KeyCDN vs UncensoredDNS

Confronta KeyCDN e UncensoredDNS su capacità, giurisdizione, garanzie e idoneità per acquirenti europei.

Entrambi elencati come alternative a: Cloudflare

Logo: KeyCDN

KeyCDN

Switzerland· Web Hosting and Cloud Computing

Needs review

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage
Logo: UncensoredDNS

UncensoredDNS

Denmark· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, encrypt-only public resolver run by a named Danish operator and you can configure DoT, DoH, or DoQ. Skip when you need a DPA, malware blocking, EU-only anycast, or a staffed SLA. Use unicast for Denmark-local queries. Consider Quad9 when you want resolver-side threat blocking, or Cloudflare / Google Public DNS when you need a mass-market anycast default.

Danish-operatedEncrypted DNS onlyNo filter listsNo-logs (claimed)Free public resolver
KeyCDN vs UncensoredDNS: Sintesi
CaratteristicaLogo: KeyCDNKeyCDNLogo: UncensoredDNSUncensoredDNS
Paese di origineSwitzerlandDenmark
CategoriaWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
SedeSwitzerlandDenmark
Soggetto giuridicoproinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, SwitzerlandNo company published. Operator: Thomas Steen Rasmussen (private individual).
Capogruppo / controllo USANessuna capogruppo USA notaNessuna capogruppo USA nota
Esposizione CLOUD Act (indicativa)MedioMedio
Hosting / residenzaCompany-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.Unicast at AS9167 (Høje Tåstrup, Denmark, sponsor tyktech). Anycast nodes: two at DeiC in Lyngby, Denmark (AS1835) and one at rgnet in Washington, USA (AS3927). No public backup, email, or analytics subprocessor list.
Riassunto

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

Danish volunteer public DNS resolver with encrypted-only DoT, DoH, and DoQ. Unfiltered lookups, unicast in the Copenhagen area, anycast that includes a US node.

Tag
A colpo d'occhio: KeyCDN vs UncensoredDNS
A colpo d'occhioLogo: KeyCDNKeyCDNLogo: UncensoredDNSUncensoredDNS
HQErmatingen, SwitzerlandNon indicato
Legal entityproinity LLC (d/b/a KeyCDN)No company imprint found
Governing lawSwitzerland; courts of SchwyzNon indicato
Network60+ PoPs in 40+ countries (vendor network page)Non indicato
Push storageEuropean data centers (vendor storage page)Non indicato
Commercial modelPrepaid credits, 14-day trial, no contractFree public service; optional GitHub Sponsors donations
Self-hostedNo (WordPress helper plugins are on GitHub)Non indicato
OperatorNon indicatoThomas Steen Rasmussen, private individual, Denmark
StartedNon indicatoNovember 2009 (censurfridns.dk registered 15 November 2009)
ProtocolsNon indicatoDoT :853, DoH /dns-query, DoQ UDP/853, DoH3 UDP/443; no port 53
AnycastNon indicato91.239.100.100 / 2001:67c:28a4:: (DeiC Lyngby + rgnet Washington)
UnicastNon indicato89.233.43.71 / 2a01:3a0:53:53:: at AS9167, Høje Tåstrup
Independent auditNon indicatoNone found
Key capabilities: KeyCDN vs UncensoredDNS
Key capabilitiesLogo: KeyCDNKeyCDNLogo: UncensoredDNSUncensoredDNS
Swiss-operatedNon indicato
Pay-as-you-go CDNNon indicato
Pull and Push ZonesNon indicato
Origin ShieldNon indicato
REST API purgeNon indicato
EU Push storageNon indicato
Danish-operatedNon indicato
Encrypted DNS onlyNon indicato
No filter listsNon indicato
No-logs (claimed)Non indicato
Free public resolverNon indicato

KeyCDN

  • Pull Zones with instant purge

    A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

  • Push Zones on European storage

    A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

  • Origin Shield (US East, US West, Amsterdam)

    An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

  • Query-string image processing

    On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

  • REST API, TLS choices, and protocol stack

    The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

  • Token, referrer, and account locks

    Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

UncensoredDNS

  • Encrypted-only recursive DNS

    Since October 2022 the resolvers do not answer classic UDP/TCP port 53. Clients use DNS-over-TLS on 853, DNS-over-HTTPS at /dns-query on 443, and (from 23 October 2025) DNS-over-QUIC on UDP/853 plus DNS-over-HTTP/3 on UDP/443. Devices that can only speak cleartext DNS will fail.

  • Unfiltered public resolution

    The service is built to skip ISP and court-style DNS blocklists that Danish providers apply. It does not offer malware, ad, or family filter modes. Choose it when you want NXDOMAIN to mean the name does not exist, not that a resolver policy hid it.

  • Anycast plus Danish unicast endpoints

    anycast.uncensoreddns.org uses 91.239.100.100 and 2001:67c:28a4::. unicast.uncensoreddns.org uses 89.233.43.71 and 2a01:3a0:53:53:: at AS9167 in Høje Tåstrup. The operator says the anycast prefix is provider-independent and unlikely to change. Legacy names under censurfridns.dk still work.

