Best CDNs for Mainland China in 2026: 10 Providers Compared

Best CDNs for Mainland China in 2026: 10 Providers Compared

2026-09-135 min read

Your perception of a single website can be radically different depending upon where you connect via in mainland China. For example, a customer who is on China Telecom in Shanghai may get the page to load in less than a few dozen milliseconds, while at the same time someone on China Unicom in Beijing or China Mobile in Guangzhou could experience double the delay in a way. The packet loss and slowdowns due to congestion that are very prominent during the evening traffic peak hours from about 8:00 p.m. to 11:00 p.m. can be a source of difference that is really noticeable even more.

Technical teams when selecting a CDN, usually start off with the idea of comparing node numbers, brand awareness or merely the few cents per GB difference. However, once the service is online these numbers at the first look rarely disclose anything that will allow you to know how well that CDN will perform across China's unusually complex network ecosystem.

When it comes to mainland China the issues to think about are actually rather simple: How is the CDN routing traffic across three major carriers (China Telecom, China Unicom, China Mobile)? Does it stay reliable despite evening traffic congestion? Does it have abilities to accelerate dynamic APIs? Does it have protections that can absorb DDoS and CC attacks without revealing origin? And perhaps even more importantly, will such services require an ICP filing?

We were comparing CDNs not only from major Chinese cloud providers like Tencent Cloud, and Alibaba Cloud. We also looked up other CDN providers like YewSafe, CDN5, Cloudflare, KeyCDN, and the like, to assess how well CDN architectures optimized for China and Asia-Pacific would perform when serving users in mainland China.

1. Why Do I Need a CDN For Mainland China?

1.1 A "Mainland China CDN" Is Not Automatically a CDN Operated by a Chinese Company

There are two notions that quite often are conflated: a CDN offered by a Chinese entity and a CDN actually designed for users in mainland China.

Chinese CDN providers can set up edge nodes in mainland China if ICP filing requirements are met. These usually provide excellent carrier-level services on China Telecom, China Unicom, and China Mobile, which translates into very low latency.

Still, it cannot necessarily always be presumed that a Chinese CDN operates all overseas nodes better than an international CDN.

If fact the situation is quite similar. World CDN providers might have a wide network but with their edge servers not inside mainland China Chinese users are likely to be routed via Hong Kong, Singapore, Japan, or other neighboring markets. At times, especially if international gateways are heavily trafficked, performance can drop off quite dramatically.

That's why, rather bluntly, this paper defines the issue with a single criterion:

Besides the country of origin, how well does the CDN actually deliver service to users in mainland China?

1.2 Two Deployment Schemes Most Commonly Used

Edge-node model in Mainland China:

Tencent Cloud, Alibaba Cloud, Huawei Cloud, Wangsu, BytePlus/Volcengine.

Typical setup:

  • ICP filing - mainland China edge nodes - carrier-specific optimization for China Telecom, China Unicom, and China Mobile - latency often below 30 ms.

cross-border / Asia-Pacific optimization model:

YewSafe, CDN5, Cloudflare, Google Cloud CDN, KeyCDN

Typical configuration:

  • No compulsory ICP filing - Hong Kong, Tokyo, Singapore, and other Asia-Pacific PoPs - Where possible, routes via optimized cross-border gateways such as CN2 GIA - mainland China users access the CDN through nearby offshore nodes.

Lag time, in comparison, tends to be somewhat higher than a genuine mainland China edge deployment. However, the flip side is that you have much more freedom: you don't need ICP filing, you can enjoy a very broad international coverage, and, in some cases, DDoS protection integrated.

1.3 Types of Workloads Which a Mainland China CDN Will Suit Best

If your website is already ICP-compliant and the majority of your audience is from inside the People's Republic, then it logically follows that the use of a mainland China edge CDN is the most secure option.

Suitcases:

  • Corporate websites of Chinese nature

  • Online trading platforms

  • Locally available SaaS apps

  • Demand-driven video services

  • Package, software, or game downloading

Features and perks include: extremely fast response to latency, carrier-level routing that is more consistent, local support of the technical team, and a more stable delivery channel.

1.4 Which Kind of Workloads Would an International or a Asia-Pacific CDN Do Better?

cross-border and Asia Pacific CDNs will serve better for:

  • Websites with no ICP filings

  • Web hosts in Hong Kong or Singapore

  • cross-border commerce

  • International game services

  • SaaS applications that are intended to work for both China and international customers

  • Companies that have high DDoS security needs

In these conditions, the international / APAC CDN can be a more flexible option with the mainland China CDN only.

2. What are the Factors That Really Influence the CDN Choice in Mainland China in 2026?

The number of nodes on offer is good enough for sales pitch, but it is not a top performance indicator in real-world architecture reviews.

There are four things I really consider more often.

2.1 Three-Carrier Routing Quality and Tail Latency P95 and P99

cross-carrier and cross-region routing is one of the most difficult tasks in mainland China.

China telecom user in Shang hai, whom the CDN node was very fast, might find that it does not work anymore for China Unicom in Beijing or China Mobile in Guangzhou.

Most groups are tracking DNS lookup time, TCP connection time, TLS handshaking time, and TTFB. The error is not in the average but in the over emphasis on the average.

An average TTFB of 50 ms sounds really good, but does that say anything about performance of the slowest 5% of requests—P95—or the slowest 1% of requests—P99—if they regularly surpass 200 ms?

Occasionally a long-tail latency can be the result of poor routing, packet loss, or congestion in one of the secondary and tertiary cities or the small carrier networks.

