DNS.SB vs KeyCDN

Compare DNS.SB and KeyCDN on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Cloudflare

Logo: DNS.SB

DNS.SB

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, German-operated public resolver with DoT/DoH and optional city-pinned endpoints. Skip when you need malware blocking, a signed DPA or SLA on the free pool, or a guarantee that queries never leave the EU. Consider Quad9 for threat blocking or run your own recursive resolver when residency must be yours.

EU-operatedNo-logs (claimed)DoT + DoHUnfilteredAnycast + unicast pin
Logo: KeyCDN

KeyCDN

Switzerland· Web Hosting and Cloud Computing

Needs review

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage
DNS.SB vs KeyCDN: Snapshot
FeatureLogo: DNS.SBDNS.SBLogo: KeyCDNKeyCDN
Country of originGermanySwitzerland
CategoryWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanySwitzerland
Legal entityxTom GmbH, Kreuzstraße 60, 40210 Düsseldorf (Amtsgericht Düsseldorf HRB 86779)proinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, Switzerland
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyPrimary: xTom global anycast (operator xTom GmbH, DE) with published unicast DoH cities. Named non-xTom PoP hosts: HostVenom (Chicago), DigitalOcean (Bengaluru), Amazon AWS (Seoul), Servers.com (Moscow), Vultr (Toronto), Misaka (Berlin). Website analytics: self-hosted Plausible. Backup/DR and support SaaS not published. DoH also advertised as a global CDN endpoint.Company-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.
Summary

Free public recursive DNS from Düsseldorf-based xTom GmbH, with DoT/DoH, claimed no logs, and optional city-pinned unicast endpoints.

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

Tags
At a glance: DNS.SB vs KeyCDN
At a glanceLogo: DNS.SBDNS.SBLogo: KeyCDNKeyCDN
HQDüsseldorf, GermanyErmatingen, Switzerland
Legal entityxTom GmbH (HRB 86779)proinity LLC (d/b/a KeyCDN)
Commercial modelFree for personal and non-commercial use; commercial use needs authorizationPrepaid credits, 14-day trial, no contract
ProtocolsDNS 53, DoT 853 (dot.sb), DoH 443 (HTTP/3); no native DoQ; no DNS64Not listed
AnycastClaimed 30+ locations on six continents, including US citiesNot listed
Open sourceResolver stack not disclosed; docs site is on GitHubNot listed
Governing lawNot listedSwitzerland; courts of Schwyz
NetworkNot listed60+ PoPs in 40+ countries (vendor network page)
Push storageNot listedEuropean data centers (vendor storage page)
Self-hostedNot listedNo (WordPress helper plugins are on GitHub)
Key capabilities: DNS.SB vs KeyCDN
Key capabilitiesLogo: DNS.SBDNS.SBLogo: KeyCDNKeyCDN
EU-operatedYesNot listed
No-logs (claimed)YesNot listed
DoT + DoHYesNot listed
UnfilteredYesNot listed
Anycast + unicast pinYesNot listed
Swiss-operatedNot listedYes
Pay-as-you-go CDNNot listedYes
Pull and Push ZonesNot listedYes
Origin ShieldNot listedYes
REST API purgeNot listedYes
EU Push storageNot listedYes

DNS.SB

  • Memorable dual-stack public resolvers

    Classic DNS on UDP/TCP 53 at 185.222.222.222 and 45.11.45.11, plus IPv6 2a09:: and 2a11:: (full form published for older stacks). Dual-stack is first-class. There is no account and no client app. Benefit: routers and homelabs can be pointed at addresses people can actually remember. Limit: this is a shared public pool, not a dedicated recursive server.

  • DoT, DoH, and DoH over HTTP/3

    Encrypted DNS over TLS on hostname dot.sb port 853, and DoH at https://doh.dns.sb/dns-query (aliases doh.sb and dns.sb, plus raw IP URLs). The FAQ states DoH supports HTTP/3 (QUIC) and that native DNS-over-QUIC (RFC 9250) is not offered yet. Benefit: OS Private DNS, browsers, and Unbound can encrypt the stub-to-resolver hop. Limit: plaintext port 53 remains available and is still visible to the local network.

  • City-pinned unicast DoH endpoints

    Besides global anycast, the DoH page lists per-city URLs such as de-dus, de-fra, nl-ams, uk-lon, ee-tll, and several non-EU cities. Hosting providers are named per row (mostly xTom, plus HostVenom, DigitalOcean, Amazon AWS, Servers.com, Vultr, Misaka). Benefit: an admin can pin the resolver hop to a chosen metro. Limit: anycast IPs still land on the nearest global node, including US cities, unless you pin unicast.

  • Claimed no-logs resolver with DNSSEC and no ECS

    Privacy policy and FAQ say query names, client IPs, and timestamps are not stored, EDNS Client Subnet is off, query name minimisation (RFC 7816) is on, and the resolver validates DNSSEC. Benefit: less data handed to authoritative servers and, if the claim holds, nothing to disclose. Limit: the software stack is undisclosed and no independent no-logs audit was found.

