Logo: DNS4EU

DNS4EU

Free public DNS resolver for individuals, operated by Czech company Whalebone as the live offering of an EU-initiated DNS programme. Five anycast profiles with DoH, DoT, and DNSSEC.

DNS4EU Public Service is a free recursive DNS resolver that an individual can point a laptop, phone, or home router at. It exists because the European Commission encouraged a public European resolver as an alternative to a few widely used services run by non-EU companies. The Commission later co-funded the development project (101095329, DNS4EU and European DNS Shield). The live public resolver is operated by Whalebone, s.r.o., a Czech company based in Brno, not by the Commission as a government department.

Users choose one of five anycast profiles: protective filtering of domains the operator treats as malicious, the same plus child-content categories, plus ad blocking, both extras together, or unfiltered resolution. All five publish IPv4 and IPv6 addresses plus DNS-over-HTTPS and DNS-over-TLS hostnames. The operator states that DNSSEC validation is on for every profile.

The useful differentiator for a tech lead is the published operating model, not a claim that this is mandatory EU infrastructure. The project site says use is voluntary, that the Commission does not get configuration or query data, and that the 2023 to 2025 build phase has moved to a Whalebone-operated service. The public resolver is written for people. Organisations are pointed at DNS4GOV or Whalebone Immunity because of rate limits.

EU-operated (Whalebone CZ)Free public resolverDoH and DoTDNSSEC validationConsumer rate-limited

Shortlist the public resolver when a household or individual wants an EU-sited recursive DNS with published DoH/DoT names, optional protective or child/ad filters, and a Czech operator. Skip it when you need organisational scale, a DPA, or a resolver that will not apply court and sanctions blocks. Consider Quad9 for a mature threat-blocking public DNS, UncensoredDNS if you want minimal policy filtering, or DNS4GOV/Immunity when you need a contract.

Key capabilities

Protective (86.54.11.1), child (86.54.11.12), ads (86.54.11.13), child+ads (86.54.11.11), and unfiltered (86.54.11.100), each with a second IPv4, IPv6, https://<name>.joindns4.eu/dns-query, and a DoT hostname. Terms and the public FAQ state DNSSEC validation is always on. Built on Whalebone's resolver on top of CZ.NIC Knot Resolver 6, announced as anycast.

The Public Resolvers Policy hashes client IPv4 and IPv6 with HMAC-SHA256 using a daily in-memory key, applies a traffic-based modulo, rewrites a prefix, and drops anonymised identities with fewer than 100 queries. Ordinary client IPs stay in RAM for milliseconds. Anonymised research logs may be stored up to six months on the EU Scaleway backend.

Child profiles block gambling, sexual content, weapons, child abuse, drugs, racism, terrorism, and violence using public feeds plus Webshrinker, and send users to a block page. Ad profiles sinkhole advertisement domains (lists such as goodbyeads) to 0.0.0.0. The operator warns that shared domains and anti-ad logic can break sites and apps.

Terms restrict the public service to personal, manual configuration. The FAQ sets 1,000 queries per second per IP, after which queries may be dropped. Organisations are directed to DNS4GOV (public sector) or Whalebone Immunity (enterprise). This is a hard product boundary, not a soft recommendation.

joindns4.eu/legal-information-and-compliance lists member-state court orders (including French judicial decisions) and EU sanctions domains, plus a 2025 transparency-report CSV set. Policy says blocks outside malware and user-elected filters happen only when required by law or an enforceable authority decision.

Auf einen Blick

HQ
Brno, Czech Republic
Legal entity
Whalebone, s.r.o. (IČO 05120403)
Public launch
Announced 11 June 2025
Commercial model
Free for individual personal use; orgs directed to paid Whalebone products
Protocols
Plain DNS, DoH, DoT, DNSSEC; IPv4 and IPv6
Rate limit
1,000 queries per second per IP (operator FAQ)

Best fit when

  • Individuals in the EU who will change device, browser, or home-router DNS and want a Czech-operated public resolver
  • Households that want malware-oriented protective DNS plus optional child-content or ad blocking without installing an agent
  • People who specifically want DoH or DoT endpoints under joindns4.eu and a published resolver policy
  • Evaluators comparing EU-initiated public DNS with Google Public DNS or Cloudflare 1.1.1.1 on jurisdiction and logging

Poor fit when

  • Companies, ISPs, schools, or government networks (Terms exclude them; 1,000 qps per IP limit)
  • Buyers who need a signed B2B DPA, SLA, or allow-listed high-volume traffic on the public IPs
  • Users who require a resolver that will not implement court orders or EU sanctions domain lists
  • Teams that need to self-host the public profiles or treat DNS4EU as an open-source product
  • Anyone who needs the European Commission to be the legal operator of their DNS

Consider instead when

  • When: You need organisational protective DNS with a contract, DPA, and no consumer rate limit

    Consider: Whalebone DNS4GOV (public sector) or Whalebone Immunity (enterprise)

    Same operator, different product. Not the free joindns4.eu anycast.

