Privacy
Policy

DNSBunker is a non-commercial, privacy-first DNS resolver operated from Germany. This policy provides a complete and technically precise account of all data processing activities in accordance with the EU General Data Protection Regulation (GDPR / DSGVO), the German Telecommunications Digital Services Data Protection Act (TDDDG), the German Digital Services Act implementation (DDG), and, where applicable, the Telecommunications Act (TKG 2021). No legal boilerplate has been added for appearance. Every statement in this policy reflects actual technical practice.

A plain-language summary for orientation. Only the full policy below is binding.

What's stored about you?

Nothing. Your lookups and your IP address are only held in memory for the milliseconds it takes to answer, and never written to disk. There are no accounts, no cookies and no analytics.

The one exception: this website

When you open this website, the web server may log your IP address and browser for up to 7 days to fend off attacks. Your language choice is saved only in your own browser.

Who else is involved?

The server is rented from IP-Projects in Frankfurt, who have no access to your lookups. To find answers, DNSBunker asks nameservers around the world, but they only see DNSBunker's IP address, never yours, and as little of the name as possible.

Your rights

You can ask for information, correction or deletion at any time, or complain to a data protection authority. Since DNS lookups aren't stored, there's usually nothing to hand over or delete.

Identity and contact

DNSBunker Project, Patrick Scholing
[enable JavaScript to view], Germany
contact [at] dnsbunker.org

The controller is a natural person operating DNSBunker as a non-commercial private project. No data protection officer is legally required under Art. 37 GDPR for operations of this nature and scale. Direct contact for all data protection matters is the address above.

How the resolver works

DNSBunker operates a recursive DNS resolver stack composed of dnsdist (query dispatcher) and PowerDNS Recursor (recursive backend). When a client sends a DNS query, the following occurs: the query is received over an encrypted transport, decrypted in memory, evaluated against filtering rules, resolved by querying authoritative nameservers on the public internet (or served from cache), and a response is returned to the client. No component in this pipeline writes query data to disk or persistent storage at any stage. The entire resolution lifecycle exists solely in volatile memory (RAM). When the process terminates or the server restarts, all in-memory state is permanently and irrecoverably lost.

Encrypted transport only

DNSBunker accepts queries exclusively over encrypted protocols: DNS-over-TLS (DoT, RFC 7858, port 853), DNS-over-HTTPS (DoH, RFC 8484), and DNS-over-QUIC (DoQ, RFC 9250, port 853). Unencrypted queries on port 53 are not accepted and are dropped without a response. This architectural decision ensures that query content, including domain names queried and client IP addresses, is not exposed to passive network observation, man-in-the-middle interception, or ISP-level surveillance during transit between client and resolver.

DNS cache

Resolved DNS records are cached in the working memory of the resolver processes (dnsdist packet cache and PowerDNS Recursor record cache) to serve subsequent identical queries without re-querying authoritative servers. The cache stores only the DNS data itself (domain, record type, response, TTL) - not which client requested it, not at what time, and not from which IP address. Cache entries cannot be linked to any individual user. The cache is shared across all clients, is never written to disk, and is lost entirely on process restart or system reboot.

TLS session tickets

TLS session tickets are used to allow faster reconnection (session resumption) without a full TLS handshake. Session ticket keys are generated in memory at process start and are never written to disk. They are not shared across server instances and are rotated on process restart. Session tickets do not identify the user and contain no query content. They serve exclusively to reduce connection establishment latency for returning clients.

EDNS Client Subnet (ECS)

EDNS Client Subnet is a DNS extension that allows resolvers to forward a portion of the client's IP address to authoritative nameservers to enable geographically optimised responses. DNSBunker has ECS explicitly disabled at both the caching and backend resolver layers. No client IP information, full or partial, is ever forwarded to authoritative nameservers. Authoritative servers only ever see the resolver's own IP address (185.250.250.61 or 2a0a:51c1:000a:00ea::).

QNAME minimisation

PowerDNS Recursor implements QNAME minimisation (RFC 9156) by default. Instead of sending the full queried domain name to every authoritative server in the resolution chain, only the minimum necessary portion of the name is sent to each server. For example, when resolving example.com, the root servers are asked only about .com, the .com servers are asked only about example.com, and so on. This prevents authoritative servers higher in the chain from learning the full query.

Upstream resolution and third-country transfers

When a requested domain is not in cache, PowerDNS Recursor contacts authoritative nameservers on the public internet to resolve it. These servers are operated globally, including outside the European Union. The data transmitted in such a query consists solely of the resolver's own IP address and the queried domain name (minimised per QNAME minimisation above). No client IP, no user identifier, and no query history is transmitted. This upstream contact is technically inherent to recursive DNS resolution and cannot be avoided while maintaining full resolution capability. It does not constitute a transfer of personal data relating to users of DNSBunker, as no user-identifying data is included.

DNS query processing

Data processed: client IP address, source port, queried domain name, query type (e.g. A, AAAA, MX), timestamp of query (in-memory only).
Purpose: To return a DNS resolution response.
Legal basis: Art. 6(1)(b) GDPR - processing necessary for the performance of a service requested by the user.
Retention: Not retained. All data exists only transiently in RAM during query processing, typically for milliseconds. No data is written to disk or any persistent medium.
Public statistics: For the display on the home page, the resolver counts only two totals: the number of all queries and the number of blocked queries. Per-minute sums of these counters are kept in RAM for at most 24 hours; they contain neither IP addresses nor domain names and cannot be linked to individual users.
Recipients: None. Data is not shared with any third party.

