bunny.net vs DNS.SB

Vergleichen Sie bunny.net und DNS.SB nach Funktionen, Rechtsraum, Nachweisen und Einsatzpassung.

Beide als Alternativen zu: Cloudflare

Logo: bunny.net

bunny.net

Slovenia· Web Hosting and Cloud Computing

Needs review

Shortlist bunny.net when you want a Slovenian-operated CDN plus storage and Stream, with an official EU pull-zone routing filter and prepaid pay-as-you-go billing. Skip it when you need Cloudflare Workers or Zero Trust as the control plane, or when account data must stay off US-group SaaS (Slack, OpenAI, SendGrid, Mixpanel, Salesforce, Braintree). Consider Cloudflare if the platform surface matters more than EU HQ.

EU-operated (Slovenia)Pay-as-you-go CDNEU pull-zone routing filterMulti-region edge storageManaged video (Stream)ISO 27001 (claimed)
Logo: DNS.SB

DNS.SB

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, German-operated public resolver with DoT/DoH and optional city-pinned endpoints. Skip when you need malware blocking, a signed DPA or SLA on the free pool, or a guarantee that queries never leave the EU. Consider Quad9 for threat blocking or run your own recursive resolver when residency must be yours.

EU-operatedNo-logs (claimed)DoT + DoHUnfilteredAnycast + unicast pin
bunny.net vs DNS.SB: Überblick
MerkmalLogo: bunny.netbunny.netLogo: DNS.SBDNS.SB
HerkunftslandSloveniaGermany
KategorieWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open SourceNeinNein
Self-HostedNeinNein
HauptsitzSloveniaGermany
RechtsträgerBunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, SloveniaxTom GmbH, Kreuzstraße 60, 40210 Düsseldorf (Amtsgericht Düsseldorf HRB 86779)
US-Mutter / KontrolleKeine bekannte US-MutterKeine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)MittelMittel
Hosting / ResidenzOperator-advertised global PoPs (Standard 119, Volume 10) and 15 storage regions, including EU (London, Stockholm, Frankfurt, Madrid, Prague) and US (New York, Miami, Los Angeles, Seattle). EU Routing Filter can pin CDN pull-zone traffic to 24 EU PoPs. DNS stays global. Account path uses Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree. Privacy page claims EU residency for BigQuery, dbt Cloud, Lemlist, Loqate, and Kickscale.Primary: xTom global anycast (operator xTom GmbH, DE) with published unicast DoH cities. Named non-xTom PoP hosts: HostVenom (Chicago), DigitalOcean (Bengaluru), Amazon AWS (Seoul), Servers.com (Moscow), Vultr (Toronto), Misaka (Berlin). Website analytics: self-hosted Plausible. Backup/DR and support SaaS not published. DoH also advertised as a global CDN endpoint.
Zusammenfassung

Slovenian edge platform from BunnyWay d.o.o.: pay-as-you-go CDN, multi-region object storage, video streaming, and Shield WAF on an operator-run global PoP network.

Free public recursive DNS from Düsseldorf-based xTom GmbH, with DoT/DoH, claimed no logs, and optional city-pinned unicast endpoints.

Tags
Auf einen Blick: bunny.net vs DNS.SB
Auf einen BlickLogo: bunny.netbunny.netLogo: DNS.SBDNS.SB
HQLjubljana, SloveniaDüsseldorf, Germany
Legal entityBunnyWay d.o.o.xTom GmbH (HRB 86779)
Product familyCDN, Storage, Stream, Shield, DNS, Optimizer, edge computeNicht angegeben
Hosting modelHosted operator PoPs (not self-hosted)Nicht angegeben
Commercial modelPrepaid pay-as-you-go, trial without credit cardFree for personal and non-commercial use; commercial use needs authorization
Open sourceNo public core license foundResolver stack not disclosed; docs site is on GitHub
ProtocolsNicht angegebenDNS 53, DoT 853 (dot.sb), DoH 443 (HTTP/3); no native DoQ; no DNS64
AnycastNicht angegebenClaimed 30+ locations on six continents, including US cities
Key capabilities: bunny.net vs DNS.SB
Key capabilitiesLogo: bunny.netbunny.netLogo: DNS.SBDNS.SB
EU-operated (Slovenia)JaJa
Pay-as-you-go CDNJaNicht angegeben
EU pull-zone routing filterJaNicht angegeben
Multi-region edge storageJaNicht angegeben
Managed video (Stream)JaNicht angegeben
ISO 27001 (claimed)JaNicht angegeben
No-logs (claimed)Nicht angegebenJa
DoT + DoHNicht angegebenJa
UnfilteredNicht angegebenJa
Anycast + unicast pinNicht angegebenJa

