Logo: UncensoredDNS

UncensoredDNS

Danish volunteer public DNS resolver with encrypted-only DoT, DoH, and DoQ. Unfiltered lookups, unicast in the Copenhagen area, anycast that includes a US node.

UncensoredDNS is a free public recursive DNS resolver operated from Denmark by Thomas Steen Rasmussen as a private individual. The project started in 2009 after he had to run the filtered resolvers that Danish ISPs use for court-ordered and industry DNS blocks. He built a small uncensored alternative so friends and the public would not have to send every lookup to an ISP filter or a large US platform resolver.

The service publishes two endpoints anyone can use: anycast.uncensoreddns.org (91.239.100.100 and 2001:67c:28a4::) and unicast.uncensoreddns.org in the Copenhagen area (89.233.43.71 and 2a01:3a0:53:53::). Since October 2022 it answers only encrypted transports. DNS-over-TLS and DNS-over-HTTPS have been the baseline, and on 23 October 2025 the operator enabled DNS-over-QUIC (UDP/853) and DNS-over-HTTP/3 (UDP/443).

The practical differentiator is a no-filter policy plus published TLS public keys for pinning, not a corporate anycast fleet. It is not a company with a DPA, SLA, or EU-only node map. The published anycast table includes two DeiC nodes in Lyngby, Denmark and one rgnet node in Washington, USA, so some clients will land outside the EU.

Danish-operatedEncrypted DNS onlyNo filter listsNo-logs (claimed)Free public resolver

Shortlist when you want an unfiltered, encrypt-only public resolver run by a named Danish operator and you can configure DoT, DoH, or DoQ. Skip when you need a DPA, malware blocking, EU-only anycast, or a staffed SLA. Use unicast for Denmark-local queries. Consider Quad9 when you want resolver-side threat blocking, or Cloudflare / Google Public DNS when you need a mass-market anycast default.

Key capabilities

Since October 2022 the resolvers do not answer classic UDP/TCP port 53. Clients use DNS-over-TLS on 853, DNS-over-HTTPS at /dns-query on 443, and (from 23 October 2025) DNS-over-QUIC on UDP/853 plus DNS-over-HTTP/3 on UDP/443. Devices that can only speak cleartext DNS will fail.

The service is built to skip ISP and court-style DNS blocklists that Danish providers apply. It does not offer malware, ad, or family filter modes. Choose it when you want NXDOMAIN to mean the name does not exist, not that a resolver policy hid it.

anycast.uncensoreddns.org uses 91.239.100.100 and 2001:67c:28a4::. unicast.uncensoreddns.org uses 89.233.43.71 and 2a01:3a0:53:53:: at AS9167 in Høje Tåstrup. The operator says the anycast prefix is provider-independent and unlikely to change. Legacy names under censurfridns.dk still work.

Each listed node publishes RSA and ECDSA TLS public keys on the DNS Servers page. DoT originally shipped with TLSA records so clients such as Stubby can pin. Key rotation (ECDSA introduction in 2020) can break pinsets until operators update them.

The censurfridns/client-configs GitHub repo documents Firefox, Edge, iOS profiles, systemd-resolved, pfSense, OPNsense, OpenWrt, and Unbound. This is community documentation for a public resolver, not a supported enterprise client.

At a glance

Operator
Thomas Steen Rasmussen, private individual, Denmark
Started
November 2009 (censurfridns.dk registered 15 November 2009)
Commercial model
Free public service; optional GitHub Sponsors donations
Protocols
DoT :853, DoH /dns-query, DoQ UDP/853, DoH3 UDP/443; no port 53
Anycast
91.239.100.100 / 2001:67c:28a4:: (DeiC Lyngby + rgnet Washington)
Unicast
89.233.43.71 / 2a01:3a0:53:53:: at AS9167, Høje Tåstrup
Legal entity
No company imprint found
Independent audit
None found

Best fit when

  • Households and labs leaving filtered Danish ISP DNS who can speak DoT, DoH, or DoQ
  • Admins who want NXDOMAIN to mean the name does not exist, not a resolver policy
  • Router and homelab setups (pfSense, OPNsense, OpenWrt, systemd-resolved) using the published client notes
  • Buyers who prefer a named European individual over sending every lookup to Google or Cloudflare
  • Teams that can pin TLS keys and accept a volunteer-run service without an SLA

Poor fit when

  • Procurement that requires a company imprint, signed DPA, or ISO/SOC package
  • Policies that require EU-only query landing (anycast includes Washington, USA)
  • Need for malware, ad, or family filtering at the resolver
  • Devices or DHCP that can only use cleartext UDP/TCP port 53
  • A regulated resolver dependency that needs staffed on-call and a status SLA

Consider instead when

  • When: You want resolver-side malware blocking with a European-adjacent operator

    Consider: Quad9

    Quad9 is a filtered secure resolver. UncensoredDNS will not apply those blocks.

