← Back to guides

European alternatives to Route 53, Cloudflare DNS and Google Cloud DNS

Max Heyer · Updated

If you want authoritative DNS run by a European company, this guide compares deSEC (Berlin, non-profit), Hetzner DNS (Germany), IONOS (Germany), OVHcloud (France), bunny.net (Slovenia), Gcore (Luxembourg) and enum DNS (Germany). Several of them are free, most have an API, and they differ on the things that matter in production: DNSSEC, anycast coverage, Terraform support and whether anyone commits to uptime. No single one matches Route 53 or Cloudflare on every row, so pick by the criteria below rather than by brand.

This guide covers authoritative DNS, the nameservers that answer for your domain. Public resolvers like 1.1.1.1 or 8.8.8.8 are a different product with a different set of European alternatives.

Why move authoritative DNS to a European provider?

Your zone records are public by design, so the question is not secrecy. It is control. Whoever runs your nameservers can take your domain offline, sees which resolvers query it and when, and holds the account that can change every record. Amazon, Google and Cloudflare are US companies, and the US CLOUD Act covers data a provider under US jurisdiction holds, wherever it is stored.

DNS is also the cheapest part of a stack to move. A zone is mostly a list of records, and moving it touches no application code. What does need repointing is DNS automation: Terraform, ExternalDNS and cert-manager DNS-01 solvers.

This guide is general information, not legal advice. Have your counsel assess your specific situation.

What should a professional DNS provider support?

Six criteria separate a hobby setup from one you can run production on:

  • Price model. Per zone, per query, or free. Per-query pricing is cheap until a traffic spike or a DNS flood lands on your bill.
  • API and Terraform. If DNS lives outside your infrastructure code, records drift. Check for an official or maintained Terraform provider, plus ACME DNS-01 support for wildcard certificates. On Kubernetes, also check whether ExternalDNS and cert-manager can talk to the provider.
  • DNSSEC. Signing lets validating resolvers detect forged answers. For anything handling logins or payments, treat it as required, not optional.
  • Anycast. With anycast, the same nameserver IP is announced from many locations and queries go to the nearest one. That lowers latency for distant users and spreads load during attacks. Unicast nameservers work, but every query travels to a fixed place.
  • SLA. Free DNS usually comes without an availability commitment. If an outage costs you money, check whether the provider publishes an SLA and what it covers.
  • Jurisdiction and operator. Who owns the company, where it is registered, and whether parts of the network run on non-EU partners.

How do the European DNS providers compare?

Facts as stated on each provider’s own pages on 2026-10-09. “Not stated” means we could not find it on the provider’s page, not that the feature is missing.

ProviderOperator, seatPriceAPI / TerraformDNSSECAnycast
deSECdeSEC e.V. (non-profit), Berlin, DEFree; new accounts start with 1 domain, and the limit grows as domains are delegated with DNSSECREST API, certbot plugin / community providers (Valodim/desec, timofurrer/desec)Yes, required by the termsYes, 15 frontend locations, 3 in the US; nameserver addresses are NetActuate (US) IP space
Hetzner DNSHetzner Online GmbH, DEFree, 25 zones by defaultHetzner Cloud API / official hcloud provider (v1.54.0+)Not currently supportedNot stated
IONOS free DNSIONOS SE, DE€0 per year for 12 years under a current offer (list price €5 per year)DNS API for IONOS customers / not statedOnly with paid DNS ProYes, 14 PoPs
IONOS Cloud DNSIONOS Cloud GmbH, DE€1.50 per zone per 30 days, no query feesREST API / official Terraform providerYes (enabled through the API)Yes, 14 PoPs
OVHcloudOVH SAS, FRZone free, also for domains registered elsewhere; Anycast is a paid option billed per domain per yearOVHcloud API / official ovh providerYes, no extra chargePaid option, 4 PoPs
bunny.net DNSBunnyWay d.o.o., Ljubljana, SIUp to 500 zones, standard and smart queries free; $1 monthly account minimum if DNS is your only bunny.net productREST API / official bunnynet providerYes36+ DNS PoPs
Gcore DNSG-Core Labs S.A., LUFree tier with unlimited zones and queries; Pro €2.49 per monthAPI / G-Core/gcore provider (Terraform partner tier)Yes, labelled betaYes, 210+ PoPs
enum DNSenum GmbH, Cologne, DEFree, no per-zone or per-query feeenum API and enumctl / no provider yet (planned for Q4 2026)YesNo, unicast today (anycast on the roadmap)