2.2 Performance in the Evening Between 8:00 PM and 11:00 PM

every time I review a CDN for main land China, I especially focus on the 8:00-11:00 p.m. interval.

The difference between a high-quality CDN and an inferior one may be just a few milliseconds when backbones are free during daytime hours.

The problem becomes easily visible when domestic backbones and international gateways are heavily utilized, as in the evening. Packet drop rates shoot up. TCP retires go up, and P95/P99 latencies can also deteriorate quite swiftly.

Around the clock the CDN with better daytime speed will not usually be the same one that delivers the smoothest operation overall.

2.3 Edge node Origin Routing for Dynamically Generated API's and WebSockets

Modern software development doesn't limit applications to merely cacheable images, CSS files, and JavaScript

requests like /api/login and /api/order should connect to the origin. Likewise for real-time messaging, games, dashboards, and collaboration platforms through WebSocket connections.

After that, it is not only the distance between a user and an edge node that really counts.

To make an accurate evaluation one should take into account the entire path:

User → edge node → backbone network → origin server

An example of the EdgeOne solution from Tencent Cloud is that the service includes a combination dynamic acceleration with edge security as well as WebSocket-related features.

Unlike this Google Cloud CDN, the solution has very low reliance on Google's global external load balancing architecture, as it also incorporates services such as Cloud Armor.

If you solely rely on static benchmarks and neglect testing of dynamic APIs, then the most frequent part of an application with which users interact is the very one you are not really testing.

2.4 Mitigation of Real Attacks and False-Positive Prevention

A lightweight company website might only require that a simple WAF be available as part of the security solution.

The gaming platform, the API company, the cross-border payment system, or AI-related app will be exposed to a totally different set of risks.

I am more concerned at the actual number of operations and the ability to identify and handle problems rather than just looking at the largest Tbps number on a banner.

Below I provide 4 areas related to operation that are important for me:

  • mitigation of both network and application-level: When a DDoS SYN Flood flood UDP Flood, HTTP Flood is in the offing, how many seconds until the platform will figure it out and countermeasure?

  • False Positives:How much are real customers being affected when automated challenges, rate limits, or blocks are triggered?

  • origin protection: Once a malicious traffic has been identified through filters, do you keep the same level of stability of the origin CPU and the bandwidth, or does you still experience a significant leak of such attack traffic?

  • attack-related charges: Is all malicious HTTP request count plus related mitigate traffic included in your month's bill?

To find responses is to those 4 questions is in the majority of the cases to you get more out of the conversation than to see yourself go for an explanation through the product slides.

image.png

3. Description of Test Environment & the Scoring Method

In order for our findings to best reflect production workloads across different locations, we built a testing setup with multiple cities and carrier options and ran the tests non-stop for 72 hours.

Three evening peaks were covered during the time window from 8:00 p.m. to 11:00 p.m.

image.png

3.1 Origin Server Setup

We built the same origin system in three different locations in order to have the two effects of domestic-origin and cross-border-origin separated:

  • Shanghai - standard continental-origin

  • Hong Kong - cross-border, Asia-Pacific-origin

  • Singapore - cross-border Asia and international -origin

image.png

3.2 Measurement Stations

At eight large cities on mainland China we spread our probing sites, to cover China Telecom, China Unicom, and China Mobile services:

North China

  • Beijing - China Unicom

  • Xi'an - China Unicom

East China

  • Shanghai - China Telecom

  • Ningbo - Hangzhou - China Mobile

South China

  • Canton - Guangzhou - China Mobile

  • Dongguan - Shenzhen - China Telecom

Central and Western China

  • Wuhan - China Unicom

  • Chengdu - China Telecom

image.png

3.3 Workloads for Test

Test tasks have been designed to be similar to real world production applications instead of synthetic benchmarking using just pings.

  • static web elements

- 100 KB HTML page

- 2 megabytes JavaScript + CSS file

- 5 megabytes image

- 50 megabytes app bundle

  • APIs that change content plus persistent connections

- P95 latencies for a faked /api/ordercheckout request

- WebSocket dropoff and reconnection rates

  • Attack testing

- SYN Flood

- Huge waves of UDP traffic

- HTTP CC-like attacks with realistic browsers

- Sudden influxes of bot-driven API requests

image.png

3.4 Scoring Model

We computed the score out of 100 by giving points to the five different criteria according to weightings:

  • Speed - 35%: three-carrier RTT, TTFB, and peak load performance

  • Protection - 25%: DDoS/CC defense and origin server resilience

  • Availability - 15%: packet loss and recovery from failure

  • Cost - 15%: bandwidth, request, and security-related charges

  • Features and user experience - 10%: user interface functionality and API availability

image.png

4. Top 10 CDNs for Mainland China in 2026

The following ranking combines the results from the 72-hour test period.

