{
  "slug": "dns4eu",
  "category": "dns-resolvers",
  "name": "DNS4EU",
  "description": "Public DNS resolver co-funded by the European Union and operated by a consortium led by Whalebone in the Czech Republic. It offers protective, child-safe, ad-blocking and unfiltered variants over DoH and DoT.",
  "website": "https://joindns4.eu",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "CZ",
    "name": "Czechia",
    "eyes": null,
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 41,
  "coverage": 100,
  "summary": "DNS4EU scores 41 out of 100 (grade D) on the DNS resolvers criteria. It meets 4 of 11 criteria: no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets no query logs. It does not meet open source, no trackers or telemetry, independent audit, transparency report, tells users about requests and security headers. It is based in Czechia: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C-.",
  "url": "https://privacyratings.com/dns-resolvers/dns4eu/",
  "markdown": "https://privacyratings.com/dns-resolvers/dns4eu/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://joindns4.eu/privacy-policy",
      "note": "The website loads Google Tag Manager and HubSpot."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://legal-documents-dns4eu.s3.fr-par.scw.cloud/DNS4EU-Public-DNS-Resolver-policy-2025.pdf",
      "note": "Co-funded by the European Union. The resolver policy rules out selling or transferring IP addresses or user identifiers."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.joindns4.eu&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.joindns4.eu",
      "note": "Grade C- (45/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "encrypted_dns": {
      "title": "Encrypted DNS",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://joindns4.eu/for-public",
      "note": "DoH and DoT endpoints are listed for each resolver variant."
    },
    "no_query_logs": {
      "title": "No query logs",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://legal-documents-dns4eu.s3.fr-par.scw.cloud/DNS4EU-Public-DNS-Resolver-policy-2025.pdf",
      "note": "Client IP addresses are anonymised with a keyed hash on the resolver before logging. Not audited."
    },
    "dnssec_validation": {
      "title": "DNSSEC validation",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://protective.joindns4.eu/dns-query?dns=AAABAAABAAAAAAABDWRuc3NlYy1mYWlsZWQDb3JnAAABAAEAACkQAAAAgAAAAA",
      "note": "A test query for the deliberately broken dnssec-failed.org returns SERVFAIL, showing validation."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "C-",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google Analytics",
        "host": "inline code",
        "effect": "no"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      }
    ],
    "tested_at": "2026-10-01T06:38:28.441Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}