DNS.SB vs Leaseweb CDN

Compare DNS.SB and Leaseweb CDN on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Cloudflare

Logo: DNS.SB

DNS.SB

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, German-operated public resolver with DoT/DoH and optional city-pinned endpoints. Skip when you need malware blocking, a signed DPA or SLA on the free pool, or a guarantee that queries never leave the EU. Consider Quad9 for threat blocking or run your own recursive resolver when residency must be yours.

EU-operatedNo-logs (claimed)DoT + DoHUnfilteredAnycast + unicast pin
Logo: Leaseweb CDN

Leaseweb CDN

Netherlands· Web Hosting and Cloud Computing

Needs review

Shortlist when you want a Dutch (or other local Leaseweb) B2B contract that fronts four partner CDNs with NS1 Pulsar steering and included Amsterdam or Washington, D.C. origin shields. Skip when you need EU-only processors, named partner inventory up front, Cloudflare-class WAF or Workers, or signed URLs without a shield hop. Consider Cloudflare for a single global edge platform, or OVHcloud if you want a French-operated CDN attached to EU datacentres.

Dutch sales entityMulti-CDN (4 partners)Origin shield (AMS + WDC)Portal + REST APIISO 27001 (company, claimed)
DNS.SB vs Leaseweb CDN: Snapshot
FeatureLogo: DNS.SBDNS.SBLogo: Leaseweb CDNLeaseweb CDN
Country of originGermanyNetherlands
CategoryWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyNetherlands
Legal entityxTom GmbH, Kreuzstraße 60, 40210 Düsseldorf (Amtsgericht Düsseldorf HRB 86779)Leaseweb Netherlands B.V. (KvK 30141839, Amsterdam). Website: Leaseweb Global B.V. (KvK 60593652). Other local sales entities exist.
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyPrimary: xTom global anycast (operator xTom GmbH, DE) with published unicast DoH cities. Named non-xTom PoP hosts: HostVenom (Chicago), DigitalOcean (Bengaluru), Amazon AWS (Seoul), Servers.com (Moscow), Vultr (Toronto), Misaka (Berlin). Website analytics: self-hosted Plausible. Backup/DR and support SaaS not published. DoH also advertised as a global CDN endpoint.Delivery is a mix of four unnamed third-party CDNs (global PoPs). Leaseweb origin shields in Amsterdam and Washington, D.C. Request steering via NS1 Pulsar. Origins may be customer HTTP hosts or S3-compatible buckets (including AWS). Raw logs (including client IP) collected from partners and optionally written to customer S3. No public CDN subprocessor list naming the four partners.
Summary

Free public recursive DNS from Düsseldorf-based xTom GmbH, with DoT/DoH, claimed no logs, and optional city-pinned unicast endpoints.

Dutch Multi-CDN that steers traffic across four partner networks with NS1 Pulsar, plus included origin shields in Amsterdam and Washington, D.C. Sold under local Leaseweb sales entities.

Tags
At a glance: DNS.SB vs Leaseweb CDN
At a glanceLogo: DNS.SBDNS.SBLogo: Leaseweb CDNLeaseweb CDN
HQDüsseldorf, GermanyAmsterdam, Netherlands
Legal entityxTom GmbH (HRB 86779)Not listed
Commercial modelFree for personal and non-commercial use; commercial use needs authorizationB2B traffic tiers, annual commitment
ProtocolsDNS 53, DoT 853 (dot.sb), DoH 443 (HTTP/3); no native DoQ; no DNS64Not listed
AnycastClaimed 30+ locations on six continents, including US citiesNot listed
Open sourceResolver stack not disclosed; docs site is on GitHubNot listed
Website operatorNot listedLeaseweb Global B.V. (KvK 60593652)
Typical NL contractNot listedLeaseweb Netherlands B.V. (KvK 30141839)
FoundedNot listed1997 (vendor, 2023 press)
Product typeNot listedManaged Multi-CDN (not self-hosted, not open source)
EdgeNot listedFour unnamed partner CDNs, 400+ PoPs (vendor claim)
Shield locationsNot listedAmsterdam and Washington, D.C.
SteeringNot listedNS1 Pulsar (Volume: cost; Premium: QoE)
Key capabilities: DNS.SB vs Leaseweb CDN
Key capabilitiesLogo: DNS.SBDNS.SBLogo: Leaseweb CDNLeaseweb CDN
EU-operatedYesNot listed
No-logs (claimed)YesNot listed
DoT + DoHYesNot listed
UnfilteredYesNot listed
Anycast + unicast pinYesNot listed
Dutch sales entityNot listedYes
Multi-CDN (4 partners)Not listedYes
Origin shield (AMS + WDC)Not listedYes
Portal + REST APINot listedYes
ISO 27001 (company, claimed)Not listedYes

