DNS resolver registry · SafeDNS
SafeDNS DNS servers
Addresses
SafeDNS DNS addresses by variant
SafeDNS
Not specified by the operator
- IPv4
- 195.46.39.39195.46.39.40
- IPv6
- 2001:67c:2778::39392001:67c:2778::3940
| Variant | Filtering (operator description) | IPv4 | IPv6 | Encrypted |
|---|---|---|---|---|
| SafeDNS | Not specified by the operator | 195.46.39.39 195.46.39.40 | 2001:67c:2778::3939 2001:67c:2778::3940 | Not documented |
Measured
What we observed
Measured 2026-09-24 from one vantage point, three rounds per address, majority result. Anycast resolvers can behave differently from other networks. How we test
DNSSEC validation Does not validate
Returned addresses for dnssec-failed.org, rhybar.cz and badsig.go.dnscheck.tools, which a validating resolver would refuse.
Client subnet (ECS)
No client subnet reached the authoritative server from any address we probed.
Plain DNS and NXDOMAIN
2/2 documented IPv4 addresses answered on port 53. Random non-existent names came back as NXDOMAIN, so errors are not rewritten into ads or search pages.
Encrypted endpoints
None documented on the page we checked.
Networks
Which networks carry it
Announcing the service addresses
- AS57926 SAFEDNS-AS SafeDNS, Inc.
Queried from, in our probe
- AS36236 NETACTUATE - NetActuate, Inc
Check it
Confirm your device is using SafeDNS
From a terminal
# Which address did the resolver query from?
dig +short whoami.akamai.net @195.46.39.39
# Does it pass your subnet on (ECS)?
dig +short TXT o-o.myaddr.l.google.com @195.46.39.39
# Does it validate DNSSEC? SERVFAIL means yes
dig dnssec-failed.org @195.46.39.39Behind a proxy
With an HTTP proxy, or a client set to socks5h://, the proxy side resolves hostnames, so your own resolver setting does not apply to that traffic. With socks5:// in curl or Python requests, your device resolves names first. The SOCKS5 vs SOCKS5h guide shows how to check which one you have.
Questions
SafeDNS questions
What are SafeDNS's DNS server addresses?
SafeDNS: 195.46.39.39, 195.46.39.40, 2001:67c:2778::3939, 2001:67c:2778::3940.
Does SafeDNS validate DNSSEC?
Not in our 2026-09-24 test: it returned addresses for all three deliberately mis-signed domains.
Does SafeDNS support DNS over HTTPS or DNS over TLS?
The SafeDNS page we checked documents plain DNS addresses only.
Does SafeDNS send my IP subnet to other servers (ECS)?
We observed no client subnet on any address we probed.
How can I check that I am using SafeDNS?
Run a DNS leak test and compare the network it reports with the one SafeDNS queried from in our probe (AS36236). On the command line, dig +short whoami.akamai.net @195.46.39.39 returns the address the resolver used to query Akamai.
Sources
Sources and dates
Compare
Other resolvers where DNSSEC does not validate
Comodo Secure DNS
8.26.56.26 · 8.20.247.20
Yandex DNS
77.88.8.8 · 77.88.8.1
AliDNS (Alibaba Cloud Public DNS)
223.5.5.5 · 223.6.6.6
DNSPod Public DNS
119.29.29.29
114DNS
114.114.114.114 · 114.114.115.115
CIRA Canadian Shield
149.112.121.10 · 149.112.122.10
Research library
Network registries & open data
Find the reference behind a network decision. Browse the records, follow their sources and download the available datasets.