  • When: You want a well-known threat-blocking public resolver without the Commission-project framing

    Consider: Quad9

    Swiss foundation model. Compare block lists and logging independently.

  • When: You want recursive resolution with as little policy filtering as possible

    Consider: UncensoredDNS

    Danish public resolver. Confirm current logging and hosting before switching.

Gerichtsbarkeit & Eigentum

Rechtsträger
Whalebone, s.r.o., Jezuitska 13/14, 602 00 Brno, Czech Republic, ID 05120403, Regional Court in Brno C 93547
US-Mutter / Kontrolle
Keine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)
Low
Hosting / Residenz
Operator: Whalebone s.r.o. (CZ). Public FAQ: resolvers on dedicated Datapacket hosts; backend Kubernetes on Scaleway (FR). Policy: resolvers in EU-controlled datacenters (14 resolvers / 14 EU member states stated); backend EU-hosted on Scaleway. Datapacket is DataCamp Limited (UK). Legal PDFs sit on Scaleway Object Storage (fr-par). Marketing website is HubSpot (US SaaS) and is not the recursive DNS path. No AWS, GCP, or Azure named for the resolver.

No US parent found (VC includes UK Unbound and HU Day One Capital). CLOUD Act score is indicative for the resolver path (CZ entity, FR Scaleway, UK Datapacket). Website HubSpot is a separate US processor. Not legal advice. Datapacket transit has been discussed in independent write-ups (AS198121 via AS60068).

  • Independent security / no-logs auditNot found
  • ISO 27001Vendor claimed
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • HighPublic IPs are not an organisational resolver

    Terms and the 1,000 qps limit make the free anycast unsuitable as company or ISP DNS. Using it anyway can mean dropped queries and a ToU problem.

  • MediumCourt and sanctions domain blocking

    Even the unfiltered profile is subject to law and authority-ordered blocks published on the legal page. That is a feature for some buyers and a disqualifier for others.

  • MediumNo public independent no-logs audit

    Anonymisation is documented first-party only. There is no third-party audit PDF to verify that raw IPs stay out of research logs.

  • LowUK transit provider plus US website SaaS

    Resolver hosts are Datapacket (DataCamp Limited, UK) with Scaleway backend. The marketing site is HubSpot. Policy still places resolver datacenters in the EU. Confirm this path if your threat model cares about every vendor in the stack.

  • MediumAs-is availability, best-effort support

    Terms disclaim uptime and individual support guarantees. There is a status page and a public form. Do not treat this as a contracted critical resolver.

Open questions for due diligence

  • Will Whalebone publish a complete subprocessor list for the resolver (including any CDN, email, or monitoring tools beyond Datapacket and Scaleway)?
  • Is there a public ISO 27001 certificate number that covers the DNS4EU public resolver operations, not only Immunity marketing copy?
  • Will an independent lab publish a no-logs or control audit of the HMAC anonymisation and six-month backend retention?
  • Which of the 14 stated EU resolver sites are currently anycast-active, and does Datapacket transit change the practical data path from a given member state?
  • For DNS4GOV or Immunity buyers: what DPA, subprocessors, and SLA are actually on offer?

Häufig gestellte Fragen

Not according to the operator. Terms of Use exclude enterprises and connectivity providers. The public FAQ says the service is for individual citizens, is not for commercial use, and is not optimised for government, enterprise, or CSP traffic because of DoS protection and the 1,000 qps per IP limit. Whalebone points organisations to DNS4GOV or Immunity instead.

No on the public record the project itself publishes. The Commission announced support for a public European resolver in its cybersecurity strategy and co-funded the 2023 to 2025 project. The About page says use is voluntary, that the EU will not have access to configuration or data, and that Whalebone now operates the live service. Treat vendor phrases such as official EU DNS as programme branding, not as a statement that an EU institution is your DNS operator.

Malware and user-elected category filters should be off. The Public Resolvers Policy still allows blocking required by law or an enforceable court or government decision. The legal-information page shows active court-ordered and sanctions domain lists. If your requirement is a resolver that will not implement those orders, look at a different operator.

Policy: resolvers in EU datacenters; backend (threat-intel propagation, log aggregation, policy) on Scaleway in the EU; FAQ also names Datapacket for dedicated resolver hosts. Anonymised research logs up to six months; raw IPs only for live resolution, attack analysis, or crash dumps. The website privacy notice (HubSpot site) is a separate processing activity. No public B2B DPA was found for the consumer resolver, which matches a personal-use service. Ask Whalebone if you are buying DNS4GOV or Immunity.

The public FAQ says it uses the Whalebone DNS Resolver built upon Knot Resolver 6 from CZ.NIC. Knot Resolver is a separate open-source project. DNS4EU Public Service is a Whalebone-operated anycast. There are no official docs to run the public profiles yourself. Self-hosted or contracted protective DNS is a different Whalebone product (Immunity).