DNS.SB

  • Memorable dual-stack public resolvers

    Classic DNS on UDP/TCP 53 at 185.222.222.222 and 45.11.45.11, plus IPv6 2a09:: and 2a11:: (full form published for older stacks). Dual-stack is first-class. There is no account and no client app. Benefit: routers and homelabs can be pointed at addresses people can actually remember. Limit: this is a shared public pool, not a dedicated recursive server.

  • DoT, DoH, and DoH over HTTP/3

    Encrypted DNS over TLS on hostname dot.sb port 853, and DoH at https://doh.dns.sb/dns-query (aliases doh.sb and dns.sb, plus raw IP URLs). The FAQ states DoH supports HTTP/3 (QUIC) and that native DNS-over-QUIC (RFC 9250) is not offered yet. Benefit: OS Private DNS, browsers, and Unbound can encrypt the stub-to-resolver hop. Limit: plaintext port 53 remains available and is still visible to the local network.

  • City-pinned unicast DoH endpoints

    Besides global anycast, the DoH page lists per-city URLs such as de-dus, de-fra, nl-ams, uk-lon, ee-tll, and several non-EU cities. Hosting providers are named per row (mostly xTom, plus HostVenom, DigitalOcean, Amazon AWS, Servers.com, Vultr, Misaka). Benefit: an admin can pin the resolver hop to a chosen metro. Limit: anycast IPs still land on the nearest global node, including US cities, unless you pin unicast.

  • Claimed no-logs resolver with DNSSEC and no ECS

    Privacy policy and FAQ say query names, client IPs, and timestamps are not stored, EDNS Client Subnet is off, query name minimisation (RFC 7816) is on, and the resolver validates DNSSEC. Benefit: less data handed to authoritative servers and, if the claim holds, nothing to disclose. Limit: the software stack is undisclosed and no independent no-logs audit was found.

  • Unfiltered recursion (legal caveats reserved)

    FAQ: no content filtering or blocking; users keep control. A separate FAQ bullet reserves blocking for legal requirements. Benefit: usable as a neutral upstream under a local filter like Pi-hole. Limit: no malware or ad blocklist on the resolver, and legal orders could still force a block.

Leaseweb CDN

  • Four-provider Multi-CDN (400+ PoPs claimed)

    Leaseweb sells a managed mix of four unnamed third-party CDNs and claims more than 400 points of presence. One distribution CNAME (examples in docs: di-xxxx.leasewebultracdn.com, *.pr.lswcdn.net, *.vo.lswcdn.net) fronts the mix. Features are limited to the common subset all four support. You cannot pin a user to a specific PoP.

  • NS1 Pulsar Volume and Premium steering

    Leaseweb says it connects partner performance to NS1 Pulsar real-user metrics. Volume tier chooses the most cost-effective partner at similar latency. Premium tier chooses on latency and quality of experience. Regional DNS logic can still send a whole region to a single partner when that path is faster.

  • Origin shields in Amsterdam and Washington, D.C.

    Shield CDN distributions add a Leaseweb cache layer so partner edges do not all hit origin. Marketing states shields are included on Volume and Premium and sit in Amsterdam and Washington, D.C. Shields support multiple path policies, origin groups (up to 10 hosts, round-robin, consistent, sticky, or failover), and tokenized URLs. Wildcard invalidation is not supported on shields. A Multi-CDN invalidation does not clear the shield automatically.

  • HTTP, S3, and object-storage origins

    Simple origins take a hostname or IP. AWS Signature Version 4 can authenticate S3-compatible buckets (Leaseweb Object Storage or AWS). Advanced origins (custom ports, subdirectory) work only behind shields and do not support Sig V4. Authenticated object storage cannot join an origin group. Each origin is HTTP or HTTPS exclusively, not mixed.

