What a DNS leak is
When you use a VPN, your DNS lookups are supposed to travel through the VPN too. A DNS leak happens when they slip out to your provider's resolver instead — so even though your traffic is encrypted, your ISP still sees a list of every domain you visit.
Once wired up, the test will work by making your browser resolve a series of unique hostnames, then checking which resolvers asked our servers about them — if a resolver belonging to your ISP shows up while you're on a VPN, that's a leak. For now, the button above returns a sample result in the same format so you can see what it'll look like.
Frequently asked questions
How do I fix a DNS leak?
Do I have a leak if I'm not using a VPN?
Coming soon. A real test needs independent resolver-facing endpoints on separate hostnames — this page is the shell, and the result below is a demo; the measurement runs server-side once wired up. FAQ ships as FAQPage schema; page carries SoftwareApplication + BreadcrumbList.