  • When: You need configurable profiles, analytics, or family filters

    Consider: NextDNS or AdGuard DNS

    Those are policy platforms. UncensoredDNS has no per-user console.

  • When: You need a mass-market anycast default and OS-level presets

    Consider: Cloudflare 1.1.1.1 or Google Public DNS

    Larger footprint and still offer cleartext 53. They are US-group services.

  • When: Every query must stay inside your EU tenancy

    Consider: Self-hosted Unbound or Knot Resolver on your own metal

    UncensoredDNS anycast can land on the published US node.

Jurisdiction & ownership

Legal entity
No company published. Operator: Thomas Steen Rasmussen (private individual).
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Unicast at AS9167 (Høje Tåstrup, Denmark, sponsor tyktech). Anycast nodes: two at DeiC in Lyngby, Denmark (AS1835) and one at rgnet in Washington, USA (AS3927). No public backup, email, or analytics subprocessor list.

No known US parent. Anycast includes a US PoP, so some queries can be answered in the United States. Indicative only, not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionPartial
  • +3

Considerations & known limitations

  • HighSingle-person operation

    The service is run by one named individual with donated nodes. There is no published company, on-call roster, or SLA. Sponsor withdrawals have already removed anycast sites.

  • MediumUS anycast node on the public map

    rgnet-iad.anycast.uncensoreddns.org is listed in Washington, USA. Anycast clients cannot pin Denmark. Use the unicast hostname if EU landing matters.

  • MediumNo public independent audit

    No-logs is a first-party FAQ statement. No audit, ISO, or SOC package was found for a security review file.

  • LowNo classic port 53

    Cleartext DNS has been off since October 2022. Guest devices, some IoT, and default DHCP resolvers will not work without a local forwarder that speaks DoT or DoH.

Open questions for due diligence

  • Will the operator form a legal entity or sign a DPA for organisational use?
  • Is there a way to pin anycast to EU nodes only, or should EU-only buyers use unicast exclusively?
  • Is an independent no-logs or infrastructure audit planned?
  • Does the recursor validate DNSSEC for all clients? (not stated as a current guarantee on the pages reviewed)
  • What subprocessors, if any, sit on the blog, email, or monitoring path?

Frequently Asked Questions

No public DPA, company imprint, or B2B processing addendum was found. The operator is a named private individual in Denmark. If your GDPR article 28 process requires a legal entity and a signed processor agreement, this service is not packaged for that. Confirm directly with admin@censurfridns.dk before treating it as a processor.

Not guaranteed. The published anycast table includes two DeiC nodes in Lyngby, Denmark and one rgnet node in Washington, USA. Routing decides which node answers. For a Denmark-local listener, the operator documents unicast.uncensoreddns.org at AS9167 in Høje Tåstrup. There is no client control plane to pin a country.

Only encrypted transports. DoT and DoH have been the supported pair since the October 2022 port 53 shutdown (brownout 1 September 2022, permanent 1 October 2022). DoQ and DoH3 were added on 23 October 2025. Plain UDP/TCP 53 and the old 5353 listener are gone, which also removed a UDP amplification surface the operator described in 2022.

No. The project exists because the operator opposes using DNS as a content filter. There are no published threat feeds, allowlists, or per-user policies. If you need resolver-side malware blocking, Quad9 is the closer European-adjacent peer. If you need configurable filters, look at a policy resolver instead.

Continuity depends on one operator plus donated anycast VMs with BGP. Sponsor nodes have been withdrawn (Bornfiber and Solido in 2021, Kracon in October 2024). There is no published status page SLA or on-call roster. That is acceptable for a lab or household. It is a hard stop for a regulated resolver dependency.