DNS.SB vs UncensoredDNS

Comparez DNS.SB et UncensoredDNS sur les capacités, la juridiction, les garanties et l'adéquation pour les acheteurs européens.

Tous deux listés comme alternatives à: Cloudflare, Google Public DNS

Logo: DNS.SB

DNS.SB

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, German-operated public resolver with DoT/DoH and optional city-pinned endpoints. Skip when you need malware blocking, a signed DPA or SLA on the free pool, or a guarantee that queries never leave the EU. Consider Quad9 for threat blocking or run your own recursive resolver when residency must be yours.

EU-operatedNo-logs (claimed)DoT + DoHUnfilteredAnycast + unicast pin
Logo: UncensoredDNS

UncensoredDNS

Denmark· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, encrypt-only public resolver run by a named Danish operator and you can configure DoT, DoH, or DoQ. Skip when you need a DPA, malware blocking, EU-only anycast, or a staffed SLA. Use unicast for Denmark-local queries. Consider Quad9 when you want resolver-side threat blocking, or Cloudflare / Google Public DNS when you need a mass-market anycast default.

Danish-operatedEncrypted DNS onlyNo filter listsNo-logs (claimed)Free public resolver
DNS.SB vs UncensoredDNS: Aperçu
CaractéristiqueLogo: DNS.SBDNS.SBLogo: UncensoredDNSUncensoredDNS
Pays d'origineGermanyDenmark
CatégorieWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNonNon
Auto-hébergéNonNon
SiègeGermanyDenmark
Entité légalexTom GmbH, Kreuzstraße 60, 40210 Düsseldorf (Amtsgericht Düsseldorf HRB 86779)No company published. Operator: Thomas Steen Rasmussen (private individual).
Maison mère / contrôle USAucune maison mère US connueAucune maison mère US connue
Exposition CLOUD Act (indicative)MoyenMoyen
Hébergement / résidencePrimary: xTom global anycast (operator xTom GmbH, DE) with published unicast DoH cities. Named non-xTom PoP hosts: HostVenom (Chicago), DigitalOcean (Bengaluru), Amazon AWS (Seoul), Servers.com (Moscow), Vultr (Toronto), Misaka (Berlin). Website analytics: self-hosted Plausible. Backup/DR and support SaaS not published. DoH also advertised as a global CDN endpoint.Unicast at AS9167 (Høje Tåstrup, Denmark, sponsor tyktech). Anycast nodes: two at DeiC in Lyngby, Denmark (AS1835) and one at rgnet in Washington, USA (AS3927). No public backup, email, or analytics subprocessor list.
Résumé

Free public recursive DNS from Düsseldorf-based xTom GmbH, with DoT/DoH, claimed no logs, and optional city-pinned unicast endpoints.

Danish volunteer public DNS resolver with encrypted-only DoT, DoH, and DoQ. Unfiltered lookups, unicast in the Copenhagen area, anycast that includes a US node.

Tags
En un coup d'œil: DNS.SB vs UncensoredDNS
En un coup d'œilLogo: DNS.SBDNS.SBLogo: UncensoredDNSUncensoredDNS
HQDüsseldorf, GermanyNon indiqué
Legal entityxTom GmbH (HRB 86779)No company imprint found
Commercial modelFree for personal and non-commercial use; commercial use needs authorizationFree public service; optional GitHub Sponsors donations
ProtocolsDNS 53, DoT 853 (dot.sb), DoH 443 (HTTP/3); no native DoQ; no DNS64DoT :853, DoH /dns-query, DoQ UDP/853, DoH3 UDP/443; no port 53
AnycastClaimed 30+ locations on six continents, including US cities91.239.100.100 / 2001:67c:28a4:: (DeiC Lyngby + rgnet Washington)
Open sourceResolver stack not disclosed; docs site is on GitHubNon indiqué
OperatorNon indiquéThomas Steen Rasmussen, private individual, Denmark
StartedNon indiquéNovember 2009 (censurfridns.dk registered 15 November 2009)
UnicastNon indiqué89.233.43.71 / 2a01:3a0:53:53:: at AS9167, Høje Tåstrup
Independent auditNon indiquéNone found
Key capabilities: DNS.SB vs UncensoredDNS
Key capabilitiesLogo: DNS.SBDNS.SBLogo: UncensoredDNSUncensoredDNS
EU-operatedOuiOui
No-logs (claimed)OuiOui
DoT + DoHOuiNon indiqué
UnfilteredOuiNon indiqué
Anycast + unicast pinOuiNon indiqué
Encrypted DNS onlyNon indiquéOui
No filter listsNon indiquéOui
Free public resolverNon indiquéOui