  • Portal, REST API, and raw logs to S3

    Distributions, origins, certificates, and invalidations are managed in the Leaseweb Customer Portal (CDN menu, active contract required) or via the documented REST API on developer.leaseweb.com. Raw logs from all partners can be normalized to JSON and uploaded as .gz files to a customer S3 bucket. Leaseweb states logs are informational only and may be delayed or incomplete versus billing records.

  • Cache templates and edge ACLs

    Web, live, and VoD templates set methods, TTL, compression, and stale-serve defaults. Operators can force CDN-controlled or origin-controlled cache, passthrough or static headers, geo blocking, IP-subnet blocking, and referrer allowlists. HTTP/2 is default on all partners. Gzip delivery compression applies only to files up to 20 MB. CORS Access-Control-Allow-Origin is stripped unless you passthrough or set it.

Assurance & compliance: DNS.SB vs Leaseweb CDN
Assurance & complianceLogo: DNS.SBDNS.SBLogo: Leaseweb CDNLeaseweb CDN
Independent security / no-logs audit
Not found

Vendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed.

Not found

Multi-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found.

ISO 27001
Not found

No ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed.

Vendor claimed

ISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope.

SOC 2 / SOC 3
Not found

No SOC 2 or SOC 3 claim found on the official pages reviewed.

Partial

SOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN.

GDPR / EU data protection
Vendor claimed

German controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests.

Vendor claimed

EU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice.

Partial

Dutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA. Free service is personal/non-commercial; commercial terms are by contact only.

Vendor claimed

Vendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled.

EU AI Act
Not applicable

Public DNS resolver, not an AI system.

Not applicable

Content delivery and traffic steering product, not an AI system offering.

PCI DSSNot listed
Partial

Vendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control.

CISPE IaaS Code of ConductNot listed
Vendor claimed

Company says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register.

Considerations & known limitations: DNS.SB vs Leaseweb CDN
Considerations & known limitationsLogo: DNS.SBDNS.SBLogo: Leaseweb CDNLeaseweb CDN
No-logs policy is unaudited
Medium

Privacy policy and FAQ say query logging is off. There is no independent audit, and the resolver software is not disclosed. Practical impact: you cannot show a third-party report to a security reviewer.

Not listed
Global anycast and US-group PoP hosts
Medium

Default anycast can land on US and other non-EU nodes. Published unicast DoH uses Amazon AWS, DigitalOcean, Vultr, HostVenom, Servers.com, and Misaka in addition to xTom. Practical impact: EU-only query residency is not the default and is not contractual.

Not listed
Free pool is not a commercial DNS contract
Medium

Terms restrict free use to personal and non-commercial cases. No SLA, no public DPA, services provided as-is. Practical impact: embedding DNS.SB in a product or relying on it for production without a license is out of policy.

Not listed
No resolver-side threat blocking
Low

Unfiltered by design, with a legal-requirements caveat. Practical impact: malware and phishing names resolve unless you filter locally or pick a protective resolver.

Not listed
No DNS64 and no native DoQ
Low

FAQ: DNS64 is not offered; native DoQ is under evaluation; DoH over HTTP/3 is available. Practical impact: NAT64-only clients and DoQ-only stubs need another resolver.

Not listed
Unnamed partner CDNs and NS1 in the data pathNot listed
High

Delivery and RUM leave Leaseweb facilities. The four partners are not named on public product or legal pages. NS1 Pulsar steers requests. Treat as a multi-processor design until sales produces a current list and DPA schedule.

Washington, D.C. origin shieldNot listed
Medium

Included shields are in Amsterdam and Washington, D.C. Enabling a shield can place origin-pull traffic in the United States even when the sales entity is Dutch. Live streaming docs also advise against shields for latency reasons.

ISO / SOC reports do not list CDNNot listed
Medium

Published ISO 27001 and SOC 1 service lists omit CDN. SOC 2 is Canada colocation only. Do not assume Multi-CDN inherits those reports without a scoped letter.

Features limited to partner intersectionNot listed
Medium

No Multi-CDN URL tokens, no PoP pin, Gzip-only compression with a 20 MB cap, no MPEG-DASH Gzip, mixed origin HTTP/HTTPS unsupported, invalidation rate-limited. SSL and stats propagate on partner clocks.

Raw logs not billed as completeNot listed
Low

Partner logs shipped to S3 are informational. Leaseweb states they may be late or missing versus invoice counters. Do not use them as a legal completeness record.

