A DNS
that works
for you,
not on you.
Ten PoPs near you. Operated from Helsinki, EU. Recursive DNS with ad-blocking, tracker-blocking, malware filtering, and a query log you actually own. No third parties, no upsell, no logs we can sell.
Fig. 1 — ten PoPs answering your DoH/DoT/DoQ queries from the closest one.
Defined by what we
refuse to ship.
Every "privacy DNS" startup of the last five years has flogged the same five claims: "blazing-fast anycast", "AI-powered", "zero-trust", "enterprise-grade", "military-grade encryption." We will not be doing any of that. Here is what we are doing instead.
/not selling logs
We make money from subscriptions. Period. Your query log is yours — you set retention, you delete it, you export it. There is no second business model where it ends up.
/EU-jurisdiction by default
The control plane is in Helsinki, the legal entity is in Slovakia, the data plane uses ten PoPs worldwide for latency. Your account and query metadata stay in the EU; cross-border processing happens under Standard Contractual Clauses. We picked this stack because it makes the GDPR question simple.
/not pretending to anycast
We have ten regional PoPs and route you to the closest one. That is geo-DNS, not anycast. Lower routing precision than a Cloudflare-class anycast network, but the topology is auditable end-to-end and the resolvers are ours, not a shared fleet.
/not closed source
The edge resolver — the binary that actually answers your queries — is open source. Audit it. Self-host it. Compile your own and point your router at it. The brand is the trust; the code is just code.
Three steps.
No agents,no apps.
Set it on the router for your whole home, on your iPhone for travel, on your Mac for the office. Same endpoint. Same log. Same rules everywhere.
- Step 01
Sign up
Create an account. Get your unique config-id in your dashboard:
k7m2px9q. Pick which blocklists you want — ads, trackers, malware, parental. - Step 02
Point your device
On iOS / macOS / Pixel: paste
https://dns.vantagedns.com/k7m2px9q/dns-queryinto Private DNS settings. Or DoT:k7m2px9q-vantagedns.dns.vantagedns.com. On routers: same endpoints in DoH/DoT field. - Step 03
Watch the log
Every query lands in your dashboard within ~2 seconds. Block what you missed, allowlist false positives, switch profiles per device. Retention is your call: 24 hours by default, up to 30 days.
Open protocols.
No magic.
DoH (RFC 8484), DoT (RFC 7858), DoQ (RFC 9250) and plain DNS — pick whichever your client speaks. Here is what a query looks like, end-to-end.
# clean query — google.com goes through, normal answer
$ kdig @https://dns.vantagedns.com/k7m2px9q/dns-query +https google.com
;; ANSWER SECTION:
google.com. 300 IN A 142.250.190.78
;; Query time: 7 msec
;; SERVER: dns.vantagedns.com (helsinki)
# tracker — blocked, returned 0.0.0.0
$ kdig @https://dns.vantagedns.com/k7m2px9q/dns-query +https doubleclick.net
;; ANSWER SECTION:
doubleclick.net. 60 IN A 0.0.0.0
;; SERVER: dns.vantagedns.com (helsinki)
;; BLOCKED BY: oisd · category=trackers
# DoT alternative — same config-id, different transport
$ kdig @k7m2px9q-vantagedns.dns.vantagedns.com +tls google.com
;; SAME ANSWER. Different protocol. Your call.The datasheet,
not the brochure.
Numbers we are willing to defend. If any of these ever drift, you will see it on the status page before you see it in marketing.
| 01 | Edge points-of-presence EU · NA · APAC · LATAM · OCE | 10cities | EU · NA · APAC · LATAM · OCE |
| 02 | Transports supported + plain UDP/TCP for self-host | DoH·DoT·DoQ | + plain UDP/TCP for self-host |
| 03 | Mean query latency, EU, p99 measured from monitor.lab | < 10ms | measured from monitor.lab |
| 04 | Recursive resolution, p99 (cache miss) own resolver, not upstream proxy | < 30ms | own resolver, not upstream proxy |
| 05 | Curated blocklists at launch OISD, AdGuard, hagezi, ... | ~12lists | OISD, AdGuard, hagezi, ... |
| 06 | Custom blocklist / allowlist (paid) on personal+ plans | ∞entries | on personal+ plans |
| 07 | Query log retention you decide, not us | 1–30days | you decide, not us |
| 08 | Control plane jurisdiction EU control plane · Helsinki, FI | EU / FI | EU control plane · Helsinki, FI |
| 09 | Edge resolver source audit · self-host · contribute | open | audit · self-host · contribute |
| 10 | Vendor lock-in switch DNS in 30 seconds | zero | switch DNS in 30 seconds |
Switch DNS.
In abouttwo minutes.
Free profile, no credit card. EU-jurisdiction control plane, 10 PoPs, DoH / DoT / DoQ — live now.