Leaseweb CDN vs UncensoredDNS

Compare Leaseweb CDN y UncensoredDNS en capacidades, jurisdicción, garantías y encaje para compradores europeos.

Ambos figuran como alternativas a: Cloudflare

Logo: Leaseweb CDN

Leaseweb CDN

Netherlands· Web Hosting and Cloud Computing

Needs review

Shortlist when you want a Dutch (or other local Leaseweb) B2B contract that fronts four partner CDNs with NS1 Pulsar steering and included Amsterdam or Washington, D.C. origin shields. Skip when you need EU-only processors, named partner inventory up front, Cloudflare-class WAF or Workers, or signed URLs without a shield hop. Consider Cloudflare for a single global edge platform, or OVHcloud if you want a French-operated CDN attached to EU datacentres.

Dutch sales entityMulti-CDN (4 partners)Origin shield (AMS + WDC)Portal + REST APIISO 27001 (company, claimed)
Logo: UncensoredDNS

UncensoredDNS

Denmark· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, encrypt-only public resolver run by a named Danish operator and you can configure DoT, DoH, or DoQ. Skip when you need a DPA, malware blocking, EU-only anycast, or a staffed SLA. Use unicast for Denmark-local queries. Consider Quad9 when you want resolver-side threat blocking, or Cloudflare / Google Public DNS when you need a mass-market anycast default.

Danish-operatedEncrypted DNS onlyNo filter listsNo-logs (claimed)Free public resolver
Leaseweb CDN vs UncensoredDNS: Resumen
CaracterísticaLogo: Leaseweb CDNLeaseweb CDNLogo: UncensoredDNSUncensoredDNS
País de origenNetherlandsDenmark
CategoríaWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Código abiertoNoNo
AutoalojadoNoNo
SedeNetherlandsDenmark
Entidad legalLeaseweb Netherlands B.V. (KvK 30141839, Amsterdam). Website: Leaseweb Global B.V. (KvK 60593652). Other local sales entities exist.No company published. Operator: Thomas Steen Rasmussen (private individual).
Matriz / control EE.UU.Sin matriz estadounidense conocidaSin matriz estadounidense conocida
Exposición CLOUD Act (indicativa)MedioMedio
Alojamiento / residenciaDelivery is a mix of four unnamed third-party CDNs (global PoPs). Leaseweb origin shields in Amsterdam and Washington, D.C. Request steering via NS1 Pulsar. Origins may be customer HTTP hosts or S3-compatible buckets (including AWS). Raw logs (including client IP) collected from partners and optionally written to customer S3. No public CDN subprocessor list naming the four partners.Unicast at AS9167 (Høje Tåstrup, Denmark, sponsor tyktech). Anycast nodes: two at DeiC in Lyngby, Denmark (AS1835) and one at rgnet in Washington, USA (AS3927). No public backup, email, or analytics subprocessor list.
Resumen

Dutch Multi-CDN that steers traffic across four partner networks with NS1 Pulsar, plus included origin shields in Amsterdam and Washington, D.C. Sold under local Leaseweb sales entities.

Danish volunteer public DNS resolver with encrypted-only DoT, DoH, and DoQ. Unfiltered lookups, unicast in the Copenhagen area, anycast that includes a US node.