  • Published TLS pins per node

    Each listed node publishes RSA and ECDSA TLS public keys on the DNS Servers page. DoT originally shipped with TLSA records so clients such as Stubby can pin. Key rotation (ECDSA introduction in 2020) can break pinsets until operators update them.

  • Router and OS client notes

    The censurfridns/client-configs GitHub repo documents Firefox, Edge, iOS profiles, systemd-resolved, pfSense, OPNsense, OpenWrt, and Unbound. This is community documentation for a public resolver, not a supported enterprise client.

Assurance & compliance: KeyCDN vs UncensoredDNS
Assurance & complianceLogo: KeyCDNKeyCDNLogo: UncensoredDNSUncensoredDNS
Independent security / no-logs audit
Not found

No public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field.

Not found

FAQ claims no personal logs and aggregate graphs only. No third-party audit PDF found.

ISO 27001
Not found

Network page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC.

Not found
SOC 2 / SOC 3
Not found

Searched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found.

Not found
GDPR / EU data protection
Vendor claimed

Swiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties.

Partial

Danish individual operator and a no-logs claim on the FAQ. No formal privacy policy or DPA page found.

US CLOUD Act exposure (indicative)
Partial

Swiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice.

Partial

No known US parent. Published anycast includes rgnet in Washington, USA (AS3927), so some queries can be answered on US soil. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

GDPR page: open a support request to receive the DPA when Article 28 processing applies.

Not found

No company imprint or processor agreement found. Operator contact is admin@censurfridns.dk.

EU AI Act
Not applicable

CDN / image transforms, not an AI system product.

Not applicable

Public recursive DNS resolver, not an AI system.

Considerations & known limitations: KeyCDN vs UncensoredDNS
Considerations & known limitationsLogo: KeyCDNKeyCDNLogo: UncensoredDNSUncensoredDNS
US cache copies and US Origin Shield
Medium

Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

Non indicato
No current named subprocessor list
Medium

Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

Non indicato
No public operator ISO 27001 or SOC 2
Medium

ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

Non indicato
Privacy Policy last updated 2018
Medium

The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

Non indicato
Push Zone required above 100 MB
Low

Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Non indicato
Single-person operationNon indicato
High

The service is run by one named individual with donated nodes. There is no published company, on-call roster, or SLA. Sponsor withdrawals have already removed anycast sites.

US anycast node on the public mapNon indicato
Medium

rgnet-iad.anycast.uncensoreddns.org is listed in Washington, USA. Anycast clients cannot pin Denmark. Use the unicast hostname if EU landing matters.

No public independent auditNon indicato
Medium

No-logs is a first-party FAQ statement. No audit, ISO, or SOC package was found for a security review file.

No classic port 53Non indicato
Low

Cleartext DNS has been off since October 2022. Guest devices, some IoT, and default DHCP resolvers will not work without a local forwarder that speaks DoT or DoH.

Idoneità

KeyCDN

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

UncensoredDNS

Best fit when

  • Households and labs leaving filtered Danish ISP DNS who can speak DoT, DoH, or DoQ
  • Admins who want NXDOMAIN to mean the name does not exist, not a resolver policy
  • Router and homelab setups (pfSense, OPNsense, OpenWrt, systemd-resolved) using the published client notes
  • Buyers who prefer a named European individual over sending every lookup to Google or Cloudflare
  • Teams that can pin TLS keys and accept a volunteer-run service without an SLA

Poor fit when

  • Procurement that requires a company imprint, signed DPA, or ISO/SOC package
  • Policies that require EU-only query landing (anycast includes Washington, USA)
  • Need for malware, ad, or family filtering at the resolver
  • Devices or DHCP that can only use cleartext UDP/TCP port 53
  • A regulated resolver dependency that needs staffed on-call and a status SLA

Consider instead when

  • When: You want resolver-side malware blocking with a European-adjacent operator

    Consider: Quad9

    Quad9 is a filtered secure resolver. UncensoredDNS will not apply those blocks.

  • When: You need configurable profiles, analytics, or family filters

    Consider: NextDNS or AdGuard DNS

    Those are policy platforms. UncensoredDNS has no per-user console.

  • When: You need a mass-market anycast default and OS-level presets

    Consider: Cloudflare 1.1.1.1 or Google Public DNS

    Larger footprint and still offer cleartext 53. They are US-group services.

  • When: Every query must stay inside your EU tenancy

    Consider: Self-hosted Unbound or Knot Resolver on your own metal

    UncensoredDNS anycast can land on the published US node.

Open questions for due diligence

KeyCDN

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?

UncensoredDNS

  • Will the operator form a legal entity or sign a DPA for organisational use?
  • Is there a way to pin anycast to EU nodes only, or should EU-only buyers use unicast exclusively?
  • Is an independent no-logs or infrastructure audit planned?
  • Does the recursor validate DNSSEC for all clients? (not stated as a current guarantee on the pages reviewed)
  • What subprocessors, if any, sit on the blog, email, or monitoring path?