BlazingCDN vs DNS.SB

Vergelijk BlazingCDN en DNS.SB op mogelijkheden, rechtsgebied, waarborgen en geschiktheid voor Europese kopers.

Beide vermeld als alternatief voor: Cloudflare

Logo: BlazingCDN

BlazingCDN

Poland· Web Hosting and Cloud Computing

Needs review

Shortlist when you need a Polish-contracted, high-volume HTTP CDN for VOD, software downloads, or pre-encoded HLS and you can live with a delivery-first product. Skip when you need WebSockets, origin DDoS, or a WAF in the same console. Consider Cloudflare for the security platform, or OVHcloud if you want European compute and CDN under one group.

EU-operated (Poland)Video and HLS CDNAnycast pull cacheSigned URLs and tokensS3/Swift origin storagePrepaid / PAYG traffic
Logo: DNS.SB

DNS.SB

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, German-operated public resolver with DoT/DoH and optional city-pinned endpoints. Skip when you need malware blocking, a signed DPA or SLA on the free pool, or a guarantee that queries never leave the EU. Consider Quad9 for threat blocking or run your own recursive resolver when residency must be yours.

EU-operatedNo-logs (claimed)DoT + DoHUnfilteredAnycast + unicast pin
BlazingCDN vs DNS.SB: Overzicht
KenmerkLogo: BlazingCDNBlazingCDNLogo: DNS.SBDNS.SB
Land van herkomstPolandGermany
CategorieWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNeeNee
Self-hostedNeeNee
HoofdkantoorPolandGermany
Juridische entiteitAdvanced Administrations Sp. z o.o. (KRS 0000567375, NIP 5252624642), Warsaw. Partner company listed: BCDN LTD, Limassol, Cyprus.xTom GmbH, Kreuzstraße 60, 40210 Düsseldorf (Amtsgericht Düsseldorf HRB 86779)
VS-moeder / zeggenschapGeen bekende VS-moederGeen bekende VS-moeder
CLOUD Act-blootstelling (indicatief)MiddelMiddel
Hosting / residentieVendor-operated global CDN, claimed 25+ PoPs in Europe, North America, and Asia-Pacific. Video CDN and Cloud Storage advertise replicas in Europe, Asia, and America, including USA data centers. Optional dedicated GDPR Cache Servers for EU-oriented footprints. No public subprocessor list. Known US-group SaaS on the account path: Stripe and PayPal (billing), HubSpot (sales). Backup and log hosts unpublished.Primary: xTom global anycast (operator xTom GmbH, DE) with published unicast DoH cities. Named non-xTom PoP hosts: HostVenom (Chicago), DigitalOcean (Bengaluru), Amazon AWS (Seoul), Servers.com (Moscow), Vultr (Toronto), Misaka (Berlin). Website analytics: self-hosted Plausible. Backup/DR and support SaaS not published. DoH also advertised as a global CDN endpoint.
Samenvatting

Polish high-volume CDN for video, software installers, and HLS, with an anycast pull cache and in-network replication for large files.

Free public recursive DNS from Düsseldorf-based xTom GmbH, with DoT/DoH, claimed no logs, and optional city-pinned unicast endpoints.

Tags
In één oogopslag: BlazingCDN vs DNS.SB
In één oogopslagLogo: BlazingCDNBlazingCDNLogo: DNS.SBDNS.SB
HQWarsaw, PolandDüsseldorf, Germany
Legal entityAdvanced Administrations Sp. z o.o.xTom GmbH (HRB 86779)
Partner companyBCDN LTD, Limassol, CyprusNiet vermeld
Governing lawPolish law (Terms 2025)Niet vermeld
Product since2021 (vendor about page)Niet vermeld
Network (claimed)25+ PoPs, US / EU / APACNiet vermeld
Commercial modelPrepaid balance and PAYG traffic tiersFree for personal and non-commercial use; commercial use needs authorization
Self-host / OSSNeither. Managed CDN only.Niet vermeld
ProtocolsNiet vermeldDNS 53, DoT 853 (dot.sb), DoH 443 (HTTP/3); no native DoQ; no DNS64
AnycastNiet vermeldClaimed 30+ locations on six continents, including US cities
Open sourceNiet vermeldResolver stack not disclosed; docs site is on GitHub
Key capabilities: BlazingCDN vs DNS.SB
Key capabilitiesLogo: BlazingCDNBlazingCDNLogo: DNS.SBDNS.SB
EU-operated (Poland)JaJa
Video and HLS CDNJaNiet vermeld
Anycast pull cacheJaNiet vermeld
Signed URLs and tokensJaNiet vermeld
S3/Swift origin storageJaNiet vermeld
Prepaid / PAYG trafficJaNiet vermeld
No-logs (claimed)Niet vermeldJa
DoT + DoHNiet vermeldJa
UnfilteredNiet vermeldJa
Anycast + unicast pinNiet vermeldJa

