Back to blog
privacy Published: AEU DNS Newsroom

DNS4EU vs NextDNS vs AEU DNS: which is truly no-logs?

Compare DNS4EU vs NextDNS vs AEU DNS: what no-logs really means, EU jurisdiction, and encrypted DNS options. Find the right resolver.

When dns0.eu shut down in October 2025, many privacy-conscious users in Europe lost their go-to no-logs resolver. If you are now weighing alternatives, you have likely come across DNS4EU, NextDNS, and AEU DNS. All three offer encrypted DNS, but they differ sharply in logging and jurisdiction. This article breaks down what "no-logs" actually means, why jurisdiction matters, and how each service stacks up.

First, a quick primer on DNS and privacy. The Domain Name System (DNS) is the internet's phonebook, translating names like example.com into IP addresses. By default, DNS queries travel in plain text on port 53, visible to anyone on the network path, including your internet service provider (ISP). Encrypted DNS, such as DNS over HTTPS (DoH), DNS over TLS (DoT), or DNS over QUIC (DoQ), protects that traffic from prying eyes. But encryption alone does not guarantee privacy; the resolver you use still sees your queries and may log them.

What does "no-logs" really mean?

A strict no-logs DNS service does not store any personally identifiable information about your queries. It may keep transient operational data, like aggregate traffic volume, but it cannot tie a query to a specific user or IP address. In contrast, a service that keeps "anonymized" or "aggregated" logs strips identifiers but still stores some data, which could potentially be re-identified or handed over under legal pressure. For the privacy purist, no-logs is the gold standard.

DNS4EU: EU-backed but not no-logs

DNS4EU is a public resolver funded by the European Union. It is based in the EU and designed with privacy in mind, which is a positive step for European digital sovereignty. However, it is not a strict no-logs service. According to its public documentation, DNS4EU keeps anonymized and aggregated logs for operational and security purposes. That means it does not log your individual queries, but it does retain some data that could, in theory, be used to infer patterns. This is a fair trade-off for a service that must balance privacy with abuse prevention and network monitoring. If you require absolute zero retention, DNS4EU may not meet that bar.

NextDNS: capable but US jurisdiction

NextDNS is a widely used and technically capable resolver, offering granular filtering, analytics, and customizable blocklists. It supports DoH, DoT, and DoQ, and it has a strong privacy policy. However, NextDNS is a US-based company, so it falls under US jurisdiction. That means your DNS queries, even if encrypted, are subject to US laws, including subpoenas and national security requests. For European users, this is a neutral jurisdictional fact, not an accusation. If you are concerned about data staying within the EU, NextDNS may not be your first choice.

AEU DNS: European, strict no-logs, and encrypted

AEU DNS is a European, privacy-first DNS service that positions itself as a direct answer to the dns0.eu gap. It is strictly no-logs, meaning it retains no query data whatsoever, and it operates under EU jurisdiction, which benefits from the General Data Protection Regulation (GDPR) and other strong privacy laws. AEU DNS supports all three major encrypted DNS protocols: DoH, DoT, and DoQ. DoH runs on port 443 and blends with regular web traffic, making it the hardest to block. DoT uses a dedicated port 853 and is simple but easy for networks to spot. DoQ is newer, runs over UDP/443-style, and offers low latency. AEU DNS also offers features like DNS-level SafeSearch enforcement, which can filter explicit content across your entire network.

Why jurisdiction matters

Jurisdiction determines which government can compel a company to hand over data. If a resolver is based in the US, it is subject to US court orders and surveillance programs. If it is based in the EU, it must comply with GDPR and EU data protection rules, which are among the strictest in the world. For European users, choosing an EU-based resolver reduces the risk of data being accessed by non-EU authorities. This is not about accusing US companies of wrongdoing; it is about understanding legal exposure.

Making your choice

So, which is truly no-logs? DNS4EU is not, NextDNS is not (it has a logging option, but its default may log some data), and AEU DNS is. If you need a strict no-logs service under EU jurisdiction, AEU DNS is the clear winner. If you prioritize EU backing and are comfortable with anonymized logs, DNS4EU is a solid choice. If you need advanced filtering and are okay with US jurisdiction, NextDNS remains a capable option.

Ultimately, the right choice depends on your threat model and privacy requirements. For families and businesses that want to keep DNS data within Europe and never stored, AEU DNS offers a compelling package. For those who value EU institutional support, DNS4EU is a respectable alternative. And for power users who want granular control, NextDNS is still worth considering, as long as you understand its jurisdictional limits.

In the end, "no-logs" is not a marketing buzzword; it is a commitment. Read the privacy policies carefully, understand the jurisdiction, and choose a resolver that aligns with your values. Your DNS queries reveal a lot about you, so make sure you trust the entity that sees them.

Terms explained

DNS
The Domain Name System, which translates human-readable domain names into IP addresses.
No-logs
A policy where a service does not store any data that could link a user to their queries.
DoH
DNS over HTTPS, which encrypts DNS queries within HTTPS traffic on port 443.
DoT
DNS over TLS, which encrypts DNS queries on a dedicated port 853.
DoQ
DNS over QUIC, a newer protocol that encrypts DNS over UDP/443-style connections for low latency.
DNS leak
When a device sends DNS queries outside the configured encrypted resolver, exposing them to the ISP.

How to protect yourself

  1. Check the privacy policy for the exact logging language: look for 'no logs' vs 'anonymized logs'.
  2. Consider jurisdiction: if you are in the EU, an EU-based resolver offers stronger legal protections.
  3. Use encrypted DNS protocols like DoH or DoQ to prevent on-path snooping, but remember the resolver still sees your queries.
  4. Test for DNS leaks using online tools to ensure your device is not sending queries to your ISP.
  5. If you need content filtering, look for DNS-level SafeSearch or parental controls.
  6. For strict privacy, choose a resolver that has been independently audited for no-logs compliance.

References

Get private, encrypted DNS