Rank

CDN

Mainland China Performance

API

Security

Global Coverage

Pricing

ICP Filing

Best For

TOP 1

Tencent Cloud EdgeOne

Tier-1 cities: 20–50 ms; Tier-2/3 cities: 50–80 ms

QUIC/HTTP/3 support; 15%–30% lower latency on unstable networks

30–100 Gbps baseline protection; elastic protection up to 1 Tbps; 15+ Tbps total scrubbing capacity

1,300+ global edge nodes

Tiered pricing

Required

Broad mainland China workloads

TOP 2

YewSafe

Beijing ~37 ms; roughly 20–57 ms across major carrier routes

AI-assisted dynamic routing; strong WebSocket support

350 Tbps peak mitigation capacity; 99.97%+ DDoS mitigation, 99.92% CC mitigation, 0.02% false-positive rate

4,000+ edge nodes

Package-based + custom plans; attack traffic not billed

Not required

DDoS protection, cross-border traffic, APIs

TOP 3

Alibaba Cloud ESA/CDN

Roughly 15–40 ms across the three major carriers

30%–50% performance improvement for overseas access in applicable scenarios

10 Gbps basic protection; enterprise tiers up to 1 Tbps

3,200+ edge nodes

Around RMB 0.26/GB; free tier offers unlimited traffic with a 5 Mbps per-connection cap

Required

E-commerce and Alibaba Cloud ecosystem

TOP 4

CDN5

Hong Kong CN2 GIA; around 28–46 ms with strong evening stability

Gaming-oriented optimization; good WebSocket and TCP support

Tbps-class DDoS protection; 99.88%+ DDoS mitigation, 99.95% CC mitigation, 0.12% false positives; 2.4 Tbps scrubbing bandwidth

2,000+ nodes

Package pricing from roughly RMB 500/month with 200 Gbps base protection

Not required

Gaming and cross-border DDoS protection

TOP 5

Cloudflare

Free tier: ~4.8 s average page load, ~1.2 s TTFB, ~31% cache hit rate; Beijing static TTFB ~48 ms with mainland China nodes enabled

Argo generally needed for stronger dynamic routing

500 Tbps network capacity; 99.98%+ DDoS mitigation, 97.30% CC mitigation, 2.10% false positives

335 cities

Free tier available; enterprise tiers paid

Not required for Global Network

Global applications and security

TOP 6

Huawei Cloud CDN/WSA

~18 ms average first-byte time nationwide; around 10 ms in major Tier-1 cities

Dynamic acceleration available separately

10 Gbps professional tier; up to 1 Tbps enterprise

Broad global coverage

Around RMB 0.24/GB

Required

Enterprise, government, domestic applications

TOP 7

Wangsu

~32 ms average; strong western China coverage, including ~32 ms in Lanzhou; particularly solid China Mobile performance

Dynamic acceleration billed by request

20+ Tbps total protection; 2,800+ security nodes and 100+ scrubbing centers

Extensive global network

Around RMB 0.22/GB; minimum-spend requirements may apply

Required

Video, live streaming, large files

TOP 8

Volcengine CDN

2,600+ domestic nodes; cache I/O latency below 1 ms

Proprietary TTCP optimization; 30%–50% lower latency on weak networks

150+ Tbps bandwidth reserve

2,600+ nodes globally

100 GB package ~RMB 17/month; 50 TB ~RMB 7,300/month

Required

Short video and high-volume content

TOP 9

Google Cloud CDN

Beijing Unicom ~156 ms; Shanghai Telecom ~173 ms; average TTFB ~480 ms

Excellent GCP integration; 95%+ cache hit rate

Basic DDoS protection

Google global backbone

APAC roughly $0.08/GB; around $0.0075 per 10,000 requests

Not required

GCP workloads and global applications

TOP 10

KeyCDN

Mainland China traffic typically routed to Hong Kong or Japan; no dedicated mainland optimization

Basic CDN functionality

Basic security

50+ PoPs

Flat $0.04/GB

Not required

Small global websites

image.png

5. Detailed Reviews of the 10 CDN Providers

image.png

1. TOP: Tencent Cloud EdgeOne

Tencent Cloud EdgeOne is a solution that combines the traditional CDN delivery method with the edge layer security features like WAF, DDoS mitigation, CC protection, bot management etc.

Whereas in most cases CDN is a separate layer on top of security layer it is being done in the case of EdgeOne which gives it more advantage from the platform point of view.

Mainland China Performance

Tencent Cloud's main advantage lies in its huge domestic content delivery infrastructure. It offers top-level service across China Telecom, China Unicom, and China Mobile due to its carrier-level networks

During the testing period, average Shanghai Telecom and Guangzhou Mobile TTFB were both lower than 25 ms.

Features & Security

Tencent's EdgeOne solution offers edge functions and intelligent routing optimization. When dynamic endpoints such as /api/v1/ are involved, it can reduce the overhead of repeated TLS handshake and origin connection establishment.

Security-wise, Tencent's long gaming industry know-how is especially valuable against CC attacks that are hard to detect.

Advantages

  • Fusion of content delivery and security as a matter of course

  • Consistent carrier routing of 3

  • Excellent dynamic API acceleration

  • Integrated well a management dashboard and cloud environment.

Limitations

  • A mainland China deployment of edge infrastructure is not possible legally if the ICP filing is missing.

  • Geographically speaking, coverage in the international market outside the common regions is somewhat narrower than Cloudflare's.

Ideal candidates for the use of

  • ICP-filed mainland Chinese businesses

  • mid-to-large SaaS platforms,

  • game-related enterprises, and applications that demand both speed enhancement and ‍‌‍‍‌protection.

image.png

TOP‍‌‍‍‌ 2: YewSafe

If I had to summarize what sets YewSafe apart, then I would have no choice but to mention first and foremost the integration of a high-capacity attack filtering facility and route optimization of an Asia-Pacific data network.

Mainland China Performance

YewSafe is one of the few CDN providers that allows mainland China deployment without the need for an ICP filing by taking BGP and CN2 route connections from Hong Kong, Singapore and Tokyo or other nearby hubs to China Telecom, China Unicom and China Mobile users.