DNS.SB

  • Memorable dual-stack public resolvers

    Classic DNS on UDP/TCP 53 at 185.222.222.222 and 45.11.45.11, plus IPv6 2a09:: and 2a11:: (full form published for older stacks). Dual-stack is first-class. There is no account and no client app. Benefit: routers and homelabs can be pointed at addresses people can actually remember. Limit: this is a shared public pool, not a dedicated recursive server.

  • DoT, DoH, and DoH over HTTP/3

    Encrypted DNS over TLS on hostname dot.sb port 853, and DoH at https://doh.dns.sb/dns-query (aliases doh.sb and dns.sb, plus raw IP URLs). The FAQ states DoH supports HTTP/3 (QUIC) and that native DNS-over-QUIC (RFC 9250) is not offered yet. Benefit: OS Private DNS, browsers, and Unbound can encrypt the stub-to-resolver hop. Limit: plaintext port 53 remains available and is still visible to the local network.

  • City-pinned unicast DoH endpoints

    Besides global anycast, the DoH page lists per-city URLs such as de-dus, de-fra, nl-ams, uk-lon, ee-tll, and several non-EU cities. Hosting providers are named per row (mostly xTom, plus HostVenom, DigitalOcean, Amazon AWS, Servers.com, Vultr, Misaka). Benefit: an admin can pin the resolver hop to a chosen metro. Limit: anycast IPs still land on the nearest global node, including US cities, unless you pin unicast.

  • Claimed no-logs resolver with DNSSEC and no ECS

    Privacy policy and FAQ say query names, client IPs, and timestamps are not stored, EDNS Client Subnet is off, query name minimisation (RFC 7816) is on, and the resolver validates DNSSEC. Benefit: less data handed to authoritative servers and, if the claim holds, nothing to disclose. Limit: the software stack is undisclosed and no independent no-logs audit was found.

  • Unfiltered recursion (legal caveats reserved)

    FAQ: no content filtering or blocking; users keep control. A separate FAQ bullet reserves blocking for legal requirements. Benefit: usable as a neutral upstream under a local filter like Pi-hole. Limit: no malware or ad blocklist on the resolver, and legal orders could still force a block.

UncensoredDNS

  • Encrypted-only recursive DNS

    Since October 2022 the resolvers do not answer classic UDP/TCP port 53. Clients use DNS-over-TLS on 853, DNS-over-HTTPS at /dns-query on 443, and (from 23 October 2025) DNS-over-QUIC on UDP/853 plus DNS-over-HTTP/3 on UDP/443. Devices that can only speak cleartext DNS will fail.

  • Unfiltered public resolution

    The service is built to skip ISP and court-style DNS blocklists that Danish providers apply. It does not offer malware, ad, or family filter modes. Choose it when you want NXDOMAIN to mean the name does not exist, not that a resolver policy hid it.

  • Anycast plus Danish unicast endpoints

    anycast.uncensoreddns.org uses 91.239.100.100 and 2001:67c:28a4::. unicast.uncensoreddns.org uses 89.233.43.71 and 2a01:3a0:53:53:: at AS9167 in Høje Tåstrup. The operator says the anycast prefix is provider-independent and unlikely to change. Legacy names under censurfridns.dk still work.

