DNS Leak Test Guide: What a DNS Leak Is and How to Check
A DNS leak happens when DNS queries take a path you did not intend—for example, going to your ISP resolver while you expect a VPN-provided resolver. A proper test compares your visible public IP, active DNS resolvers and VPN configuration.
What DNS does
The Domain Name System translates names such as example.com into IP addresses that devices can connect to. A resolver handles those queries on your behalf. Depending on your network, that resolver may be operated by your ISP, router, workplace, VPN provider or a public DNS service.
What people mean by a DNS leak
When a VPN is expected to carry DNS queries through its tunnel, a leak means some requests are instead reaching a resolver outside that intended path. This can reveal DNS activity to another network operator even though the visible web traffic exits through the VPN.
A DNS result that differs from the VPN company’s name is not automatically a leak. VPN providers can use third-party resolvers, anycast networks or cloud infrastructure. The important question is whether the observed resolver path matches the VPN’s documented design.
How to check for a DNS leak
- Before connecting to the VPN, note your public IP and normal DNS environment.
- Connect to the VPN and confirm that your public IP changes as expected.
- Use a reputable DNS leak test that generates unique DNS queries and reports the resolvers that receive them.
- Compare the reported resolver organization and country with your VPN provider’s expected DNS setup.
- Repeat the test after reconnecting, and test both IPv4 and IPv6 if your VPN claims to protect both.
IPWander can help with step two by showing the public address and its network context, but a true DNS leak test needs controlled DNS queries and therefore is a different tool.
Common causes
- Operating-system DNS settings that bypass the tunnel.
- Split tunneling rules that intentionally send some traffic outside the VPN.
- IPv6 traffic not handled by an IPv4-only tunnel.
- Browser or application features using encrypted DNS independently of the VPN.
- Network changes during VPN reconnects.
- Misconfigured enterprise VPN profiles.
DNS leak protection
Use a VPN client that explicitly handles DNS and IPv6, keep the client updated, and understand whether split tunneling is enabled. If the VPN offers a kill switch, test what happens during reconnects rather than assuming the feature works in every network condition.
Encrypted DNS such as DNS over HTTPS or DNS over TLS can protect DNS traffic from local observation, but it does not automatically mean the DNS path matches your VPN. Privacy depends on the whole route and the resolver you choose.
DNS leaks vs IP leaks
An IP leak and a DNS leak are related but different. An IP leak exposes traffic through an unintended public address. A DNS leak exposes name-resolution queries through an unintended resolver. A complete privacy test checks both.
For public-address context, see how VPN and proxy IP detection works.
Look up an IP address
Check approximate location, network ownership and privacy/risk signals.