DNS resolvers
Applied Privacy DNS privacy rating
Public DNS over HTTPS and DNS over TLS resolver run by the Foundation for Applied Privacy, a non-profit association in Vienna. It validates DNSSEC and uses QNAME minimisation.
Summary
Applied Privacy DNS scores 57 out of 100 (grade D) on the DNS resolvers criteria. It meets 5 of 11 criteria: no trackers or telemetry, no ads or data sales, TLS configuration, Encrypted DNS and DNSSEC validation. It partly meets security headers and no query logs. It does not meet open source, independent audit, transparency report and tells users about requests. It is based in Austria: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B.
Score 57 out of 100. How scoring works
Criteria
-
No
Open source Weight 3 of 3
Is all the source code needed to run the product public?
Closed source. The resolver configuration is not published.
-
Yes
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The website logs requests without IP addresses and uses no third-party analytics. Only the external donation providers are outside its control.
-
Yes
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Non-profit funded by donations and sponsors. No ads.
-
No
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
No independent audit is published.
-
No
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
No transparency report or government request policy is published.
-
No
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
No published policy on notifying users about data requests.
-
Yes
Encrypted DNS Weight 3 of 3
Are DNS over HTTPS and DNS over TLS supported?
DoH and DoT endpoints are both documented.
-
Partial
No query logs Weight 3 of 3
Are queries stored without IP addresses, and is this independently audited?
The policy states IP addresses and queries are not logged, only aggregated statistics. Not audited.
-
Yes
DNSSEC validation Weight 1 of 3
Does the resolver validate DNSSEC?
The documentation states the resolvers perform DNSSEC validation.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
Partial
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade B (70/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.