Etiquetas
De un vistazo: Leaseweb CDN vs UncensoredDNS
De un vistazoLogo: Leaseweb CDNLeaseweb CDNLogo: UncensoredDNSUncensoredDNS
HQAmsterdam, NetherlandsNo indicado
Website operatorLeaseweb Global B.V. (KvK 60593652)No indicado
Typical NL contractLeaseweb Netherlands B.V. (KvK 30141839)No indicado
Founded1997 (vendor, 2023 press)No indicado
Product typeManaged Multi-CDN (not self-hosted, not open source)No indicado
EdgeFour unnamed partner CDNs, 400+ PoPs (vendor claim)No indicado
Shield locationsAmsterdam and Washington, D.C.No indicado
SteeringNS1 Pulsar (Volume: cost; Premium: QoE)No indicado
Commercial modelB2B traffic tiers, annual commitmentFree public service; optional GitHub Sponsors donations
OperatorNo indicadoThomas Steen Rasmussen, private individual, Denmark
StartedNo indicadoNovember 2009 (censurfridns.dk registered 15 November 2009)
ProtocolsNo indicadoDoT :853, DoH /dns-query, DoQ UDP/853, DoH3 UDP/443; no port 53
AnycastNo indicado91.239.100.100 / 2001:67c:28a4:: (DeiC Lyngby + rgnet Washington)
UnicastNo indicado89.233.43.71 / 2a01:3a0:53:53:: at AS9167, Høje Tåstrup
Legal entityNo indicadoNo company imprint found
Independent auditNo indicadoNone found
Key capabilities: Leaseweb CDN vs UncensoredDNS
Key capabilitiesLogo: Leaseweb CDNLeaseweb CDNLogo: UncensoredDNSUncensoredDNS
Dutch sales entityNo indicado
Multi-CDN (4 partners)No indicado
Origin shield (AMS + WDC)No indicado
Portal + REST APINo indicado
ISO 27001 (company, claimed)No indicado
Danish-operatedNo indicado
Encrypted DNS onlyNo indicado
No filter listsNo indicado
No-logs (claimed)No indicado
Free public resolverNo indicado

Leaseweb CDN

  • Four-provider Multi-CDN (400+ PoPs claimed)

    Leaseweb sells a managed mix of four unnamed third-party CDNs and claims more than 400 points of presence. One distribution CNAME (examples in docs: di-xxxx.leasewebultracdn.com, *.pr.lswcdn.net, *.vo.lswcdn.net) fronts the mix. Features are limited to the common subset all four support. You cannot pin a user to a specific PoP.

  • NS1 Pulsar Volume and Premium steering

    Leaseweb says it connects partner performance to NS1 Pulsar real-user metrics. Volume tier chooses the most cost-effective partner at similar latency. Premium tier chooses on latency and quality of experience. Regional DNS logic can still send a whole region to a single partner when that path is faster.

  • Origin shields in Amsterdam and Washington, D.C.

    Shield CDN distributions add a Leaseweb cache layer so partner edges do not all hit origin. Marketing states shields are included on Volume and Premium and sit in Amsterdam and Washington, D.C. Shields support multiple path policies, origin groups (up to 10 hosts, round-robin, consistent, sticky, or failover), and tokenized URLs. Wildcard invalidation is not supported on shields. A Multi-CDN invalidation does not clear the shield automatically.

  • HTTP, S3, and object-storage origins

    Simple origins take a hostname or IP. AWS Signature Version 4 can authenticate S3-compatible buckets (Leaseweb Object Storage or AWS). Advanced origins (custom ports, subdirectory) work only behind shields and do not support Sig V4. Authenticated object storage cannot join an origin group. Each origin is HTTP or HTTPS exclusively, not mixed.

  • Portal, REST API, and raw logs to S3

    Distributions, origins, certificates, and invalidations are managed in the Leaseweb Customer Portal (CDN menu, active contract required) or via the documented REST API on developer.leaseweb.com. Raw logs from all partners can be normalized to JSON and uploaded as .gz files to a customer S3 bucket. Leaseweb states logs are informational only and may be delayed or incomplete versus billing records.

  • Cache templates and edge ACLs

    Web, live, and VoD templates set methods, TTL, compression, and stale-serve defaults. Operators can force CDN-controlled or origin-controlled cache, passthrough or static headers, geo blocking, IP-subnet blocking, and referrer allowlists. HTTP/2 is default on all partners. Gzip delivery compression applies only to files up to 20 MB. CORS Access-Control-Allow-Origin is stripped unless you passthrough or set it.

UncensoredDNS

  • Encrypted-only recursive DNS

    Since October 2022 the resolvers do not answer classic UDP/TCP port 53. Clients use DNS-over-TLS on 853, DNS-over-HTTPS at /dns-query on 443, and (from 23 October 2025) DNS-over-QUIC on UDP/853 plus DNS-over-HTTP/3 on UDP/443. Devices that can only speak cleartext DNS will fail.

  • Unfiltered public resolution

    The service is built to skip ISP and court-style DNS blocklists that Danish providers apply. It does not offer malware, ad, or family filter modes. Choose it when you want NXDOMAIN to mean the name does not exist, not that a resolver policy hid it.

