What a DNS leak actually is

A VPN can hide web traffic while DNS lookups still travel through a resolver outside the tunnel. That matters because DNS requests reveal which domains you ask to visit even when the page itself is encrypted.

Start with a resolver test

Run the DNS Leak Test while your VPN is connected. Note the resolver address or network and compare it with what your VPN provider says it should use. A different resolver is not automatically a leak—many people intentionally use Cloudflare, Google, Quad9 or another trusted resolver—but an ISP resolver can be a warning sign.

Check the other leak paths too

DNS is only one privacy path. Run the WebRTC Leak Test, IPv6 Checker and VPN & IP Check. A privacy setup is strongest when the public IP, IPv6 route, WebRTC candidates and DNS resolver all match the network path you intended.

Retest after changes

If you change VPN servers, secure-DNS settings or Wi-Fi networks, run the checks again. Privacy configuration can differ by browser, device and network.