BlazingCDN

  • Anycast pull cache for static assets

    Create a zone, point it at your origin, and cache on demand at the nearest advertised edge. The vendor claims a 96%+ average hit ratio and HTTP/2, HTTP/3, Brotli, IPv6, purge API, and origin shield. Product copy caps Anycast files at 70 MB and sends multi-GB installers to Video CDN.

  • Video CDN with in-network replication

    Large files are copied inside the CDN across Europe, Asia, and America according to the products page, so delivery need not hit the origin after import. Docs mention auto-import, range requests, cache warming, and a permanent cache option. One Video CDN FAQ also claims HLS/DASH transcoding, which conflicts with the Streaming CDN page.

  • HLS and LL-HLS delivery without packaging

    Streaming CDN is a delivery layer for pre-encoded HLS, LL-HLS, and DASH from your own media server. The company claims 2 to 4 second glass-to-glass latency on LL-HLS versus 20 to 40 seconds for standard HLS. You bring the encoder. Live event broadcasts still need prior provider approval.

  • Signed URLs, tokens, and geo filters

    HMAC-signed links with expiry, per-request tokens, referrer and user-agent filters, and country or IP allowlists and blocklists are listed as available on all account sizes. DRM-encrypted segments are delivered as-is. Licensing stays in your stack.

  • Object storage origin plus zone API

    Buckets can be created with S3 or Swift protocols and used as a CDN origin. Help docs cover FTP, SFTP, rclone, and OpenStack Swift uploads. Public API docs exist for zone management and purge from CI. Image optimization is marked coming soon.

DNS.SB

  • Memorable dual-stack public resolvers

    Classic DNS on UDP/TCP 53 at 185.222.222.222 and 45.11.45.11, plus IPv6 2a09:: and 2a11:: (full form published for older stacks). Dual-stack is first-class. There is no account and no client app. Benefit: routers and homelabs can be pointed at addresses people can actually remember. Limit: this is a shared public pool, not a dedicated recursive server.

  • DoT, DoH, and DoH over HTTP/3

    Encrypted DNS over TLS on hostname dot.sb port 853, and DoH at https://doh.dns.sb/dns-query (aliases doh.sb and dns.sb, plus raw IP URLs). The FAQ states DoH supports HTTP/3 (QUIC) and that native DNS-over-QUIC (RFC 9250) is not offered yet. Benefit: OS Private DNS, browsers, and Unbound can encrypt the stub-to-resolver hop. Limit: plaintext port 53 remains available and is still visible to the local network.

  • City-pinned unicast DoH endpoints

    Besides global anycast, the DoH page lists per-city URLs such as de-dus, de-fra, nl-ams, uk-lon, ee-tll, and several non-EU cities. Hosting providers are named per row (mostly xTom, plus HostVenom, DigitalOcean, Amazon AWS, Servers.com, Vultr, Misaka). Benefit: an admin can pin the resolver hop to a chosen metro. Limit: anycast IPs still land on the nearest global node, including US cities, unless you pin unicast.

  • Claimed no-logs resolver with DNSSEC and no ECS

    Privacy policy and FAQ say query names, client IPs, and timestamps are not stored, EDNS Client Subnet is off, query name minimisation (RFC 7816) is on, and the resolver validates DNSSEC. Benefit: less data handed to authoritative servers and, if the claim holds, nothing to disclose. Limit: the software stack is undisclosed and no independent no-logs audit was found.

