← Home

DNS Leak Test

Your browser runs encrypted DNS queries against major public resolvers and checks whether any answer comes back through your own ISP's network - a sign your DNS traffic isn't protected by an encrypted tunnel.

Frequently Asked Questions

What is a DNS leak?
A DNS leak happens when your device sends DNS lookups to your ISP's resolver instead of your VPN's encrypted tunnel. Even with a VPN active, anyone watching those queries can see which sites you visit - defeating much of the privacy a VPN is meant to provide.
How does this test work?
Your browser sends encrypted DNS-over-HTTPS (DoH) queries directly to several major public resolvers (Google, Cloudflare, Quad9, DNS.SB) and records the egress network that answers each one. Those networks are then compared against your own public IP's ISP and ASN. If a resolver resolves through your own ISP's network, that's a strong sign your DNS isn't being tunnelled.
Why does it matter if my ISP sees my DNS?
Your DNS history is a complete log of every domain you visit. ISPs can use it for traffic shaping, ad targeting, or hand it to third parties. Keeping DNS inside an encrypted VPN tunnel - or using an independent encrypted resolver - keeps that browsing history private.
How do I fix a DNS leak?
Use a VPN that routes DNS through its own servers and enables DNS leak protection, turn on encrypted DNS (DoH/DoT) in your browser or OS, and disable IPv6 if your VPN doesn't tunnel it. Re-run this test afterwards to confirm the leak is gone.
What can't this test detect?
Without a dedicated DNS logging server, this test can't see the exact resolver your operating system is configured to use. It checks whether reachable public resolvers route through your own ISP's network - a practical privacy signal - rather than fingerprinting your full DNS configuration.

Related Tools