Web server access

Data processed: IP address, timestamp, HTTP method, requested URL, HTTP status code, referrer, user agent string.
Purpose: Technical operation, security diagnostics, and detection of service abuse.
Legal basis: Art. 6(1)(f) GDPR: legitimate interest of the operator in maintaining service availability and security.
Retention: Short-term. Web server access logs, if generated, are retained for a maximum of 7 days and then automatically deleted. They are not analysed for user behaviour and not shared with third parties.
Recipients: None beyond the hosting provider (see Hosting section).

Security incident response

Data processed: source IP address, query type, queried domain, query rate, viewed in real time via in-memory diagnostics only.
Purpose: Detection and mitigation of denial-of-service attacks, flooding, and other forms of service abuse.
Legal basis: Art. 6(1)(f) GDPR: legitimate interest in maintaining service integrity for all users.
Retention: Not retained. Diagnostic data exists only in volatile memory and is never written to persistent storage. Automated blocking rules (IP-level rate limits and dynamic blocks) are held in memory and are cleared on process restart.
Recipients: None.

Content filtering

Data processed: queried domain name (compared against blocklists in memory).
Purpose: Blocking of domains associated with malware, phishing, tracking, advertising, and other categories defined by the Hagezi blocklist project.
Legal basis: Art. 6(1)(f) GDPR: legitimate interest in providing a safer and less privacy-invasive resolution service.
Retention: Not retained. Filtering decisions are made in memory during query processing and are not logged.
Blocklist source: Hagezi (github.com/hagezi/dns-blocklists). Lists are publicly available. No data about users or their queries is transmitted to Hagezi or any third party during list updates.
Effect: Domains on active blocklists receive a NXDOMAIN response. This filtering cannot be disabled per client.

Cookies, tracking and analytics

Neither this website nor the DNS resolver service uses cookies, session storage, browser fingerprinting, tracking pixels, web beacons, or any third-party analytics or advertising technology. The website contains a small client-side language toggle: the selected language is stored only in the browser's local storage on the visitor's own device, purely to remember the preference on return visits, and is never transmitted to DNSBunker or any third party. No data is transmitted to advertising networks, data brokers, or social media platforms. No consent banner is presented because none is needed.

Automated decision-making and profiling

DNSBunker does not engage in automated decision-making or profiling within the meaning of Art. 22 GDPR. Automated IP-level rate limiting and blocking are applied purely for service protection purposes, based on anonymous aggregate traffic metrics, and do not constitute profiling of individuals.

Hosting provider

The DNS infrastructure is hosted on a server operated by IP-Projects GmbH & Co. KG, Am Vogelherd 14, 97295 Waldbrunn, Germany. The server is located in a IP-Projects data centre in Frankfurt, Germany. IP-Projects acts as a data processor within the meaning of Art. 4(8) GDPR and Art. 28 GDPR. A data processing agreement (DPA) pursuant to Art. 28(3) GDPR is in place with IP-Projects. IP-Projects's own privacy policy governs their processing activities and is available at ip-projects.de. IP-Projects has no access to DNS query content processed by DNSBunker.

Server location and data transfers

All DNSBunker infrastructure is located within the European Union (Germany). No personal data is transferred to countries outside the EU/EEA, subject to the following clarification: recursive DNS resolution requires contacting authoritative nameservers worldwide. As described in the Technical Architecture section, these contacts involve only the resolver's own IP address and a minimised domain name fragment, no user personal data. This does not constitute a transfer of personal data to third countries within the meaning of Chapter V GDPR.

Art. 6(1)(b) GDPR
Contract performance: in-memory processing of DNS queries to deliver the resolution service requested by the user.
Art. 6(1)(f) GDPR
Legitimate interest: temporary in-memory processing for security incident detection, content filtering, and web server access logging. The privacy impact is minimal given the absence of persistent storage.
Rights under the GDPR

You have the following rights under the GDPR, subject to applicable conditions and exceptions:

Right of access (Art. 15): You may request information about what personal data is processed about you. Given that no data is retained, a truthful response to any such request is: no personal data relating to you is held.

Right to rectification (Art. 16): You may request correction of inaccurate data. Not applicable for the same reason.

Right to erasure (Art. 17): You may request deletion of personal data. Architecturally satisfied: no data is stored, therefore there is nothing to delete.

Right to restriction of processing (Art. 18): You may request that processing be restricted in certain circumstances.

Right to data portability (Art. 20): You may request your data in a portable format. Not applicable as no data is held.

Right to object (Art. 21): You may object to processing based on legitimate interest (Art. 6(1)(f)). A practical way to exercise this right is to discontinue use of the service.

To exercise any of these rights, contact: contact [at] dnsbunker.org. Requests will be responded to within one month in accordance with Art. 12(3) GDPR.

Right to lodge a complaint

You have the right to lodge a complaint with a competent supervisory authority under Art. 77 GDPR. The supervisory authority with jurisdiction over the controller is:

Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17, 01067 Dresden, Germany
www.datenschutz.sachsen.de

You may also contact the supervisory authority in the EU member state of your habitual residence or place of work.

Changes to this policy

This policy may be updated to reflect changes in technical operation, applicable law, or hosting arrangements. Material changes will be indicated by an updated date at the bottom of this page. Continued use of the service following an update constitutes acknowledgement of the revised policy. The current version is always the one published at this URL.