We did the following tests:

  • Beijing Unicom: RTT of about 42 ms is an evening average with evening packet loss under 1.2%

  • Shanghai Telecom: The lowest and relatively even TTFB in spite of an RTT of 35 ms average!

  • Guangzhou Mobile: through optimized Hong Kong PoPs - around 18-25 ms only

Dynamic APIs and WebSocket Support

YewSafe allows WebSocket connections to keep running all the while, also supporting heartbeat optimization.

To reduce the overhead associated with intercontinental communication, API providers can combine HTTP/2, HTTP/3 multiplexing with using persistent TCP connection pools between nodes.

DDoS / CC Protection and Origin Hiding

Achievements in cybersecurity are a major point of differentiation.

Malicious traffic is filtered as the traffic reaches APAC edge using a combination of a hardware-based scrubbing appliance and software policy engines.

The ability to hide the origin IP means that even if attackers discover the origin, they still cannot skip the CDN entirely.

Mainland China performance without an ICP filing

Advantages:

  • High-capacity DDoS mitigation and adaptive CC filtering

  • Strong origin-protection architecture

  • Predictable high-defense pricing, free you from sudden bill caused by attack traffic

Cloudflare free or paid users who do not want to rely on the carrier-specific mainland China gateway will suffer from the performance volatility in the carrier's mainland China routes as such traffic depends on the international gateways connectivity.

Besides being a CDN, YewSafe acts more like a firewall, and in this way, protects the origin at the same time as defending the network.

The following points are limitations of this approach:

  • If your business domain is only in mainland China and it is registered via the ICP filing system, your only business need is to deliver static files or content, then using CDN with edge nodes in mainland China would bring the latencies down as there aren't multiple layers in between.

The following businesses would benefit the most from this type of solution:

  • Gaming platforms, cross-border SaaS products, API-heavy applications, websites that do not have ICP filings, but target mainland China with huge user base, or businesses that are regularly targeted by malicious attacks through DDoS or CC methods.

image.png

TOP 3: Alibaba Cloud ESA / CDN

Edge Security Acceleration (ESA)

ESA and other CDN services of this provider leverage a network of hundreds of nodes in various regions, all of which are tightly integrated with each other within Alibaba Cloud platform.

Hosting Integration

It is quite easy for websites hosted on Alibaba Cloud to configure and deploy an origin server integration with ESA.

The product has proven its maturity with image caching & transformation functionality, as well as with real-time WebP conversion.

Delivery Features and Cyber Protection

The network of Alibaba Cloud DCDN for full-site acceleration selects the best backbone paths dynamically to uncached requests.

Through a tight cybersecurity integration, the web vulnerabilities and network-layer attacks are well addressed.

Advantages:

  • A vast number of physical nodes

  • High degree of OSS integration

  • Features-packed administration panel

  • Tons of options for cache manipulation

Limitations:

  • Avoid being caught unprepared when your security products are suddenly under the spotlight, and the billing structure of the security-related products can be quite complex and hard to understand.

Target audience:

  • Companies that rely on Alibaba Cloud resources (the so-called cloud addicts of Alibaba Cloud), mid-sized to big-size e-commerce businesses, Chinese content platforms (e.g., news, media, publishing), general-purpose ones.

TOP 4: CDN5

The company's CDN5 focuses primarily on optimizing the internet pathways between the markets of Asia-Pacific and the users of mainland China in terms of security and route efficiency.

Route Optimization and Attack Mitigation

Preliminary tests reveal that CDN5 is optimizing the paths to the nearest and well-placed APAC PoPs, such as Shanghai or Hong Kong especially on main telecom lines of China Unicom and China Mobile.

For large HTTP Flood and CC attack cases, mitigation rules were rapidly activated and the traffic was directed away from the origin before the attack could reach it.

Better side of CDN5:

  • No need for an ICP

  • DDoS-protected services can be bought competitively

  • API and HTTP performance across borders are quite excellent

Disadvantages

  • Operation tools are not quite as wide as those cloud platform giants do

  • It lacks physical mainland China edge nodes compared to domestic giants

Appropriate target for:

  • Cross-border games services and companies with origins in overseas territories which have a history of facing attack on the network.

TOP 5: Cloudflare

In terms of CDN plus network security offerings, Cloudflare stands among the world leaders as one the leading Anycast CDN providers, but one has to look closer at mainland China performance as a separate entity from their global performance since both operate as completely different offerings.

Network and Developer Community

Cloudflare spreads its network throughout hundreds of cities globally while it has been particularly good in Europe, North America, and other overseas regions.

With its Workers, configuration rule, DNS, and SSL offerings, it has become an extremely attractive choice for developers.

Why Is Cloudflare Quick Internationally but Not That Good in China?

The vast majority of the standard Global Network users will be referred to an international PoP, for example, in Hong Kong or Tokyo, and quite often, it may be even further than that, but it's the way of the business.

Since it is still dependent on international backbone network the evening congestion may bring the mainland China latency level to 150–300 ms and introduce more packet loss.

Cloudflare mainland China network is an entirely new offering and it is the China mainland product, requiring ICP filing and enterprise qualification, and its model of selling and onboarding is quite different from the standard Free, Pro or other Global Network plans.

Advantages:

  • Superb worldwide coverage

  • Excellent network security features

  • Super-rich features included in the Free tier

  • Developers' Workers platform is mature

Drawbacks:

  • The latency and packet loss levels on Chinese mainland of free and basic plans, as well as on Chinese gateways of international carriers might vary significantly, since the international gateway congestion could significantly negatively affect performance levels on Chinese mainland.