  • Anycast plus Danish unicast endpoints

    anycast.uncensoreddns.org uses 91.239.100.100 and 2001:67c:28a4::. unicast.uncensoreddns.org uses 89.233.43.71 and 2a01:3a0:53:53:: at AS9167 in Høje Tåstrup. The operator says the anycast prefix is provider-independent and unlikely to change. Legacy names under censurfridns.dk still work.

  • Published TLS pins per node

    Each listed node publishes RSA and ECDSA TLS public keys on the DNS Servers page. DoT originally shipped with TLSA records so clients such as Stubby can pin. Key rotation (ECDSA introduction in 2020) can break pinsets until operators update them.

  • Router and OS client notes

    The censurfridns/client-configs GitHub repo documents Firefox, Edge, iOS profiles, systemd-resolved, pfSense, OPNsense, OpenWrt, and Unbound. This is community documentation for a public resolver, not a supported enterprise client.

Assurance & compliance: Leaseweb CDN vs UncensoredDNS
Assurance & complianceLogo: Leaseweb CDNLeaseweb CDNLogo: UncensoredDNSUncensoredDNS
Independent security / no-logs audit
Not found

Multi-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found.

Not found

FAQ claims no personal logs and aggregate graphs only. No third-party audit PDF found.

ISO 27001
Vendor claimed

ISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope.

Not found
SOC 2 / SOC 3
Partial

SOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN.

Not found
GDPR / EU data protection
Vendor claimed

EU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed.

Partial

Danish individual operator and a no-logs claim on the FAQ. No formal privacy policy or DPA page found.

US CLOUD Act exposure (indicative)
Partial

Dutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice.

Partial

No known US parent. Published anycast includes rgnet in Washington, USA (AS3927), so some queries can be answered on US soil. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled.

Not found

No company imprint or processor agreement found. Operator contact is admin@censurfridns.dk.

EU AI Act
Not applicable

Content delivery and traffic steering product, not an AI system offering.

Not applicable

Public recursive DNS resolver, not an AI system.

PCI DSS
Partial

Vendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control.

No indicado
CISPE IaaS Code of Conduct
Vendor claimed

Company says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register.

No indicado
Considerations & known limitations: Leaseweb CDN vs UncensoredDNS
Considerations & known limitationsLogo: Leaseweb CDNLeaseweb CDNLogo: UncensoredDNSUncensoredDNS
Unnamed partner CDNs and NS1 in the data path
High

Delivery and RUM leave Leaseweb facilities. The four partners are not named on public product or legal pages. NS1 Pulsar steers requests. Treat as a multi-processor design until sales produces a current list and DPA schedule.

No indicado
Washington, D.C. origin shield
Medium

Included shields are in Amsterdam and Washington, D.C. Enabling a shield can place origin-pull traffic in the United States even when the sales entity is Dutch. Live streaming docs also advise against shields for latency reasons.

No indicado
ISO / SOC reports do not list CDN
Medium

Published ISO 27001 and SOC 1 service lists omit CDN. SOC 2 is Canada colocation only. Do not assume Multi-CDN inherits those reports without a scoped letter.

No indicado
Features limited to partner intersection
Medium

No Multi-CDN URL tokens, no PoP pin, Gzip-only compression with a 20 MB cap, no MPEG-DASH Gzip, mixed origin HTTP/HTTPS unsupported, invalidation rate-limited. SSL and stats propagate on partner clocks.

No indicado
Raw logs not billed as complete
Low

Partner logs shipped to S3 are informational. Leaseweb states they may be late or missing versus invoice counters. Do not use them as a legal completeness record.

No indicado
Single-person operationNo indicado
High

The service is run by one named individual with donated nodes. There is no published company, on-call roster, or SLA. Sponsor withdrawals have already removed anycast sites.

US anycast node on the public mapNo indicado
Medium

rgnet-iad.anycast.uncensoreddns.org is listed in Washington, USA. Anycast clients cannot pin Denmark. Use the unicast hostname if EU landing matters.

No public independent auditNo indicado
Medium

No-logs is a first-party FAQ statement. No audit, ISO, or SOC package was found for a security review file.

No classic port 53No indicado
Low

Cleartext DNS has been off since October 2022. Guest devices, some IoT, and default DHCP resolvers will not work without a local forwarder that speaks DoT or DoH.