  • Unfiltered recursion (legal caveats reserved)

    FAQ: no content filtering or blocking; users keep control. A separate FAQ bullet reserves blocking for legal requirements. Benefit: usable as a neutral upstream under a local filter like Pi-hole. Limit: no malware or ad blocklist on the resolver, and legal orders could still force a block.

KeyCDN

  • Pull Zones with instant purge

    A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

  • Push Zones on European storage

    A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

  • Origin Shield (US East, US West, Amsterdam)

    An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

  • Query-string image processing

    On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

  • REST API, TLS choices, and protocol stack

    The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

  • Token, referrer, and account locks

    Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

Assurance & compliance: DNS.SB vs KeyCDN
Assurance & complianceLogo: DNS.SBDNS.SBLogo: KeyCDNKeyCDN
Independent security / no-logs audit
Not found

Vendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed.

Not found

No public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field.

ISO 27001
Not found

No ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed.

Not found

Network page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC.

SOC 2 / SOC 3
Not found

No SOC 2 or SOC 3 claim found on the official pages reviewed.

Not found

Searched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found.

GDPR / EU data protection
Vendor claimed

German controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests.

Vendor claimed

Swiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice.

Partial

Swiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA. Free service is personal/non-commercial; commercial terms are by contact only.

Vendor claimed

GDPR page: open a support request to receive the DPA when Article 28 processing applies.

EU AI Act
Not applicable

Public DNS resolver, not an AI system.

Not applicable

CDN / image transforms, not an AI system product.

Considerations & known limitations: DNS.SB vs KeyCDN
Considerations & known limitationsLogo: DNS.SBDNS.SBLogo: KeyCDNKeyCDN
No-logs policy is unaudited
Medium

Privacy policy and FAQ say query logging is off. There is no independent audit, and the resolver software is not disclosed. Practical impact: you cannot show a third-party report to a security reviewer.

Not listed
Global anycast and US-group PoP hosts
Medium

Default anycast can land on US and other non-EU nodes. Published unicast DoH uses Amazon AWS, DigitalOcean, Vultr, HostVenom, Servers.com, and Misaka in addition to xTom. Practical impact: EU-only query residency is not the default and is not contractual.

Not listed
Free pool is not a commercial DNS contract
Medium

Terms restrict free use to personal and non-commercial cases. No SLA, no public DPA, services provided as-is. Practical impact: embedding DNS.SB in a product or relying on it for production without a license is out of policy.

Not listed
No resolver-side threat blocking
Low

Unfiltered by design, with a legal-requirements caveat. Practical impact: malware and phishing names resolve unless you filter locally or pick a protective resolver.

Not listed
No DNS64 and no native DoQ
Low

FAQ: DNS64 is not offered; native DoQ is under evaluation; DoH over HTTP/3 is available. Practical impact: NAT64-only clients and DoQ-only stubs need another resolver.

Not listed
US cache copies and US Origin ShieldNot listed
Medium

Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

No current named subprocessor listNot listed
Medium

Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

No public operator ISO 27001 or SOC 2Not listed
Medium

ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

Privacy Policy last updated 2018Not listed
Medium

The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

Push Zone required above 100 MBNot listed
Low

Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Fit

DNS.SB

Best fit when

  • Homelabs and small networks that want a German-operated public resolver with addresses people can remember
  • Teams that already filter locally (Pi-hole, AdGuard Home, Unbound) and need a neutral encrypted upstream
  • Users who want DoT (dot.sb) or DoH without an account or client app
  • Operators who will pin a named EU/UK unicast DoH city instead of trusting global anycast
  • Personal and non-commercial use allowed by the published terms

Poor fit when

  • Regulated or commercial production DNS that needs a signed DPA, SLA, or prior commercial license
  • Anyone who needs resolver-side malware, ads, or family filtering
  • EU-only data residency requirements if you stay on anycast or non-EU unicast cities
  • IPv6-only NAT64 networks that need DNS64
  • Buyers who require an independent no-logs audit or a disclosed resolver software stack

Consider instead when

  • When: You want threat blocking at the resolver, not a neutral recursive cache

    Consider: Quad9 (Swiss foundation, not yet in this catalog) or a protective DNS4EU profile

    DNS.SB documents an unfiltered policy aside from legal requirements.

  • When: You need a signed DPA, SLA, or EU-only query path under contract

    Consider: Self-hosted Unbound or Knot Resolver, or a commercial recursive DNS with a written DPA

    Free DNS.SB is personal/non-commercial; city pins are operational, not a contract.

  • When: You need a full-tunnel VPN plus resolver under one European vendor

    Consider: Mullvad

    Different product class. Mullvad is a VPN, not a standalone public DNS.

KeyCDN

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

Open questions for due diligence

DNS.SB

  • Will xTom sign a DPA and publish a complete subprocessor list for commercial DNS.SB use?
  • Can they contractually pin recursion to named EU cities (not just publish unicast URLs)?
  • Will they commission an independent no-logs or resolver-security audit and name the software?
  • What process would force query logging or blocking beyond the current legal-requirements caveat?
  • What infrastructure sits behind the advertised global DoH CDN endpoint besides the named unicast PoPs?

KeyCDN

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?