  • Published TLS pins per node

    Each listed node publishes RSA and ECDSA TLS public keys on the DNS Servers page. DoT originally shipped with TLSA records so clients such as Stubby can pin. Key rotation (ECDSA introduction in 2020) can break pinsets until operators update them.

  • Router and OS client notes

    The censurfridns/client-configs GitHub repo documents Firefox, Edge, iOS profiles, systemd-resolved, pfSense, OPNsense, OpenWrt, and Unbound. This is community documentation for a public resolver, not a supported enterprise client.

Assurance & compliance: DNS.SB vs UncensoredDNS
Assurance & complianceLogo: DNS.SBDNS.SBLogo: UncensoredDNSUncensoredDNS
Independent security / no-logs audit
Not found

Vendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed.

Not found

FAQ claims no personal logs and aggregate graphs only. No third-party audit PDF found.

ISO 27001
Not found

No ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed.

Not found
SOC 2 / SOC 3
Not found

No SOC 2 or SOC 3 claim found on the official pages reviewed.

Not found
GDPR / EU data protection
Vendor claimed

German controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests.

Partial

Danish individual operator and a no-logs claim on the FAQ. No formal privacy policy or DPA page found.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice.

Partial

No known US parent. Published anycast includes rgnet in Washington, USA (AS3927), so some queries can be answered on US soil. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA. Free service is personal/non-commercial; commercial terms are by contact only.

Not found

No company imprint or processor agreement found. Operator contact is admin@censurfridns.dk.

EU AI Act
Not applicable

Public DNS resolver, not an AI system.

Not applicable

Public recursive DNS resolver, not an AI system.

Considerations & known limitations: DNS.SB vs UncensoredDNS
Considerations & known limitationsLogo: DNS.SBDNS.SBLogo: UncensoredDNSUncensoredDNS
No-logs policy is unaudited
Medium

Privacy policy and FAQ say query logging is off. There is no independent audit, and the resolver software is not disclosed. Practical impact: you cannot show a third-party report to a security reviewer.

Non indiqué
Global anycast and US-group PoP hosts
Medium

Default anycast can land on US and other non-EU nodes. Published unicast DoH uses Amazon AWS, DigitalOcean, Vultr, HostVenom, Servers.com, and Misaka in addition to xTom. Practical impact: EU-only query residency is not the default and is not contractual.

Non indiqué
Free pool is not a commercial DNS contract
Medium

Terms restrict free use to personal and non-commercial cases. No SLA, no public DPA, services provided as-is. Practical impact: embedding DNS.SB in a product or relying on it for production without a license is out of policy.

Non indiqué
No resolver-side threat blocking
Low

Unfiltered by design, with a legal-requirements caveat. Practical impact: malware and phishing names resolve unless you filter locally or pick a protective resolver.

Non indiqué
No DNS64 and no native DoQ
Low

FAQ: DNS64 is not offered; native DoQ is under evaluation; DoH over HTTP/3 is available. Practical impact: NAT64-only clients and DoQ-only stubs need another resolver.

Non indiqué
Single-person operationNon indiqué
High

The service is run by one named individual with donated nodes. There is no published company, on-call roster, or SLA. Sponsor withdrawals have already removed anycast sites.

US anycast node on the public mapNon indiqué
Medium

rgnet-iad.anycast.uncensoreddns.org is listed in Washington, USA. Anycast clients cannot pin Denmark. Use the unicast hostname if EU landing matters.

No public independent auditNon indiqué
Medium

No-logs is a first-party FAQ statement. No audit, ISO, or SOC package was found for a security review file.

No classic port 53Non indiqué
Low

Cleartext DNS has been off since October 2022. Guest devices, some IoT, and default DHCP resolvers will not work without a local forwarder that speaks DoT or DoH.