Encaje

Leaseweb CDN

Best fit when

  • Teams already on Leaseweb dedicated servers, object storage, or private cloud who want delivery on the same invoice
  • Media, ads, SaaS, or gaming publishers who want multi-CDN failover without four vendor contracts
  • Origins that can sit behind an Amsterdam or Washington, D.C. shield and pull over HTTP or HTTPS (or S3 with Sig V4)
  • Operators who will live with partner-subset features (HTTP/2, geo/IP/referrer ACLs, portal and REST API) rather than Workers-style compute
  • Buyers who can accept Volume (cost) versus Premium (QoE) steering instead of pinning a single CDN

Poor fit when

  • Organizations that require an EU-only edge with a public, named subprocessor list (partners are unnamed; WDC shield and NS1 are in path)
  • Sites that need signed URLs, a WAF, bot management, or edge functions on the same product
  • Teams that must purge thousands of URLs per minute or treat invalidation as the publish pipeline
  • Buyers who want a self-serve free tier or an open-source, self-hosted CDN
  • Workloads that need MPEG-DASH Gzip, mixed HTTP and HTTPS to one origin, or per-user PoP selection

Consider instead when

  • When: You need a single global edge with WAF, bot management, Workers, and a self-serve free tier

    Consider: Cloudflare

    US company. Broader edge platform. Different jurisdiction story.

  • When: You want CDN plus compute from one European infrastructure group and can diligence that group's own PoPs

    Consider: OVHcloud

    French operator. Own datacentres. Not a four-provider multi-CDN.

  • When: You mainly need EU origin compute and will add a CDN you can inventory yourself

    Consider: Hetzner or Scaleway

    Neither replaces Multi-CDN. They keep origin in EU facilities you can name.

  • When: You wanted Swiss-branded hosting with optional Cloudflare, not a multi-CDN fabric

    Consider: Swissnode

    Different product class. Optional Cloudflare on web plans.

UncensoredDNS

Best fit when

  • Households and labs leaving filtered Danish ISP DNS who can speak DoT, DoH, or DoQ
  • Admins who want NXDOMAIN to mean the name does not exist, not a resolver policy
  • Router and homelab setups (pfSense, OPNsense, OpenWrt, systemd-resolved) using the published client notes
  • Buyers who prefer a named European individual over sending every lookup to Google or Cloudflare
  • Teams that can pin TLS keys and accept a volunteer-run service without an SLA

Poor fit when

  • Procurement that requires a company imprint, signed DPA, or ISO/SOC package
  • Policies that require EU-only query landing (anycast includes Washington, USA)
  • Need for malware, ad, or family filtering at the resolver
  • Devices or DHCP that can only use cleartext UDP/TCP port 53
  • A regulated resolver dependency that needs staffed on-call and a status SLA

Consider instead when

  • When: You want resolver-side malware blocking with a European-adjacent operator

    Consider: Quad9

    Quad9 is a filtered secure resolver. UncensoredDNS will not apply those blocks.

  • When: You need configurable profiles, analytics, or family filters

    Consider: NextDNS or AdGuard DNS

    Those are policy platforms. UncensoredDNS has no per-user console.

  • When: You need a mass-market anycast default and OS-level presets

    Consider: Cloudflare 1.1.1.1 or Google Public DNS

    Larger footprint and still offer cleartext 53. They are US-group services.

  • When: Every query must stay inside your EU tenancy

    Consider: Self-hosted Unbound or Knot Resolver on your own metal

    UncensoredDNS anycast can land on the published US node.

Open questions for due diligence

Leaseweb CDN

  • What are the current four partner CDN legal names, and can they be listed in the DPA?
  • Can routing be constrained to EU (or named) partners and the Amsterdam shield only?
  • Is Multi-CDN in the current ISO 27001 statement of applicability?
  • Will Leaseweb sign a standalone DPA that covers NS1 Pulsar and each partner?
  • What is the current annual-commitment commercial offer (confirm on the official Multi-CDN page or with sales)?

UncensoredDNS

  • Will the operator form a legal entity or sign a DPA for organisational use?
  • Is there a way to pin anycast to EU nodes only, or should EU-only buyers use unicast exclusively?
  • Is an independent no-logs or infrastructure audit planned?
  • Does the recursor validate DNSSEC for all clients? (not stated as a current guarantee on the pages reviewed)
  • What subprocessors, if any, sit on the blog, email, or monitoring path?