DNS Leak Test
Run a DNS leak test to see which recursive DNS resolvers are visible when your browser makes DNS requests. This can help you check whether DNS traffic is following the path you expect, especially when using a VPN.
Check visible DNS resolvers
Most tests finish within a few seconds.
What is a DNS leak?
DNS translates domain names into IP addresses. Those requests are commonly handled by resolvers run by an ISP, VPN provider, public DNS provider, or organization.
When you use a VPN, you may expect DNS requests to follow the VPN's intended DNS path. A DNS leak can occur when requests unexpectedly travel outside that path and reach another resolver. DNS requests can reveal the domain names a connection attempts to resolve, although they do not necessarily reveal the exact page or content viewed.
An unfamiliar resolver does not automatically prove a leak. Forwarding, resolver pools, enterprise DNS, public resolvers, and network design can all produce legitimate differences.
How this DNS Leak Test works
- Your browser creates a temporary random identifier.
- It requests temporary test hostnames that include that identifier.
- Your DNS infrastructure resolves those names.
- Our authoritative DNS endpoint sees the recursive resolver or forwarder that reaches it.
- The page displays that address and available network information.
The displayed address is the recursive resolver or forwarder visible to our authoritative DNS server. It is not necessarily the exact DNS server configured directly on your device.
How to read your results
One DNS resolver observed
One address can simply mean the test requests reached one visible resolver path. Compare its network with the DNS service you expect to be used on this connection.
Multiple DNS resolvers observed
Multiple addresses can result from resolver pools, IPv4 and IPv6 infrastructure, forwarding, load balancing, VPN configuration, or enterprise and network policy.
Matching network
When your connection and observed resolver show the same network, that is useful context about the visible DNS path. It does not by itself mean the connection is safe or that no leak exists.
VPN users
Compare the observed resolver network with the DNS service or path your VPN says it uses. An ISP or other unexpected resolver may deserve investigation, but provider, ASN, or country differences alone do not establish a DNS leak.
Unknown network or country
IP intelligence can be incomplete or approximate. An unknown value does not change the observed resolver address or make the test unsuccessful.
No result
Browser or network restrictions, unusual DNS behavior, and temporary network conditions can prevent an observation. No result does not mean there is no DNS leak.
Common causes of unexpected DNS paths
- VPN DNS configuration: a VPN may not use or enforce its intended DNS service.
- Device or router settings: configured DNS, local forwarding, or fallback resolvers can affect the path.
- IPv6 and split tunneling: a separate route may follow different VPN or DNS behavior.
- Enterprise policy: managed networks can forward DNS through organization-operated infrastructure.
- Browser and network behavior: resolver selection, caches, and network policy can change which address is visible.
How to investigate a possible DNS leak
- Run the test with your VPN disconnected and note the resolver network.
- Connect the VPN and run it again.
- Compare the observed resolver and network context with the DNS path you expect.
- Review the VPN app's DNS or leak-protection settings.
- Check device and router DNS settings if an unexpected resolver remains visible.
- Review IPv6 behavior and split-tunneling settings where they apply.
- Reconnect or restart the VPN after changing a relevant setting, then retest.
- Consult your VPN provider's DNS documentation if the result remains unexpected.
Do not make broad network changes, such as disabling IPv6, without understanding how they affect your connection and the VPN's documented behavior.
DNS Leak vs WebRTC Leak vs IPv6 Leak
| Test | What it examines | Related tool |
|---|---|---|
| DNS Leak | An unexpected DNS resolver path. | This test |
| WebRTC Leak | Browser WebRTC behavior that may expose IP or network information. | WebRTC Leak Test |
| IPv6 Leak | IPv6 traffic following a path outside the expected VPN route. | IPv6 Leak Test |
For broader connection context, use the VPN / Proxy / Tor Checker, Is My VPN Working?, Privacy Check, or DNS Lookup when it fits the question you are investigating.
DNS encryption clarification
This test does not determine whether the connection between your device or browser and a resolver uses traditional DNS, DNS over HTTPS (DoH), or DNS over TLS (DoT). Our authoritative endpoint observes the resolver or forwarder that ultimately reaches it. Encrypted DNS and DNS leaks are related but different questions.
Privacy and methodology
Every run uses a fresh random anonymous token to correlate temporary test DNS requests. Resolver observations are held in memory, expire within five minutes, and do not create a durable DNS resolver history. Token and resolver values are not included in analytics events.
Available resolver network information is enriched server-side using this site's existing IP intelligence capability. That can process a resolver address through the site's IP-data provider, but it does not add the token to that lookup.
DNS Leak Test FAQ
What is a DNS leak?
A DNS leak is an unexpected DNS resolver path, often considered in relation to a VPN's intended DNS handling.
How do I know if my DNS is leaking?
Compare the observed resolver and network context with the DNS path you expect. This result is evidence, not an automatic verdict.
Does seeing my ISP's DNS mean I have a DNS leak?
Not necessarily. It may be expected on a normal connection, or it may reflect forwarding, policy, or VPN behavior that needs context.
Should my DNS resolver match my VPN provider?
Compare it with the DNS service your VPN says it uses. A literal provider-name match is not required to make a conclusion.
Why does the test show multiple DNS resolvers?
Resolver pools, forwarding, IPv4 and IPv6 paths, load balancing, and network policy can all show more than one visible address.
Can IPv6 cause or contribute to DNS leaks?
IPv6 can follow a different network or VPN path. Review it in context with the IPv6 Leak Test.
Does DoH or DoT prevent DNS leaks?
Encryption protects a DNS transport segment; it does not by itself prove requests follow the DNS path you expect.
Why did the DNS Leak Test return no result?
Browser restrictions, DNS behavior, network policy, or temporary conditions can prevent an observation. Retry after checking your connection.