Checked October 2026.

Of the European options, IONOS Cloud DNS commits to 99.995% nameserver availability and bunny.net publishes a 99.99% platform SLA. deSEC states that its free service is best effort. We found no DNS SLA for Hetzner, OVHcloud’s free zone or Gcore, and enum publishes none for DNS. Links are under Sources.

For reference, the US providers most teams compare against:

ProviderPriceAPI / TerraformDNSSECAnycast
Amazon Route 53Per hosted zone per month, lower rate above 25 zones; plus per million queriesAWS API / official hashicorp/aws providerYesYes
Google Cloud DNSPer managed zone per month; plus per million queries; no free tierCloud DNS API / official hashicorp/google providerYesYes
Cloudflare DNSIncluded on every plan, including Free; no query charges below EnterpriseCloudflare API / official cloudflare providerYesYes

Checked October 2026.

The honest summary: Cloudflare’s free plan bundles DNS with its CDN and proxy, which a DNS-only provider does not replace. Among the providers in this table, Gcore has the widest anycast footprint (210+ PoPs), followed by bunny.net (36+), deSEC (15) and IONOS (14). deSEC, enum DNS and OVHcloud’s free zone (without the paid anycast option) include DNSSEC at no cost. Gcore’s free tier includes DNSSEC as a beta feature, and bunny.net includes it within its $1 monthly account minimum.

deSEC

deSEC is a registered non-profit association in Berlin, built on open-source software, and free to use. DNSSEC is part of the design rather than an add-on. The REST API is well documented and has a certbot plugin for Let’s Encrypt DNS-01.

Four things to know. The Terraform providers (Valodim/desec and timofurrer/desec) are community-maintained, not run by deSEC. New accounts start with a limit of one domain, which grows as your domains are delegated with DNSSEC, so a bulk migration needs planning. The terms require deSEC’s nameservers and a working DNSSEC chain of trust at the registrar: a domain without them can get a deletion warning and be deleted four weeks later. And there is no SLA; deSEC says its free services run on a best-effort basis.

On jurisdiction, deSEC’s anycast network runs on NetActuate, a US company. Both nameserver addresses (ns1.desec.io and ns2.desec.org) are NetActuate IP space, and 3 of the 15 frontend locations on deSEC’s map are in the US. According to a deSEC staff reply on its forum, the frontends hold only the published DNS data, not the user database or signing keys, and the signing keys stay on a server in Germany. If your policy says “no US company anywhere in the path”, deSEC does not meet it.

Hetzner DNS

Hetzner DNS is free and now part of Hetzner Console and the Hetzner Cloud API, so the official hcloud Terraform provider (v1.54.0 and later) manages zones next to your servers. It supports a long list of record types, including TLSA, SVCB and HTTPS, and accounts start with 25 zones (more on request).

The gap is DNSSEC: Hetzner’s DNS page states that Hetzner Console does not currently support it. If you need signed zones, Hetzner is not the right choice today.

IONOS

IONOS has two products, which causes confusion. The DNS hosting from the web hosting side also works for domains registered elsewhere and includes anycast across 14 PoPs. It is not permanently free: IONOS currently offers it at €0 per year for 12 years against a list price of €5 per year, as a limited-time offer. DNSSEC is not included. It comes with the paid DNS Pro add-on, together with secondary DNS and premium anycast.