bunny.net

  • Pull-zone CDN with Perma-Cache

    Create a pull zone, attach an origin, and cache on the vendor-stated Standard network (119 PoPs) or the smaller Volume network (10 PoPs). Perma-Cache can store objects permanently on Edge Storage so the zone aims for a full cache hit ratio. Let's Encrypt, instant purge, Edge Rules, SafeHop origin retries, and real-time logs are part of the CDN product. Limit: this is a hosted network, not a self-hosted cache you run in your own racks.

  • EU Routing Filter for pull zones

    Docs describe a Pricing and Routing toggle that sends all pull-zone traffic only through PoPs in EU member states (24 locations listed). Users outside the EU are also sent to those EU PoPs, which raises latency. The filter applies to CDN pull-zone traffic, not to the global DNS network. Combine this with EU storage regions if residency is the purchase filter.

  • Multi-region edge object storage

    Bunny Storage is object storage you upload over FTP, SFTP, HTTP API, or the web file manager, then replicate to chosen regions. The Storage page lists 15 regions spanning EU, US, APAC, LATAM, and Africa, with standard HDD and SSD Edge tiers. Traffic from Storage into Bunny CDN is described as free of API request and API egress fees. You pick each replica region. A US replica is optional, not forced, but global CDN delivery can still cache copies at non-EU PoPs unless filtered.

  • Bunny Stream transcoding and player

    Stream accepts uploads (including TUS resumable API), transcodes multiple resolutions, replicates video, and ships a customizable player or raw HLS. Token authentication, hotlink protection, watermarking, and optional Media Cage multi-DRM are documented product features. Encoding and the player are included in the Stream commercial model. If you enable Transcribe AI or related AI features, audio or prompts can be sent to OpenAI in the United States.

  • Signed URL tokens and access controls

    Token authentication blocks pull-zone requests unless a signed token is present. Basic tokens use MD5 with expiry and optional IP checks. Advanced tokens use SHA256 and add geo restrictions, directory tokens, and speed limits. The same security toolbox includes geo-blocking and hotlink protection. Enabling token authentication disables IPv6 on that zone, per the docs.

  • Bunny Shield WAF and DDoS

    Shield is a separate security product in front of the same edge: managed WAF rules, DDoS mitigation, global rate limits, bot controls, access lists, and upload scanning. Basic WAF rules are available on a free Shield tier. Custom rule counts and request allowances rise on paid tiers. It is not a substitute for Cloudflare Zero Trust or a full SOC platform.

DNS.SB

  • Memorable dual-stack public resolvers

    Classic DNS on UDP/TCP 53 at 185.222.222.222 and 45.11.45.11, plus IPv6 2a09:: and 2a11:: (full form published for older stacks). Dual-stack is first-class. There is no account and no client app. Benefit: routers and homelabs can be pointed at addresses people can actually remember. Limit: this is a shared public pool, not a dedicated recursive server.

  • DoT, DoH, and DoH over HTTP/3

    Encrypted DNS over TLS on hostname dot.sb port 853, and DoH at https://doh.dns.sb/dns-query (aliases doh.sb and dns.sb, plus raw IP URLs). The FAQ states DoH supports HTTP/3 (QUIC) and that native DNS-over-QUIC (RFC 9250) is not offered yet. Benefit: OS Private DNS, browsers, and Unbound can encrypt the stub-to-resolver hop. Limit: plaintext port 53 remains available and is still visible to the local network.

  • City-pinned unicast DoH endpoints

    Besides global anycast, the DoH page lists per-city URLs such as de-dus, de-fra, nl-ams, uk-lon, ee-tll, and several non-EU cities. Hosting providers are named per row (mostly xTom, plus HostVenom, DigitalOcean, Amazon AWS, Servers.com, Vultr, Misaka). Benefit: an admin can pin the resolver hop to a chosen metro. Limit: anycast IPs still land on the nearest global node, including US cities, unless you pin unicast.