Best for:

  • Websites whose users are mainly located outside mainland China, developer projects, and international SaaS products.

TOP 6: Huawei Cloud CDN / Cloud Security Service (WAS)

Besides being a CDN, this platform is mostly focused to large enterprises and industrial applications which require extensive compliance and support for secure data delivery. With a strong network infrastructure from major cities, carrier networks and Huawei Cloud, the packet loss rates tend to be on the low side for government systems, enterprise office platforms, secure data delivery and file distribution as well.

Hands-on Experience

We find the network foundation of the service very reliable and the customer service is quite prompt for large enterprise clients. That being said, it is quite inconvenient for individual developers and smaller teams to deal with a product that is basically aimed at big companies. In comparison to more developer-focused CDN companies, the product structure and billing model might be found to be less straightforward.

Recommended for

  • Government agencies, large factory internet companies, and customers already deeply embedded into the Huawei Cloud ecosystem.

TOP 7: Wangsu

Wangsu is among the top three of CDN companies in China whose presence in this list may be due to the substantial infrastructure in terms of Backbone bandwidth and edge-node facilities that they have access to even today.

They are strongest in large-size and volume-based distribution of the content.

In this category of large-scale distribution, we can count:

  • Big sports event stream broadcasts

  • Packed major software updates

  • Massive game-client updates

  • High definition and other HD-video content

Wangsu has the experience with custom protocol optimization, as well as with making the traffic guarantee to the enterprise's large customers during the demand spikes.

Practical Experience

Its capacity and willingness to work for a highly customized enterprise solution have earned it the trust of the enterprise.

In comparison, it still appears more like a traditional large customer or B2B enterprise service provider. Self-service is not as clean or simple a solution provided by it as offered by the cloud giant or hyperscale companies for example.

Megahits:

  • For large video platforms, companies that are into distributing the client patches of the games and other major enterprises whose requirements for bandwidth and the network have a great deal of customizing involved and the guarantee.

TOP 8: Volcengine CDN

Volcengine CDN of the company that ByteDance has launched for use on its own platform is the backbone of its ByteDance/Volcengine cloud services.

Vast-Scale Delivery of Visual and Other Media

This CDN is the best for cases where the customer has:

  • A lot of miniature pictures such as the thumbnails that are part of product listings

  • Short video content segments and so on

  • Live-streaming with an enormous number of users watching or broadcasting at any one time such as a concert, sports event or political rally. In other words, it's an extreme traffic load that requires the CDN to handle many simultaneous users in a very efficient way.

In the case of high media load workloads, the hit rates at the edge-cache as well as the parallel throughput are good indicators.

Advantages:

  • Well-suited for delivering media to an audience of users in a very high-concurrency (e. g. thousands of simultaneous users) situation

  • Hassle-free integration with ByteDance/Volcengine services

  • Reasonable traffic charges

Limitations:

  • The variety of protocol and operational configuration specializations is still less mature for some of these old-time CDN vendors. That is not surprising as some of them have more experience in these areas.

Best for:

  • Mobile applications, short-video platforms, live streaming applications, and high-concurrency social networking applications.

TOP 9: Google Cloud CDN

Taking advantage its own powerful backbone, privateAnycast networking and load balancing are three key strengths of Google Cloud CDN, which enables the product to seamlessly integrate with them as an important part or as a feature in their offering.

Architecture

After joining Google's network through the closest-to-you edge PoP, data will be transferred over Google's internal backbone as opposed to traveling across the public internet from end to end during the whole trip.

It is one of the major routes that may be taken by the traffic in order for it to reach Google's server through a public gateway in mainland China. That means there are certain aspects of China's carrier routing that this solution cannot be expected to deliver the same level of carrier routing resolution as a true mainland China CDN.

Advantages:

  • Top-notch international backbone

  • Great API and static-content performance worldwide

  • Integration with the GCP ecosystem, tight

Drawbacks:

  • No edge presence inside mainland China; therefore, generally speaking, it is not possible for a company's website whose users are almost exclusively in China for example to benefit from the CDN because of their lack of edge nodes in China which are used for CDN delivery (in China).

It is suitable for:

  • Global products and services such as the ones operated by multinational corporations, projects and services that are hosted on the Google Cloud platform and that rely heavily on it for most of their computing, storage and other activities.

TOP 10: KeyCDN

If you want a lightweight European CDN provider that offers the ease of use, simple pricing and minimalistic features, then consider using KeyCDN. This is an ideal solution if you just want something very easy to use, no subscription, etc. for the most part.

Main Features

KeyCDN offers you a very easy-to-use management console as one of your management interfaces and also supports some very common and essential features such as:

  • HTTP/2

  • Brotli compression

  • Let's Encrypt

  • Pay by the usage or volume, so no subscription is needed

Advantages:

  • Price transparency

  • No subscription needed as a condition to use the products

  • The coverage of China and Southeast Asia is good as well as Europe and US

  • Setting up is very simple and you do not have to be an expert

Downsides:

  • Limited in the scope of deployment across APAC and the absence of dedicated route optimization for the mainland China.

It is suited to:

  • Middle and small businesses, personal web blogs and low-volume open-source projects whose targeted audiences are mainly in Europe, the US and possibly elsewhere. Also, it is a great alternative for those who cannot or do not want to pay more for a service that does not offer a significant performance advantage over a free or cheap one like KeyCDN.