Fit

DNS.SB

Best fit when

  • Homelabs and small networks that want a German-operated public resolver with addresses people can remember
  • Teams that already filter locally (Pi-hole, AdGuard Home, Unbound) and need a neutral encrypted upstream
  • Users who want DoT (dot.sb) or DoH without an account or client app
  • Operators who will pin a named EU/UK unicast DoH city instead of trusting global anycast
  • Personal and non-commercial use allowed by the published terms

Poor fit when

  • Regulated or commercial production DNS that needs a signed DPA, SLA, or prior commercial license
  • Anyone who needs resolver-side malware, ads, or family filtering
  • EU-only data residency requirements if you stay on anycast or non-EU unicast cities
  • IPv6-only NAT64 networks that need DNS64
  • Buyers who require an independent no-logs audit or a disclosed resolver software stack

Consider instead when

  • When: You want threat blocking at the resolver, not a neutral recursive cache

    Consider: Quad9 (Swiss foundation, not yet in this catalog) or a protective DNS4EU profile

    DNS.SB documents an unfiltered policy aside from legal requirements.

  • When: You need a signed DPA, SLA, or EU-only query path under contract

    Consider: Self-hosted Unbound or Knot Resolver, or a commercial recursive DNS with a written DPA

    Free DNS.SB is personal/non-commercial; city pins are operational, not a contract.

  • When: You need a full-tunnel VPN plus resolver under one European vendor

    Consider: Mullvad

    Different product class. Mullvad is a VPN, not a standalone public DNS.

Leaseweb CDN

Best fit when

  • Teams already on Leaseweb dedicated servers, object storage, or private cloud who want delivery on the same invoice
  • Media, ads, SaaS, or gaming publishers who want multi-CDN failover without four vendor contracts
  • Origins that can sit behind an Amsterdam or Washington, D.C. shield and pull over HTTP or HTTPS (or S3 with Sig V4)
  • Operators who will live with partner-subset features (HTTP/2, geo/IP/referrer ACLs, portal and REST API) rather than Workers-style compute
  • Buyers who can accept Volume (cost) versus Premium (QoE) steering instead of pinning a single CDN

Poor fit when

  • Organizations that require an EU-only edge with a public, named subprocessor list (partners are unnamed; WDC shield and NS1 are in path)
  • Sites that need signed URLs, a WAF, bot management, or edge functions on the same product
  • Teams that must purge thousands of URLs per minute or treat invalidation as the publish pipeline
  • Buyers who want a self-serve free tier or an open-source, self-hosted CDN
  • Workloads that need MPEG-DASH Gzip, mixed HTTP and HTTPS to one origin, or per-user PoP selection

Consider instead when

  • When: You need a single global edge with WAF, bot management, Workers, and a self-serve free tier

    Consider: Cloudflare

    US company. Broader edge platform. Different jurisdiction story.

  • When: You want CDN plus compute from one European infrastructure group and can diligence that group's own PoPs

    Consider: OVHcloud

    French operator. Own datacentres. Not a four-provider multi-CDN.

  • When: You mainly need EU origin compute and will add a CDN you can inventory yourself

    Consider: Hetzner or Scaleway

    Neither replaces Multi-CDN. They keep origin in EU facilities you can name.

  • When: You wanted Swiss-branded hosting with optional Cloudflare, not a multi-CDN fabric

    Consider: Swissnode

    Different product class. Optional Cloudflare on web plans.

Open questions for due diligence

DNS.SB

  • Will xTom sign a DPA and publish a complete subprocessor list for commercial DNS.SB use?
  • Can they contractually pin recursion to named EU cities (not just publish unicast URLs)?
  • Will they commission an independent no-logs or resolver-security audit and name the software?
  • What process would force query logging or blocking beyond the current legal-requirements caveat?
  • What infrastructure sits behind the advertised global DoH CDN endpoint besides the named unicast PoPs?

Leaseweb CDN

  • What are the current four partner CDN legal names, and can they be listed in the DPA?
  • Can routing be constrained to EU (or named) partners and the Amsterdam shield only?
  • Is Multi-CDN in the current ISO 27001 statement of applicability?
  • Will Leaseweb sign a standalone DPA that covers NS1 Pulsar and each partner?
  • What is the current annual-commitment commercial offer (confirm on the official Multi-CDN page or with sales)?