IONOS Cloud DNS is the infrastructure product, sold by IONOS Cloud GmbH: €1.50 per zone per 30 days with no query fees, DNSSEC (enabled through the API), secondary zones, an official Terraform provider, a Go SDK and ExternalDNS support for Kubernetes. IONOS commits to 99.995% availability of its nameservers. It is the closest European match to Route 53 on API, Terraform, DNSSEC and per-zone billing, though it does not document latency, geo or failover routing policies or health checks.

OVHcloud

At OVHcloud, a DNS zone comes with a domain registered there, and DNSSEC is available at no extra charge. You can also order a DNS zone for a domain registered elsewhere; OVHcloud’s public order catalog lists that zone at no charge, and its DNSSEC guide covers domains at other registrars. Anycast is a paid option billed per domain per year, which replicates records to four points of presence. The official ovh Terraform provider has resources for zones, records and DNSSEC.

bunny.net

bunny.net is a CDN company registered in Ljubljana, Slovenia. Bunny DNS hosts up to 500 zones with no query fees, including smart (scriptable) records; if DNS is the only bunny.net product you use, the $1 monthly account minimum applies. It signs zones with DNSSEC, runs on 36+ DNS PoPs, and has an official Terraform provider with bunnynet_dns_zone and bunnynet_dns_record resources. bunny.net publishes a 99.99% uptime SLA for its platform. It is the closest European match to Cloudflare’s model of DNS bundled with a CDN.

Gcore

Gcore is headquartered in Luxembourg; the contracting entity is G-Core Labs S.A. Its Managed DNS free tier has unlimited zones and unlimited queries on 210+ anycast PoPs, the largest footprint among the European providers in this guide. DNSSEC is included on every tier but is still labelled beta. The Pro plan costs €2.49 per month with 10 million queries included and adds lower minimum TTLs, more health checks and email support. Gcore lists Terraform, OctoDNS, ExternalDNS and Certbot integrations, and its Terraform provider is in HashiCorp’s partner tier. Like bunny.net, Gcore also sells a CDN in the same account.

enum DNS

enum DNS is our product, so weigh this section accordingly. It is generally available, free for every enum account with no per-zone or per-query fee, and that pricing is permanent rather than a promotion. You get A, AAAA, CNAME, MX, TXT, NS, SRV and CAA records, BIND zone import and export (merge, replace or prune, with a dry run), DNSSEC, deletion protection on by default, and DNS-01 certificates through cert-manager. A CNAME at the zone apex is flattened to signed A and AAAA records, so it works with DNSSEC turned on. Zone ownership is confirmed by reading the delegation at the parent TLD, which prevents another account from blocking or claiming your domain. Roman’s write-up explains why that matters.

The limits, stated plainly. enum DNS is not anycast yet: each project’s two nameservers are unicast, reachable over IPv4 only for now, and sit in the same network in Germany. The rollout to an anycast edge network is on the roadmap, not shipped. There is no published SLA for DNS. There is no Terraform provider yet (planned for Q4 2026), and the ExternalDNS provider is planned but not shipped. Zones must be registrable domains, so a subdomain cannot be its own zone; you delegate it with NS records instead. An apex CNAME is resolved once from enum’s side, so a geo-aware or load-balanced target returns the same answer to every client, and the target’s own TTL is not used. It supports eight record types, fewer than Hetzner or Cloudflare, and has no PTR records, GeoDNS or health-check failover. Included support runs on working days; 24/7 response for critical incidents comes with Enterprise Support. And it launched in July 2026, so it has a shorter track record than every other provider in this table. You need an enum account; registration is open and DNS is self-service.

Which provider fits which case?

