DNS Leak Test

A DNS leak happens when the DNS queries your browser makes do not go through your VPN, silently exposing which sites you visit to your internet provider. This test checks whether your connection is leaking DNS while a VPN is active.

Do You Have a DNS Leak?

A DNS leak is a privacy flaw that occurs when your device's DNS queries are routed to your internet service provider (ISP) instead of the DNS servers your VPN is supposed to use. When you are on a VPN, every website domain you visit should be resolved through the VPN's secure tunnel. If DNS requests leak out the side door to your ISP, the ISP can see every domain you visit โ€” completely defeating the privacy you are paying the VPN for.

Leaks happen for a few common reasons: your operating system's DNS settings are ignored by certain applications, the VPN does not cover the DNS resolver used by your browser, IPv6 is enabled without VPN support (so IPv6 DNS queries bypass the tunnel), or your router forces its own DNS regardless of your device. Our test blends several client-side checks to flag the most common leak patterns.

The test runs entirely in your browser and only queries public IP and DNS endpoints โ€” nothing is stored on our servers.

Connect through your VPN (if you use one), then click test to check for a DNS leak.

What Is a DNS Leak?

DNS (the Domain Name System) is the phonebook of the internet. When you type a website address, your device asks a DNS server to translate that name into a numeric IP address your computer can connect to. By default, the DNS server your device uses โ€” and therefore the record of everywhere you browse โ€” is often the one run by your internet service provider.

When a VPN is working correctly, your DNS queries travel through the encrypted VPN tunnel to the VPN provider's DNS servers. A DNS leak is when some of those queries bypass the tunnel and reach a DNS server outside it (typically your ISP's). The information โ€” which domains you visit โ€” is then visible to your provider even though your IP address is hidden by the VPN. This is why privacy experts recommend testing for DNS leaks as well as WebRTC leaks.

How to Run the Test

DNS Leak โ€” Frequently Asked Questions

How do I fix a DNS leak?

In your VPN app, turn on the settings commonly labelled "kill switch", "block leaks", or "IPv6 leak protection". Set a DNS server explicitly (for example 1.1.1.1 or 8.8.8.8) on your device or router, disable IPv6 if your VPN does not support it, and prefer VPN apps that route all DNS through the tunnel. After changing settings, run this test again.

Is my VPN hiding my DNS?

If your VPN is working properly, the DNS queries your browser makes should be resolved by the VPN provider's servers, not your ISP's. Run this test while connected to your VPN: if the result shows no leak and the source IP is flagged as a VPN / datacenter address with consistent DNS answers, your DNS is likely travelling inside the tunnel.

What is an IPv6 DNS leak?

Many networks have IPv6 enabled, but not every VPN supports it. If your device has a real IPv6 address exposed while the VPN only tunnels IPv4, then IPv6-based DNS queries (and IPv6 traffic) can bypass the VPN entirely and be seen by your ISP. This test checks whether an IPv6 address is visible on top of your VPN connection.

Does a DNS leak mean I'm hacked?

No. A DNS leak is a privacy weakness, not a sign of compromise. It means your ISP could see which domains you visit when you think you are anonymous via a VPN. It does not mean an attacker has broken into your device.

Does this test store anything about me?

No. The test runs in your browser and queries public IP and DNS endpoints for that single request. No results, IP addresses or browsing history are stored or logged by us.