DNS resolver registry · Whalebone, s.r.o.

DNS4EU DNS servers

DNS4EU is run by Whalebone, s.r.o. and offers 5 service variants with different filtering, reachable over DNS (53), DoT, DoH. Every address and endpoint below is taken from the operator's documentation; the behaviour is what we measured on 2026-09-24.
86.54.11.1
primary address
20
addresses in 5 variants
Validates
DNSSEC in our test
None sent
client subnet (ECS)

Addresses

DNS4EU DNS addresses by variant

Set the IPv4 or IPv6 addresses as your DNS servers, or use an encrypted endpoint where one is listed.

Protective

Malware, phishing and command-and-control domains

IPv4
86.54.11.1
86.54.11.201
IPv6
2a13:1001::86:54:11:1
2a13:1001::86:54:11:201
DoH
https://protective.joindns4.eu/dns-query
DoT
protective.joindns4.eu

Protective with child protection

Protective, plus content not appropriate for children

IPv4
86.54.11.12
86.54.11.212
IPv6
2a13:1001::86:54:11:12
2a13:1001::86:54:11:212
DoH
https://child.joindns4.eu/dns-query
DoT
child.joindns4.eu

Protective with ad blocking

Protective, plus advertising and tracking domains

IPv4
86.54.11.13
86.54.11.213
IPv6
2a13:1001::86:54:11:13
2a13:1001::86:54:11:213
DoH
https://noads.joindns4.eu/dns-query
DoT
noads.joindns4.eu

Protective with child protection and ad blocking

Protective, plus child protection and ad blocking

IPv4
86.54.11.11
86.54.11.211
IPv6
2a13:1001::86:54:11:11
2a13:1001::86:54:11:211
DoH
https://child-noads.joindns4.eu/dns-query
DoT
child-noads.joindns4.eu

Unfiltered

None

IPv4
86.54.11.100
86.54.11.200
IPv6
2a13:1001::86:54:11:100
2a13:1001::86:54:11:200
DoH
https://unfiltered.joindns4.eu/dns-query
DoT
unfiltered.joindns4.eu

Measured

What we observed

Measured 2026-09-24 from one vantage point, three rounds per address, majority result. Anycast resolvers can behave differently from other networks. How we test

DNSSEC validation Validates

Returned SERVFAIL for dnssec-failed.org, rhybar.cz and badsig.go.dnscheck.tools on every address that answered, while resolving example.com.

Client subnet (ECS)

No client subnet reached the authoritative server from any address we probed.

Plain DNS and NXDOMAIN

10/10 documented IPv4 addresses answered on port 53. Random non-existent names came back as NXDOMAIN, so errors are not rewritten into ads or search pages.

Encrypted endpoints

  • DoH https://protective.joindns4.eu/dns-queryAnswered
  • DoH https://child.joindns4.eu/dns-queryAnswered
  • DoH https://noads.joindns4.eu/dns-queryAnswered
  • DoH https://child-noads.joindns4.eu/dns-queryAnswered
  • DoH https://unfiltered.joindns4.eu/dns-queryAnswered
  • DoT protective.joindns4.euAnswered
  • DoT child.joindns4.euAnswered
  • DoT noads.joindns4.euAnswered
  • DoT child-noads.joindns4.euAnswered
  • DoT unfiltered.joindns4.euAnswered

Networks

Which networks carry it

The announcing network comes from RIPEstat routing data for each documented address. The query network is where the resolver sent its own lookups during our probe, which a DNS leak test reports.

Announcing the service addresses

  • AS198121 DNS4EU Whalebone, s.r.o.

Queried from, in our probe

  • AS60068 CDN77 Datacamp Limited

In the operator's words

Operator statements

Quoted from the operator's pages and checked word for word. We have not audited these practices.
“Operated by Whalebone, s.r.o., Jezuitská 14/13, 602 00 Brno, Czech Republic”
www.joindns4.eu
“The client's IP address is fully anonymised before being logged directly onto the resolver.”
www.joindns4.eu

Check it

Confirm your device is using DNS4EU

Changing a DNS setting does not guarantee your lookups reach that resolver: a VPN, a browser's own secure DNS or a proxy can send them elsewhere. Our DNS leak test shows which resolvers actually received your queries.

From a terminal

# Which address did the resolver query from?
dig +short whoami.akamai.net @86.54.11.1

# Does it pass your subnet on (ECS)?
dig +short TXT o-o.myaddr.l.google.com @86.54.11.1

# Does it validate DNSSEC? SERVFAIL means yes
dig dnssec-failed.org @86.54.11.1

Behind a proxy

With an HTTP proxy, or a client set to socks5h://, the proxy side resolves hostnames, so your own resolver setting does not apply to that traffic. With socks5:// in curl or Python requests, your device resolves names first. The SOCKS5 vs SOCKS5h guide shows how to check which one you have.

Questions

DNS4EU questions

What are DNS4EU's DNS server addresses?

Protective: 86.54.11.1, 86.54.11.201, 2a13:1001::86:54:11:1, 2a13:1001::86:54:11:201. Protective with child protection: 86.54.11.12, 86.54.11.212, 2a13:1001::86:54:11:12, 2a13:1001::86:54:11:212. Protective with ad blocking: 86.54.11.13, 86.54.11.213, 2a13:1001::86:54:11:13, 2a13:1001::86:54:11:213. Protective with child protection and ad blocking: 86.54.11.11, 86.54.11.211, 2a13:1001::86:54:11:11, 2a13:1001::86:54:11:211. Unfiltered: 86.54.11.100, 86.54.11.200, 2a13:1001::86:54:11:100, 2a13:1001::86:54:11:200.

Does DNS4EU validate DNSSEC?

Yes. On 2026-09-24 every DNS4EU address that answered returned SERVFAIL for three deliberately mis-signed domains while resolving ordinary names.

Does DNS4EU support DNS over HTTPS or DNS over TLS?

DoH: https://protective.joindns4.eu/dns-query, https://child.joindns4.eu/dns-query, https://noads.joindns4.eu/dns-query, https://child-noads.joindns4.eu/dns-query, https://unfiltered.joindns4.eu/dns-query. DoT: protective.joindns4.eu, child.joindns4.eu, noads.joindns4.eu, child-noads.joindns4.eu, unfiltered.joindns4.eu. 10 of 10 answered our test query on 2026-09-24.

Does DNS4EU send my IP subnet to other servers (ECS)?

We observed no client subnet on any address we probed.

How can I check that I am using DNS4EU?

Run a DNS leak test and compare the network it reports with the one DNS4EU queried from in our probe (AS60068). On the command line, dig +short whoami.akamai.net @86.54.11.1 returns the address the resolver used to query Akamai.

Sources

Sources and dates

Documentation checked 2026-09-24. Measured 2026-09-24. Registry reviewed 2026-09-24.