Decide what you expect
Check your VPN’s documentation for its intended DNS provider. Also note whether browser secure DNS is enabled or whether your workplace sets a resolver policy. These layers can affect which service answers a lookup. Avoid changing several settings before taking an initial result.
Run the resolver check
Connect to the intended VPN and open the DNS Leak Test. It requests public connection information and contacts third-party resolver probes. A successful response may identify a resolver or client-subnet signal. Not all networks, browsers and blockers allow those probes.
Treat unavailable results as unknown
A failed probe cannot establish that DNS is private or exposed. Blocking, outages or a changed service response can prevent a result. Do not interpret “not reported” as a complete audit of all DNS traffic. The page explains which third-party endpoints it contacts.
Interpret differences in context
Public DNS providers, ISP resolvers and VPN-operated resolvers can use addresses distinct from your web exit IP. Compare the provider with your intended configuration. If it is unexpected, review VPN DNS protection and browser secure-DNS settings, then repeat. Use another trusted resolver test to cross-check.
Check other paths separately
A VPN/IP Check shows what this website sees. The WebRTC check examines another browser mechanism and contacts a STUN service. Neither replaces DNS inspection. No single webpage proves that every app on the device follows the same tunnel or privacy settings.