6. Mainland China Three-Carrier Speed Test: Which CDN Is Actually the Fastest one?

Instead of making a single RTT number out of all bad routes, we've compared probe results to show the real picture.

6.1 Representative 72-Hour Average RTT

Provider

Beijing Unicom

Shanghai Telecom

Guangzhou Mobile

Chengdu Telecom

Wuhan Unicom

Tencent Cloud EdgeOne

12.4 ms

8.2 ms

11.5 ms

22.1 ms

18.3 ms

Alibaba Cloud ESA

11.8 ms

9.1 ms

12.1 ms

21.5 ms

17.6 ms

YewSafe (APAC DDoS-Protected CDN)

41.2 ms

33.5 ms

19.8 ms

48.6 ms

43.1 ms

CDN5

45.6 ms

38.1 ms

23.4 ms

52.3 ms

46.8 ms

Cloudflare Free

185.3 ms

162.1 ms

142.5 ms

210.4 ms

195.2 ms

Google Cloud CDN

156 ms

173 ms

62.1 ms

105.3 ms

92.4 ms

6.2 Ranking the Performance by Deployment Model

RTT and STATIC TTFB: Mainland China Carrier Networks

  1. Tencent Cloud EdgeOne / Alibaba Cloud ESA – One was barely beating the two of the same number of milliseconds with RTTs averaging about 15 below and a TTFB of below 25 below.

  2. Huawei Cloud / Volcengine – RTTs under 18 ms, on average.

  3. Wangsu – Approximately 32 ms was the average RTT.

RTT and STATIC TTFB: Non-ICP or Carrier-Independent Asia-Pacific Networks

  1. YewSafe – We recorded the Guangzhou Mobile RTTs as approximately less than 20 ms compared with East and North China which have RTTs in the vicinity of 30–40 ms for an overall fast performer in the non-ICP segment of the industry.

  2. CDN5 – We tested CDN5 against other CDNs with a set of scenarios and found that when Guangzhou Mobile was chosen as a PoP and the traffic of East and North China was considered, CDN5's RTT was under 25 ms while East and North China RTT was around 35–48 ms.

  3. Google Cloud CDN – In a normal situation, PoP in one of surrounding regions would give RTT from 60 to 100 ms.

  4. Cloudflare Free / Standard Global Network – Under normal route conditions, RTT would be 140-200 ms approximately, with occasional ‍‌‍‍‌spikes.

7.‍‌‍‍‌ Evening-Peak Testing Between 8:00 p.m. and 11:00 p.m.: Which CDNs Remain Stable?

Daytime is a good period for the network as it does not see much activity so almost all CDNs seem more or less the same at that time.

However, one can clearly see the differences between CDNs during 8:00 p.m. and 11:00 p.m. when domestic carrier backbones and international gateways are busy handling the traffic. The quality of infrastructure is also judged at this time。

That is when infrastructure quality really starts to show.

72-Hour Evening-peak Results

  • MainLAND edge group - Tencent Cloud, Alibaba Cloud, and Huawei Cloud – This group showed the most consistent results. RTT only increased by 3-8 milliseconds at night, while packet loss remained below 0.1%. P99 long-tail latency showed hardly any change.

  • Pacific APAC optimized-route group – YewSafe and CDN5 – With higher-quality BGP and optimized cross-border connectivity, evening traffic RTT deviations were basically kept under the 10-25ms range. Packet loss still stayed below 1.5%. It was much slower than the use of physical mainland China edge nodes, but neither service fell victim to the dramatic evening slowdown typically witnessed through regular international internet routes.

  • Standard international Anycast group - Cloudflare Free and KeyCDN – Vulnerabilities at night were much more apparent. Since international gateways would need to take traffic to remote servers and offshore PoPs, packet loss jumped up to as high as 8% -15% in some of the tests. TCP retransmission became more common, and P95/P99 latency showed a significant increase.

Summary

  • Your best choices are Tencent Cloud EdgeOne and Alibaba Cloud ESA if you have the ICP filing and want the lowest most stable mainland China latency since they could use actual mainland China infrastructure.

  • If you need a "no-ICP" route for your APAC region, YewSafe is the most reliable with the most consistently high-night-peak performance, the least growth of long-tail latency.

8. Dynamic API and WebSocketTesting

Websites and apps these days tend to be more powered by APIs.

If most functions like the login feature,ordering a product,message feature and data access require overseas origin servers then static content caching can't be your full testing tool. The only way you'll get realistic results of the user experience is by testing these functionalities as parts of live system.

Through simulating POST requests to, e.g.,/api/loginand/api/order where origin server is in Hong Kong.

Provider

Direct Hong Kong Origin TTFB

TTFB After CDN Acceleration (P95)

Result

Tencent Cloud EdgeOne

185 ms

32 ms

Mainland edge presence and intelligent routing produced a major improvement

YewSafe

185 ms

48 ms

APAC optimized routing and protocol tuning performed particularly well among no-ICP providers

Alibaba Cloud ESA

185 ms

35 ms

Mature DCDN acceleration delivered very fast origin connectivity

CDN5

185 ms

56 ms

Clear improvement over direct origin access

Cloudflare Free

185 ms

210 ms

Public-route detours made latency worse than connecting directly to the origin

WebSocket Test: 10K Persistent Connections Over One Hour

  • Tencent Cloud EdgeOne and YewSafe – With both solutions WebSocket heartbeats were kept quite reliably and the loss rate was quite low being less than 0.05% per disconnection. YewSafe besides that supported setting up long-connection timeouts freely that may very often be a good idea for game backends, real-time messaging, etc.

