DNS Leak Test
Real-time DNS leak detection powered by Cloudflare's public resolver. If your DNS queries are leaking outside your VPN tunnel, your ISP can still see every website you visit.
Your DNS Resolvers
What Is a DNS Leak?
When you visit a website, your device first asks a DNS resolver to translate the domain name (e.g., example.com) into an IP address. Without a VPN, these DNS queries go to your ISP's DNS servers — giving your ISP a complete log of every website you visit, even if the website itself uses HTTPS.
A properly configured VPN routes all DNS queries through the encrypted tunnel to the VPN provider's own DNS servers. A DNS leak happens when these queries accidentally leak around the tunnel and go to your ISP anyway. The result: even though you're connected to a VPN, your ISP still sees every website you visit.
How to Read These Results
If the resolver IPs above belong to your VPN provider (or to Cloudflare, Google, or another public DoH provider you've configured), your DNS is properly protected. If you see your ISP's resolvers (Comcast, Verizon, AT&T, etc.) while connected to a VPN, you have a DNS leak.
For a more comprehensive test, also run this check at dnsleaktest.com with the "Extended Test" option.
How to Fix a DNS Leak
- Ensure your VPN's DNS leak protection setting is enabled (most premium VPNs have this on by default)
- Switch to your VPN's WireGuard or proprietary protocol (Lightway, NordLynx) — these handle DNS more reliably
- On Windows, disable Smart Multi-Homed Name Resolution via Group Policy
- If problems persist, switch VPN providers — see our top-rated VPNs for 2026
For a deeper technical explanation, read our guide on how VPN encryption and tunneling work.