  • Unfiltered recursion (legal caveats reserved)

    FAQ: no content filtering or blocking; users keep control. A separate FAQ bullet reserves blocking for legal requirements. Benefit: usable as a neutral upstream under a local filter like Pi-hole. Limit: no malware or ad blocklist on the resolver, and legal orders could still force a block.

Assurance & compliance: BlazingCDN vs DNS.SB
Assurance & complianceLogo: BlazingCDNBlazingCDNLogo: DNS.SBDNS.SB
Independent security / no-logs audit
Not found

Searched official site, legal page, features, and help centre. No third-party audit PDF or no-logs report.

Not found

Vendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed.

ISO 27001
Not found

No ISO 27001 claim or certificate found on primary pages.

Not found

No ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed.

SOC 2 / SOC 3
Not found

No SOC 2 or SOC 3 report found.

Not found

No SOC 2 or SOC 3 claim found on the official pages reviewed.

GDPR / EU data protection
Vendor claimed

Polish VAT-registered entity; dedicated GDPR page treats the vendor as processor. Dedicated EU cache servers sold separately. Default Video/storage products replicate outside the EU.

Vendor claimed

German controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent, but US and Asian content replicas plus Stripe, PayPal, and HubSpot on the account path. Not legal advice.

Partial

EU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download or in-product DPA found. Blog discusses DPAs as a buyer question. Ask sales.

Not found

No public DPA. Free service is personal/non-commercial; commercial terms are by contact only.

EU AI Act
Not applicable

CDN and object storage. Marketing mentions 'Smart AI Caching' and MSA authorises unnamed third-party AI vendors. Not an AI-centric product.

Not applicable

Public DNS resolver, not an AI system.

Considerations & known limitations: BlazingCDN vs DNS.SB
Considerations & known limitationsLogo: BlazingCDNBlazingCDNLogo: DNS.SBDNS.SB
DDoS cover is for cached objects
High

Help docs say protection is tailored to cached content. Uncached origin paths and dynamic sites can still be taken down. Pair with a dedicated mitigation product if origin availability is the requirement.

Niet vermeld
Default replicas include the US and Asia
Medium

Video CDN and Cloud Storage advertise three-continent copies, including USA data centers. EU-only delivery is a separate GDPR Cache Servers SKU, not the default.

Niet vermeld
US-group billing and CRM tools
Medium

Stripe and PayPal process top-ups. HubSpot is used for sales meetings. No published subprocessor list. Account metadata is not EU-only even if you pin caches.

Niet vermeld
No public audit, ISO, SOC, or DPA
Medium

Procurement teams that need a cert pack will stall. MSA text also conflicts with the GDPR page on whether personal data is processed.

Niet vermeld
No WebSockets, VPN, or unapproved live events
Medium

HTTP(S) delivery only. Live broadcasts need rights paperwork and prior approval. Anycast file size is capped at 70 MB on the product page.

Niet vermeld
Polish HQ plus Cyprus partner, shared MSA wording
Low

Contact lists two companies. Legal-information MSA hyperlinks advancedhosting.com. Confirm which entity invoices you and which terms apply.

Niet vermeld
No-logs policy is unauditedNiet vermeld
Medium

Privacy policy and FAQ say query logging is off. There is no independent audit, and the resolver software is not disclosed. Practical impact: you cannot show a third-party report to a security reviewer.

Global anycast and US-group PoP hostsNiet vermeld
Medium

Default anycast can land on US and other non-EU nodes. Published unicast DoH uses Amazon AWS, DigitalOcean, Vultr, HostVenom, Servers.com, and Misaka in addition to xTom. Practical impact: EU-only query residency is not the default and is not contractual.

Free pool is not a commercial DNS contractNiet vermeld
Medium

Terms restrict free use to personal and non-commercial cases. No SLA, no public DPA, services provided as-is. Practical impact: embedding DNS.SB in a product or relying on it for production without a license is out of policy.

No resolver-side threat blockingNiet vermeld
Low

Unfiltered by design, with a legal-requirements caveat. Practical impact: malware and phishing names resolve unless you filter locally or pick a protective resolver.

No DNS64 and no native DoQNiet vermeld
Low

FAQ: DNS64 is not offered; native DoQ is under evaluation; DoH over HTTP/3 is available. Practical impact: NAT64-only clients and DoQ-only stubs need another resolver.