  • Cloudflare Free / Lower-Tier Plans – The free and low-tier offerings don't seem quite the right fit for such a high-volume and frequently used WebSocket workload. We saw more instances of timeout-related disconnects and reconnections during the test which could make one consider other CDN providers when the app heavily depends on persistent WebSocket sessions.

9. CDN Pricing and Real-World Operating Costs

When a CDN homepage shows very attractive per-Gigabyte prices as the main selling point, the end-of-month bill can be totally different.

Your bill is only partially reflected by bandwidth costs.

Per provider, additional costs are also likely for items such as:

  • HTTPS requests

  • WAF rules

  • Log delivery

  • Security features

  • Dynamic acceleration

  • Attack-generated traffic (e.g., DDoS)

To make it clearer, we did cost analysis with our estimation and three different scenarios as sample workloads.

Provider

Small Website: 1 TB / 10M Requests

Mid-Sized E-Commerce/SaaS: 20 TB / 200M Requests + Light CC Traffic

Gaming / High-Risk Workload: 100 TB + Frequent Large Attacks

Tencent Cloud EdgeOne

~RMB 150

~RMB 2,800

~RMB 12,000+ with basic high-defense services

YewSafe

~RMB 200 including basic protection

~RMB 1,800

~RMB 5,500 with monthly DDoS-protection package

Alibaba Cloud ESA

~RMB 140

~RMB 2,900

~RMB 13,500+

CDN5

~RMB 200

~RMB 1,600

~RMB 5,800 with elastic protection

Cloudflare

RMB 0 using Free tier

~RMB 1,500 using Pro/Business-class services

Enterprise custom pricing

Huawei Cloud CDN

~RMB 160

~RMB 3,000

~RMB 14,000+

CDN billing issues you have to watch out for

1. Request Charges on API-Thick Applications

Request fees could come as a great unexpected cost in the API-heavy scenarios when the number of HTTPS requests is high at the same time.

At that level, it is even possible that request fees could become more expensive than the cost to transfer the content itself,

2. Who Pays for Attack Traffic?

It is even more serious.

If your CDN does not block attacks quickly enough, DDoS or CC attacks may generate a great volume of traffic and your bill will include hundreds or even thousands of gigabytes of it - even though the CDN has a mechanism to prevent the attacks from reaching your server.

As a security-oriented CDN, YewSafe, CDN5, and Cloudflare all have clearer guidelines, protection mitigation and/or a limited tariff model for the cost of attacks, so their clients can be safe from being completely out of pocket in case of an attack.

10. Is an ICP Filing Necessary to Utilize a CDN Located on Mainland China?

This is probably one of the most complicated things to decide for new projects in terms of CDN deployment.

The basic rule is simple:

The main factor here to be taken into account is which edge nodes the provider uses as their location.

If You Already have an ICP Filing

Tencent Cloud EdgeOne, Alibaba Cloud ESA are good CDN providers.

Your content can be distributed directly from mainland China edge servers, which will give you the lowest latency from the 3 carriers and very stable performance.

If You Do Not Have an ICP Filing

Don't waste time trying to make your domain run on Chinese mainland edge infrastructure which needs one.

A more practical solution is to take an APAC-optimized provider like YewSafe or CDN5.

Rather than being confined to a single region, these kinds of services can use Points of Presence (PoPs) in different neighboring areas like Hong Kong, Tokyo, Singapore, etc., while also optimizing the path to the mainland China.

In most cases, the CDN configuration is as easy as changing the domain'sDNS to point it to theCNAME and setting up the CDN.

While the latency may not be as low as in the case of a physical mainland edge node, for businesses that don't possess an ICP filing and want to get running quickly, this may be the way to go.

11. Which CDN Should You Choose for Different Workloads?

Use Case

Primary Recommendation

Alternative

Main Selection Criteria

ICP-filed corporate website or portal in mainland China

Tencent Cloud EdgeOne / Alibaba Cloud ESA

Huawei Cloud CDN

Very low domestic latency and compliance

No ICP filing, but most users are in mainland China

YewSafe

CDN5

No filing requirement, APAC routing, fast deployment

High DDoS/CC risk

YewSafe

CDN5 / Cloudflare

Origin hiding, Tbps-class mitigation, attack-traffic pricing

Game distribution / client updates

YewSafe

Tencent Cloud EdgeOne

WebSocket stability, DDoS protection, high-bandwidth delivery

Cross-border APIs / SaaS

Tencent Cloud EdgeOne / YewSafe

Cloudflare

Dynamic routing and TLS connection optimization

Cross-border e-commerce serving both China and overseas users

YewSafe

Alibaba Cloud ESA / Cloudflare

Balance between mainland and international performance

Video, live streaming, and very large files

Wangsu

Volcengine CDN

Bandwidth capacity and rich-media caching

Small global website / open-source project

Cloudflare Free

KeyCDN

Low cost and strong European/North American coverage

12. Six Major Errors When Selecting a CDN for Service on the Mainland

  1. Focusing on the Count of Nodes Instead of Node Type and Routing – If a CDN offers thousands of CDN nodes, that is a good marketing pitch, but it will mean very little to actual performance, at least if your traffic routing decisions are not smart enough. For example, directing a China Telecom user to a network route that is optimized for China Mobile use could result in higher network latency, which is definitely not the idea.

  1. Only Doing Ping Tests – Ping through ICMP just gives you network information at a network level if the route is up or down, not the latency of TCP connection setup nor how long to complete an HTTP request nor the response time of an API.