  • Free, signed zones, no account at a hosting company: deSEC, if a US network operator for the anycast layer and best-effort service are acceptable.
  • Already on Hetzner Cloud, DNSSEC not required: Hetzner DNS, managed in the same Terraform as your servers.
  • Closest match to Route 53 on API, Terraform, DNSSEC and per-zone billing, with an SLA: IONOS Cloud DNS, if you do not need routing policies or health checks.
  • Domains already registered at OVHcloud: OVHcloud DNS, with the anycast option for public-facing domains.
  • Largest European anycast footprint on a free tier: Gcore, if DNSSEC in beta is acceptable.
  • CDN in the same account and a published platform SLA: bunny.net.
  • Free DNSSEC with apex CNAME, next to object storage, with Kubernetes on request, in Frankfurt: enum DNS, if unicast IPv4 nameservers without an SLA are acceptable for now.

How do you move a zone without downtime?

  1. Export the zone from your current provider as a BIND file. Not every provider offers a zone file export; where yours does not, list the records through its API or CLI.
  2. Import it at the new provider and compare record by record. Watch for provider-specific features that need a plain equivalent: Route 53 alias records, routing policies and health checks, and Cloudflare proxied or flattened records. A proxied Cloudflare record moved to plain DNS points straight at your origin, without Cloudflare’s CDN and WAF in front, so plan that replacement first.
  3. Lower the NS TTL at your current provider at least as far ahead as its current value, often two days (172800 seconds). The NS TTL in the parent zone is set by the registry (48 hours for .com, 24 hours for .de) and cannot be lowered, so some resolvers keep the old nameservers that long.
  4. If DNSSEC is on, remove the DS record at your registrar first, keep the old provider signing, and wait for the DS TTL plus the registry’s publication delay. A signed transfer (multi-signer DNSSEC, RFC 8901) only works if both providers support it, and Route 53 does not. Changing nameservers while an old DS record is live breaks resolution for validating resolvers.
  5. Change the nameservers at the registrar. Keep the old zone running for at least 48 hours while resolver caches expire.
  6. Repoint DNS automation to the new provider: Terraform, ExternalDNS, cert-manager DNS-01 solvers and dynamic DNS clients.
  7. Turn DNSSEC on at the new provider and publish the new DS record.

FAQ

Is there a free European alternative to Cloudflare DNS? Yes. deSEC, Hetzner DNS, OVHcloud’s DNS zone, Gcore’s free tier and enum DNS cost nothing for authoritative DNS. IONOS’s DNS hosting is €0 under a current 12-year offer, and bunny.net is free apart from a $1 monthly account minimum. Of these, deSEC, enum DNS and OVHcloud include DNSSEC at no cost, and Gcore’s free tier has it in beta. None of them replaces Cloudflare’s CDN and proxy, which come with its DNS.

Which German DNS providers have an API? deSEC, Hetzner, IONOS and enum all offer an API. Hetzner and IONOS Cloud DNS have official Terraform providers. deSEC has community providers. enum has the enum API and enumctl, with a Terraform provider planned for Q4 2026.

Does it matter where the nameservers are if the records are public anyway? It matters for who can change or take down your zone, who sees query logs, and which law applies to the operator. It matters less for confidentiality of the records themselves.

Is enum DNS anycast? Not yet. Each project’s two nameservers are unicast, IPv4 only for now, and sit in the same network in Germany. Rolling enum DNS out to an anycast edge network is on the roadmap and has not shipped.

Can I keep my domain at my registrar and only move DNS? Yes, with every provider here. You change the nameservers at your registrar and leave the registration where it is. One exception: domains registered with Cloudflare Registrar can only use Cloudflare nameservers, so transfer the registration first. deSEC also needs the DS record set at your registrar, not only the nameservers.

If you want to try the free option on this list that sits next to object storage (and Kubernetes on request), enum DNS takes one enumctl dns zones create and a nameserver change at your registrar. The launch post explains why it is free.

Sources

Build on enum.
Start today.

Sign up and use object storage and DNS right away, or talk to us about Kubernetes.