Logo: DNS.SB

DNS.SB

Free public recursive DNS from Düsseldorf-based xTom GmbH, with DoT/DoH, claimed no logs, and optional city-pinned unicast endpoints.

DNS.SB is a free public recursive DNS resolver operated by xTom GmbH in Düsseldorf, Germany. It exists so people and small networks can stop sending plaintext DNS to their ISP or to a US Big Tech resolver, without creating an account. The service answers classic DNS on port 53 plus encrypted DNS over TLS (hostname dot.sb, port 853) and DNS over HTTPS.

The product is deliberately unfiltered. The FAQ states that DNS.SB does not implement content filtering or blocking. The same FAQ also notes an exception for legal requirements. Memorable addresses are part of the design: IPv4 185.222.222.222 and 45.11.45.11, and IPv6 2a09:: and 2a11::.

The concrete differentiator is the mix of a German legal entity, a no-logs claim (no independent audit published), annual transparency reports, and a published unicast DoH list so an operator can pin queries to a named city instead of accepting global anycast.

EU-operatedNo-logs (claimed)DoT + DoHUnfilteredAnycast + unicast pin

Shortlist when you want an unfiltered, German-operated public resolver with DoT/DoH and optional city-pinned endpoints. Skip when you need malware blocking, a signed DPA or SLA on the free pool, or a guarantee that queries never leave the EU. Consider Quad9 for threat blocking or run your own recursive resolver when residency must be yours.

Key capabilities

Classic DNS on UDP/TCP 53 at 185.222.222.222 and 45.11.45.11, plus IPv6 2a09:: and 2a11:: (full form published for older stacks). Dual-stack is first-class. There is no account and no client app. Benefit: routers and homelabs can be pointed at addresses people can actually remember. Limit: this is a shared public pool, not a dedicated recursive server.

Encrypted DNS over TLS on hostname dot.sb port 853, and DoH at https://doh.dns.sb/dns-query (aliases doh.sb and dns.sb, plus raw IP URLs). The FAQ states DoH supports HTTP/3 (QUIC) and that native DNS-over-QUIC (RFC 9250) is not offered yet. Benefit: OS Private DNS, browsers, and Unbound can encrypt the stub-to-resolver hop. Limit: plaintext port 53 remains available and is still visible to the local network.

Besides global anycast, the DoH page lists per-city URLs such as de-dus, de-fra, nl-ams, uk-lon, ee-tll, and several non-EU cities. Hosting providers are named per row (mostly xTom, plus HostVenom, DigitalOcean, Amazon AWS, Servers.com, Vultr, Misaka). Benefit: an admin can pin the resolver hop to a chosen metro. Limit: anycast IPs still land on the nearest global node, including US cities, unless you pin unicast.

Privacy policy and FAQ say query names, client IPs, and timestamps are not stored, EDNS Client Subnet is off, query name minimisation (RFC 7816) is on, and the resolver validates DNSSEC. Benefit: less data handed to authoritative servers and, if the claim holds, nothing to disclose. Limit: the software stack is undisclosed and no independent no-logs audit was found.

FAQ: no content filtering or blocking; users keep control. A separate FAQ bullet reserves blocking for legal requirements. Benefit: usable as a neutral upstream under a local filter like Pi-hole. Limit: no malware or ad blocklist on the resolver, and legal orders could still force a block.

A colpo d'occhio

HQ
Düsseldorf, Germany
Legal entity
xTom GmbH (HRB 86779)
Commercial model
Free for personal and non-commercial use; commercial use needs authorization
Protocols
DNS 53, DoT 853 (dot.sb), DoH 443 (HTTP/3); no native DoQ; no DNS64
Anycast
Claimed 30+ locations on six continents, including US cities
Open source
Resolver stack not disclosed; docs site is on GitHub

Best fit when

  • Homelabs and small networks that want a German-operated public resolver with addresses people can remember
  • Teams that already filter locally (Pi-hole, AdGuard Home, Unbound) and need a neutral encrypted upstream
  • Users who want DoT (dot.sb) or DoH without an account or client app
  • Operators who will pin a named EU/UK unicast DoH city instead of trusting global anycast
  • Personal and non-commercial use allowed by the published terms

Poor fit when

  • Regulated or commercial production DNS that needs a signed DPA, SLA, or prior commercial license
  • Anyone who needs resolver-side malware, ads, or family filtering
  • EU-only data residency requirements if you stay on anycast or non-EU unicast cities
  • IPv6-only NAT64 networks that need DNS64
  • Buyers who require an independent no-logs audit or a disclosed resolver software stack

Consider instead when

  • When: You want threat blocking at the resolver, not a neutral recursive cache

    Consider: Quad9 (Swiss foundation, not yet in this catalog) or a protective DNS4EU profile

    DNS.SB documents an unfiltered policy aside from legal requirements.