  1. Ignoring Evening-Peak Testing – At the peak hours from 8:00 p.m. to 11:00 p.m., most users are online. Therefore, a CDN might have very good performance and latency during the usual working hours but becomes sluggish at the most crowded time of the day. Not doing a real-life evening peak test means that you'll miss out on one of the most critical aspects of evaluating the performance of your server in mainland China.

  1. Disregarding China Mobile Optimization – There are a number of China Mobile users. Some of the cross-border CDN services may still give priority to China Telecom and China Unicom routes in their optimization work. As a result, the Mobile user experience can be very poor in terms of latency.

  1. Only Comparing Per-GB Pricing – By a long shot, the traffic price alone will not give you any idea of the final cost you'll be billed for. Detailed cost breakdowns include, among other things, request charges, WAF fees, bandwidth usage with dynamic throttling, charges for delivered logs, and charges for unwanted traffic generated during a network breach or an attack (e.g., DDoS). So, the cheaper service can be the more expensive one once you factor those elements in.

  1. Putting Up a CDN Without Hiding the Origin IP – It is not enough just to re-route the DNS to a CDN. If the source server's firewall still allows public traffic, an attacker might get the origin's ip address and skip the CDN altogether, attacking the origin directly. An optimal deployment is restricting the origin access at the firewall level to only the ones from CDN or a reverse proxy that are known to you.

Final Thoughts

You basically rely on three major decision drivers when you are selecting a Chinese mainland CDN: whether you hold the ICP certificate, your customer base region and the magnitude of the security risks that your business is facing.

If you already possess an ICP filing, most of your customer traffic is domestic and your application is very much integrated with Chinese cloud infrastructure, either Tencent Cloud EdgeOne or Alibaba Cloud ESA are considered two of the most secure choices. Having a physical edge presence in China gives them a very obvious lateny advantage.

Of course the calculation will change dramatically if you do not have the ICP filing the originating server is based abroad or the service is commonly victim of CC or D DoS attacks. P

Hence, providers like YewSafe or CDN5 who are able to provide APAC route optimization together with integrated protection against DDOS attacks and other security threats help reduce both the operation complexity and the likelihood of unexpected security costs.

To pick the right CDN you have to test it by using a real test domain.

Put your real static assets, your business APIs and your WebSocket backend under a CDN then you perform your test for 2 to 3 days during which you include the 8:00 PM - 11:00 PM evening peak hour.

Be sure to collect real data about latencies, packet loss rate, P95/P99, the actual speed of the Origin and how long it takes the system to recover from a problem that has occurred

All this information will provide a much better indication of what kind of CDN would be best suited for your live production workloads rather than what is being claimed by a marketing representative or dashboard presentation of the provider.

Frequently Asked Questions

What is the main factor that separates a CDN ofMainland Chinafrom that of a no-ICP CDN?

A mainland China CDN relies on edge nodes that are physically located inside mainland China and hence is subject to a requirement for ICP filing. Typically these services offer a very low latency — often below 30 ms — and a great level of stability.

A no-ICP CDN normally uses nodes offshore such as in Hong Kong, etc., which do not require an ICP filing. However, latency does increase and may vary between 20–60 ms for a well-optimized APAC network, or even be as high as 80 ms up to well over 200 ms, for normal international internet paths.

Nearly-CDNs are especially suited for the situations where the origin is located abroad, it is a cross-border business, or a project that hasn't finished an ICP filing yet.

If my website mainly targets users inMainland China, is the free version of good enough?

No, it is definitely not the case.

At least for standard users of , there is no provision to access mainland China edge architecture other than what you get for Cloudflare's Mainland China Network.

Consequently, your users in mainland China may need to access offshore PoPs via international routes, and evening delays can exceed 200 ms on congested paths.

The saving you might expect on the CDN cost may be less than the turnover and user retention you would expect to lose to slower page loads and user abandonment.

What differentiates YewSafe from CDN5?

These two are the major CDN and no-ICP players that also provide DDoS protection, both of them can make use of highly optimized Hong Kong connectivity such as CN2 GIA etc.

YewSafe, more so, has emphasized on secure communications by features like TLS 1.3 + ECH and, in terms of false-positive rate, their system is at a very low level (0.02%).

CDN5 has stressed on CC (i.e., HTTP-based attack) mitigation performance: its system has recorded the highest CC mitigation rate of 99.95% and good evening-peak stability.

Therefore, the better CDN depends a lot on your actual working conditions such as traffic types. The most reliable method is by running trials on both and comparing them with a real-like working condition.

Why is evening-peak testing really necessary?

Because it can be a big problem in disguise - just one single average figure. It might look like a good CDN, but it can also become a very sluggish one precisely when most of the user traffic occurs, i.e., at night, i.e., between 8:00 p.m. and 11:00 p.m.

If a company chooses not to do evening-peak CDN testing on mainland China users and just does business as usual it misses out on one the major factors in the whole test plan.

If I have already obtained the ICP filing, would I still have any reasons to consider using a no-ICP CDN?

If all your users and infrastructures are located mainland China you will not need a no-ICP or APAC CDN.

A CDN having physical nodes inside mainland China will on average have lower latency and better domestic carrier routing.

On the other hand, no-ICP or APAC CDN would be a more attractive option if your origin is overseas, a large portion of your users is outside of China as well or if you require a single network that could balance mainland China accessibility with international ‍‌‍‍‌coverage.