Geschiktheid

BlazingCDN

Best fit when

  • OTT or VOD teams that want large files replicated inside the CDN so the origin can leave the delivery path
  • Software and game publishers shipping installers or patches over HTTP(S) with signed URLs
  • AdTech or MarTech delivery of tags, scripts, and VAST where latency and EU invoicing matter more than a WAF
  • Sports or live HLS operators who already have a packager and want LL-HLS delivery, not transcoding
  • Teams running a multi-CDN or backup-CDN trial against an existing provider

Poor fit when

  • Products that need WebSockets, VPN tunnels, or generic TCP/UDP forwarding at the edge
  • Sites that need origin DDoS, WAF, bot management, and authoritative DNS in one console
  • Workloads that must stay EU-only by default without buying a dedicated GDPR cache footprint
  • Live event broadcasts without rights paperwork and prior provider approval
  • Buyers who require a public ISO 27001 or SOC 2 pack and a published subprocessor list before RFP

Consider instead when

  • When: You need DNS, WAF, bot management, Workers, and origin DDoS in one platform

    Consider: Cloudflare

    Broader US-headquartered edge platform. BlazingCDN is delivery-first and only claims DDoS cover for cached objects.

  • When: You want European compute, object storage, and CDN under one group with a public DC catalogue

    Consider: OVHcloud

    French-group IaaS plus CDN. Less specialised for high-volume VOD replication than BlazingCDN marketing claims.

  • When: You mainly need German-group web hosting with CDN as an add-on

    Consider: IONOS

    Closer if the origin stack is IONOS hosting rather than a specialist video CDN.

DNS.SB

Best fit when

  • Homelabs and small networks that want a German-operated public resolver with addresses people can remember
  • Teams that already filter locally (Pi-hole, AdGuard Home, Unbound) and need a neutral encrypted upstream
  • Users who want DoT (dot.sb) or DoH without an account or client app
  • Operators who will pin a named EU/UK unicast DoH city instead of trusting global anycast
  • Personal and non-commercial use allowed by the published terms

Poor fit when

  • Regulated or commercial production DNS that needs a signed DPA, SLA, or prior commercial license
  • Anyone who needs resolver-side malware, ads, or family filtering
  • EU-only data residency requirements if you stay on anycast or non-EU unicast cities
  • IPv6-only NAT64 networks that need DNS64
  • Buyers who require an independent no-logs audit or a disclosed resolver software stack

Consider instead when

  • When: You want threat blocking at the resolver, not a neutral recursive cache

    Consider: Quad9 (Swiss foundation, not yet in this catalog) or a protective DNS4EU profile

    DNS.SB documents an unfiltered policy aside from legal requirements.

  • When: You need a signed DPA, SLA, or EU-only query path under contract

    Consider: Self-hosted Unbound or Knot Resolver, or a commercial recursive DNS with a written DPA

    Free DNS.SB is personal/non-commercial; city pins are operational, not a contract.

  • When: You need a full-tunnel VPN plus resolver under one European vendor

    Consider: Mullvad

    Different product class. Mullvad is a VPN, not a standalone public DNS.

Open questions for due diligence

BlazingCDN

  • Which legal entity issues the invoice and signs the DPA: Advanced Administrations Sp. z o.o. or BCDN LTD?
  • Is there a written DPA with Article 28 clauses, SCCs, and a current subprocessor list?
  • Can Video CDN or Cloud Storage be pinned to EU regions without the separate GDPR Cache Servers SKU?
  • Where are control-panel logs, raw logs, and Graylog exports stored, and for how long?
  • Does Video CDN transcode, or is packaging limited to Streaming CDN as that page states?
  • What is the contractual SLA (marketing copy uses both 99.999% and 99.998%) and what credits apply?

DNS.SB

  • Will xTom sign a DPA and publish a complete subprocessor list for commercial DNS.SB use?
  • Can they contractually pin recursion to named EU cities (not just publish unicast URLs)?
  • Will they commission an independent no-logs or resolver-security audit and name the software?
  • What process would force query logging or blocking beyond the current legal-requirements caveat?
  • What infrastructure sits behind the advertised global DoH CDN endpoint besides the named unicast PoPs?