  • Claimed no-logs resolver with DNSSEC and no ECS

    Privacy policy and FAQ say query names, client IPs, and timestamps are not stored, EDNS Client Subnet is off, query name minimisation (RFC 7816) is on, and the resolver validates DNSSEC. Benefit: less data handed to authoritative servers and, if the claim holds, nothing to disclose. Limit: the software stack is undisclosed and no independent no-logs audit was found.

  • Unfiltered recursion (legal caveats reserved)

    FAQ: no content filtering or blocking; users keep control. A separate FAQ bullet reserves blocking for legal requirements. Benefit: usable as a neutral upstream under a local filter like Pi-hole. Limit: no malware or ad blocklist on the resolver, and legal orders could still force a block.

Assurance & compliance: bunny.net vs DNS.SB
Assurance & complianceLogo: bunny.netbunny.netLogo: DNS.SBDNS.SB
Independent security / no-logs audit
Not found

Vendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found.

Not found

Vendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed.

ISO 27001
Vendor claimed

September 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry.

Not found

No ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed.

SOC 2 / SOC 3
Not found

Trust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found.

Not found

No SOC 2 or SOC 3 claim found on the official pages reviewed.

GDPR / EU data protection
Vendor claimed

EU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material.

Vendor claimed

German controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice.

Partial

EU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page.

Not found

No public DPA. Free service is personal/non-commercial; commercial terms are by contact only.

EU AI Act
Not applicable

Core product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product.

Not applicable

Public DNS resolver, not an AI system.

Considerations & known limitations: bunny.net vs DNS.SB
Considerations & known limitationsLogo: bunny.netbunny.netLogo: DNS.SBDNS.SB
Default routing is global, including US and Moscow PoPs
Medium

Without the EU Routing Filter, cached objects can sit at non-EU PoPs listed on the CDN map, including US cities and Moscow. The filter covers pull-zone traffic only and hurts latency for non-EU users.

Nicht angegeben
US-group account and feature subprocessors
Medium

Support, mail, CRM, payments, product analytics, and optional AI features use Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, Braintree, and others. EU HQ does not isolate account data from those vendors.

Nicht angegeben
ISO 27001 not independently opened in this draft
Low

The company publishes a UKAS link and a Trust Center certificate. This agent draft could not read the JavaScript registry page, so the checklist stays at claimed until a human confirms scope and dates.

Nicht angegeben
Optional OpenAI path for Stream and support
Medium

Transcription, Fluffee/support chat, and CDN AI image generation send data to OpenAI in the United States. Disable those features for workloads that cannot use a US AI processor.

Nicht angegeben
Narrower platform than Cloudflare
Low

Shield and Edge Scripting exist, but this is still primarily a delivery, storage, and video stack. Do not expect feature parity with Cloudflare Workers or Zero Trust.

Nicht angegeben
No-logs policy is unauditedNicht angegeben
Medium

Privacy policy and FAQ say query logging is off. There is no independent audit, and the resolver software is not disclosed. Practical impact: you cannot show a third-party report to a security reviewer.

Global anycast and US-group PoP hostsNicht angegeben
Medium

Default anycast can land on US and other non-EU nodes. Published unicast DoH uses Amazon AWS, DigitalOcean, Vultr, HostVenom, Servers.com, and Misaka in addition to xTom. Practical impact: EU-only query residency is not the default and is not contractual.

Free pool is not a commercial DNS contractNicht angegeben
Medium

Terms restrict free use to personal and non-commercial cases. No SLA, no public DPA, services provided as-is. Practical impact: embedding DNS.SB in a product or relying on it for production without a license is out of policy.

No resolver-side threat blockingNicht angegeben
Low

Unfiltered by design, with a legal-requirements caveat. Practical impact: malware and phishing names resolve unless you filter locally or pick a protective resolver.

No DNS64 and no native DoQNicht angegeben
Low

FAQ: DNS64 is not offered; native DoQ is under evaluation; DoH over HTTP/3 is available. Practical impact: NAT64-only clients and DoQ-only stubs need another resolver.

