generator to build a custom updater for exactly the lists your mangle rules use. File routeros-install.rsc remains the minimal default helper. Both include on-error handling, temp file cleanup, and size checks.

/tool fetch url="https://lists.di-labs.org/routeros-install.rsc" dst-path=routeros-install.rsc mode=https
/import file-name=routeros-install.rsc
/system script run di-labs-update-lists
/system scheduler add name=di-labs-update-lists interval=12h start-time=startup on-event="/system script run di-labs-update-lists"

6. Verify

/ip firewall address-list print count-only where list=antifilter-plus
/ip firewall address-list print count-only where list=ai
/ip firewall address-list print count-only where list=telegram
/ip firewall mangle print stats where comment~"Di Labs"

.rsc files first build and verify a reserved di-stage-* candidate, then merge all desired entries into the canonical list, and only afterwards remove obsolete records with comment prefix di-labs-auto. Manual entries are preserved. IPv4 uses /ip firewall address-list; IPv6 is published separately as *-ipv6.rsc.

FQDN/AI caveat: RouterOS resolves FQDN address-list entries via its own DNS. If clients use DoH/DoT, Secure DNS, or external DNS directly, ai/custom-domains may not resolve. Force DNS through the router, block DoT tcp/udp 853, manage browser DoH policies, or use a CIDR/proxy-client approach.

Notes