Adéquation

DNS.SB

Best fit when

  • Homelabs and small networks that want a German-operated public resolver with addresses people can remember
  • Teams that already filter locally (Pi-hole, AdGuard Home, Unbound) and need a neutral encrypted upstream
  • Users who want DoT (dot.sb) or DoH without an account or client app
  • Operators who will pin a named EU/UK unicast DoH city instead of trusting global anycast
  • Personal and non-commercial use allowed by the published terms

Poor fit when

  • Regulated or commercial production DNS that needs a signed DPA, SLA, or prior commercial license
  • Anyone who needs resolver-side malware, ads, or family filtering
  • EU-only data residency requirements if you stay on anycast or non-EU unicast cities
  • IPv6-only NAT64 networks that need DNS64
  • Buyers who require an independent no-logs audit or a disclosed resolver software stack

Consider instead when

  • When: You want threat blocking at the resolver, not a neutral recursive cache

    Consider: Quad9 (Swiss foundation, not yet in this catalog) or a protective DNS4EU profile

    DNS.SB documents an unfiltered policy aside from legal requirements.

  • When: You need a signed DPA, SLA, or EU-only query path under contract

    Consider: Self-hosted Unbound or Knot Resolver, or a commercial recursive DNS with a written DPA

    Free DNS.SB is personal/non-commercial; city pins are operational, not a contract.

  • When: You need a full-tunnel VPN plus resolver under one European vendor

    Consider: Mullvad

    Different product class. Mullvad is a VPN, not a standalone public DNS.

UncensoredDNS

Best fit when

  • Households and labs leaving filtered Danish ISP DNS who can speak DoT, DoH, or DoQ
  • Admins who want NXDOMAIN to mean the name does not exist, not a resolver policy
  • Router and homelab setups (pfSense, OPNsense, OpenWrt, systemd-resolved) using the published client notes
  • Buyers who prefer a named European individual over sending every lookup to Google or Cloudflare
  • Teams that can pin TLS keys and accept a volunteer-run service without an SLA

Poor fit when

  • Procurement that requires a company imprint, signed DPA, or ISO/SOC package
  • Policies that require EU-only query landing (anycast includes Washington, USA)
  • Need for malware, ad, or family filtering at the resolver
  • Devices or DHCP that can only use cleartext UDP/TCP port 53
  • A regulated resolver dependency that needs staffed on-call and a status SLA

Consider instead when

  • When: You want resolver-side malware blocking with a European-adjacent operator

    Consider: Quad9

    Quad9 is a filtered secure resolver. UncensoredDNS will not apply those blocks.

  • When: You need configurable profiles, analytics, or family filters

    Consider: NextDNS or AdGuard DNS

    Those are policy platforms. UncensoredDNS has no per-user console.

  • When: You need a mass-market anycast default and OS-level presets

    Consider: Cloudflare 1.1.1.1 or Google Public DNS

    Larger footprint and still offer cleartext 53. They are US-group services.

  • When: Every query must stay inside your EU tenancy

    Consider: Self-hosted Unbound or Knot Resolver on your own metal

    UncensoredDNS anycast can land on the published US node.

Open questions for due diligence

DNS.SB

  • Will xTom sign a DPA and publish a complete subprocessor list for commercial DNS.SB use?
  • Can they contractually pin recursion to named EU cities (not just publish unicast URLs)?
  • Will they commission an independent no-logs or resolver-security audit and name the software?
  • What process would force query logging or blocking beyond the current legal-requirements caveat?
  • What infrastructure sits behind the advertised global DoH CDN endpoint besides the named unicast PoPs?

UncensoredDNS

  • Will the operator form a legal entity or sign a DPA for organisational use?
  • Is there a way to pin anycast to EU nodes only, or should EU-only buyers use unicast exclusively?
  • Is an independent no-logs or infrastructure audit planned?
  • Does the recursor validate DNSSEC for all clients? (not stated as a current guarantee on the pages reviewed)
  • What subprocessors, if any, sit on the blog, email, or monitoring path?