  • When: You need a signed DPA, SLA, or EU-only query path under contract

    Consider: Self-hosted Unbound or Knot Resolver, or a commercial recursive DNS with a written DPA

    Free DNS.SB is personal/non-commercial; city pins are operational, not a contract.

  • When: You need a full-tunnel VPN plus resolver under one European vendor

    Consider: Mullvad

    Different product class. Mullvad is a VPN, not a standalone public DNS.

Giurisdizione e proprietà

Soggetto giuridico
xTom GmbH, Kreuzstraße 60, 40210 Düsseldorf (Amtsgericht Düsseldorf HRB 86779)
Capogruppo / controllo USA
Nessuna capogruppo USA nota
Esposizione CLOUD Act (indicativa)
Medium
Hosting / residenza
Primary: xTom global anycast (operator xTom GmbH, DE) with published unicast DoH cities. Named non-xTom PoP hosts: HostVenom (Chicago), DigitalOcean (Bengaluru), Amazon AWS (Seoul), Servers.com (Moscow), Vultr (Toronto), Misaka (Berlin). Website analytics: self-hosted Plausible. Backup/DR and support SaaS not published. DoH also advertised as a global CDN endpoint.

No known US parent. Terms governed by German law, Düsseldorf courts. US PoPs plus US-group cloud (AWS, DigitalOcean, Vultr) keep CLOUD Act exposure medium and indicative, not legal advice. Queries on anycast follow the nearest node, which may be outside the EU.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumNo-logs policy is unaudited

    Privacy policy and FAQ say query logging is off. There is no independent audit, and the resolver software is not disclosed. Practical impact: you cannot show a third-party report to a security reviewer.

  • MediumGlobal anycast and US-group PoP hosts

    Default anycast can land on US and other non-EU nodes. Published unicast DoH uses Amazon AWS, DigitalOcean, Vultr, HostVenom, Servers.com, and Misaka in addition to xTom. Practical impact: EU-only query residency is not the default and is not contractual.

  • MediumFree pool is not a commercial DNS contract

    Terms restrict free use to personal and non-commercial cases. No SLA, no public DPA, services provided as-is. Practical impact: embedding DNS.SB in a product or relying on it for production without a license is out of policy.

  • LowNo resolver-side threat blocking

    Unfiltered by design, with a legal-requirements caveat. Practical impact: malware and phishing names resolve unless you filter locally or pick a protective resolver.

  • LowNo DNS64 and no native DoQ

    FAQ: DNS64 is not offered; native DoQ is under evaluation; DoH over HTTP/3 is available. Practical impact: NAT64-only clients and DoQ-only stubs need another resolver.

Open questions for due diligence

  • Will xTom sign a DPA and publish a complete subprocessor list for commercial DNS.SB use?
  • Can they contractually pin recursion to named EU cities (not just publish unicast URLs)?
  • Will they commission an independent no-logs or resolver-security audit and name the software?
  • What process would force query logging or blocking beyond the current legal-requirements caveat?
  • What infrastructure sits behind the advertised global DoH CDN endpoint besides the named unicast PoPs?

Domande Frequenti

Not with the shared anycast addresses alone. The FAQ says queries go to the nearest node on a 30+ location, six-continent anycast network that includes multiple United States cities. To choose the resolver hop, use a unicast DoH URL from the official list (for example https://de-dus.doh.sb/dns-query or https://nl-ams.doh.sb/dns-query). Confirm the client actually stays on that host (no unexpected CNAME or anycast fallback). There is no published contract that queries never leave the EU.

Terms say the service is free for personal and non-commercial use. Commercial use, including using DNS.SB as an upstream inside a commercial product or as critical business infrastructure, requires prior authorization. The FAQ and terms point commercial and SLA needs to the contact page (admin at dns.sb). There is no public DPA or self-serve enterprise plan on the site.

No public independent no-logs or security audit was found. The company states logging is disabled and that it cannot share query data it does not have. It does publish annual transparency reports (2019 through 2025). The 2025 report tables zero German legal-process requests answered or in process across the listed categories. Treat no-logs as a vendor claim until an audit appears.

The FAQ on blocking says no: DNS.SB does not implement content filtering and presents itself as a neutral resolver. A different FAQ item says domains are not blocked or filtered except for legal requirements. There is no published malware or ads profile. If you need resolver-side threat blocking, look at Quad9 or a protective DNS4EU profile, or filter locally and keep DNS.SB as upstream.

The FAQ says DNS64 is not provided today. Native DoQ (RFC 9250) is not offered; DoH over HTTP/3 is, which uses QUIC under HTTPS on port 443. If you need DNS64 for NAT64 access, or DoQ specifically, this resolver does not cover those protocols.