Passung

bunny.net

Best fit when

  • EU-headquartered teams that need a pull-zone CDN and can enable the EU Routing Filter when residency matters
  • Sites and APIs that want prepaid bandwidth billing without per-request CDN fees
  • Software, game, or firmware delivery that benefits from Perma-Cache and multi-region storage (see NZXT, System76, Nexus Mods case studies)
  • VOD or event video that can use Stream transcoding and the bundled player, without sending audio to OpenAI
  • Teams that want token-authenticated downloads, geo-blocking, and a separate Shield WAF on the same account

Poor fit when

  • Architectures built around Cloudflare Workers, Zero Trust, or Cloudflare as the primary application platform
  • Workloads with a hard ban on US-group subprocessors for billing, support, mail, or analytics
  • Buyers who need a self-hosted or open-source CDN they can run in their own data centers
  • Global audiences that must stay on the nearest PoP while also forbidding any non-EU cache (the EU filter trades latency for residency)
  • Regulated video that requires on-platform transcription without a US AI subprocessor

Consider instead when

  • When: You need Workers, Zero Trust, or a single US-scale security and compute control plane

    Consider: Cloudflare

    Cloudflare is US-headquartered. The tradeoff is platform breadth, not EU ownership.

  • When: Origin already lives on AWS and you need IAM, PrivateLink, or CloudFront contracts

    Consider: Amazon CloudFront (with S3 or Media Services)

    Bunny is faster to start for a standalone CDN plus Stream. It will not replace AWS account controls.

  • When: You want a European CDN peer that is not Cloudflare and bunny.net's US PoPs or US SaaS tools are disqualifying

    Consider: KeyCDN or Myra Security (not yet in this catalog)

    Re-check those vendors on their own legal and subprocessor pages. Do not assume they are cleaner.

DNS.SB

Best fit when

  • Homelabs and small networks that want a German-operated public resolver with addresses people can remember
  • Teams that already filter locally (Pi-hole, AdGuard Home, Unbound) and need a neutral encrypted upstream
  • Users who want DoT (dot.sb) or DoH without an account or client app
  • Operators who will pin a named EU/UK unicast DoH city instead of trusting global anycast
  • Personal and non-commercial use allowed by the published terms

Poor fit when

  • Regulated or commercial production DNS that needs a signed DPA, SLA, or prior commercial license
  • Anyone who needs resolver-side malware, ads, or family filtering
  • EU-only data residency requirements if you stay on anycast or non-EU unicast cities
  • IPv6-only NAT64 networks that need DNS64
  • Buyers who require an independent no-logs audit or a disclosed resolver software stack

Consider instead when

  • When: You want threat blocking at the resolver, not a neutral recursive cache

    Consider: Quad9 (Swiss foundation, not yet in this catalog) or a protective DNS4EU profile

    DNS.SB documents an unfiltered policy aside from legal requirements.

  • When: You need a signed DPA, SLA, or EU-only query path under contract

    Consider: Self-hosted Unbound or Knot Resolver, or a commercial recursive DNS with a written DPA

    Free DNS.SB is personal/non-commercial; city pins are operational, not a contract.

  • When: You need a full-tunnel VPN plus resolver under one European vendor

    Consider: Mullvad

    Different product class. Mullvad is a VPN, not a standalone public DNS.

Open questions for due diligence

bunny.net

  • Is the UKAS ISO 27001 entry still current, and what is the certified scope (which products and locations)?
  • Does the in-dashboard DPA include SCCs and a current annex that matches the public sub-processor list plus the longer privacy-policy vendor list?
  • Which products besides CDN pull zones honor an EU-only data path (Stream libraries, Shield logs, Optimizer, Edge Scripting)?
  • Can Mixpanel, Salesforce, SendGrid, or Slack be contractually excluded for a given account?
  • What is the legal relationship between BunnyWay d.o.o. and the UK and German hiring entities?
  • Is the Moscow PoP still active, and can it be excluded without the full EU filter?

DNS.SB

  • Will xTom sign a DPA and publish a complete subprocessor list for commercial DNS.SB use?
  • Can they contractually pin recursion to named EU cities (not just publish unicast URLs)?
  • Will they commission an independent no-logs or resolver-security audit and name the software?
  • What process would force query logging or blocking beyond the current legal-requirements caveat?
  • What infrastructure sits behind the advertised global DoH CDN endpoint besides the named unicast PoPs?