DNS Leak Test

See which DNS resolvers answer for your connection - and whether your VPN is carrying them

A DNS leak cannot be detected inside your browser. This test works the other way round: we hand your browser a one-off hostname we are authoritative for, and record which resolver comes asking us for it. That resolver is the one your connection really uses.

🔍

Ready to test your DNS

Nothing is looked up until you start the test. It takes a few seconds.

Resolvers that answered for you

Your connection

IP address 216.73.216.56
Network Amazon.com, Inc. (AS16509)
Country United States
VPN / Tor None detected

What this test can and cannot see

  • If your browser uses encrypted DNS (DoH), we see that provider's resolver rather than the one your operating system would use. That is a correct result for this browser, but it does not prove the rest of your device is safe.
  • Large resolvers query from many addresses, so several may appear for one test. All of them are listed.
  • We only ever see the resolvers, never your DNS queries. The only name looked up here is the one-off hostname this page generated.
  • Resolver addresses are held in memory for a few minutes and never written to our logs.
🛡️

A VPN with its own encrypted DNS stops this leak entirely.

Get a leak-proof VPN →

Ad - we may earn a commission.

What is a DNS leak?

Every site you visit starts with a DNS lookup. When a VPN is connected, those lookups should travel inside the tunnel and be answered by the VPN's own resolver. A DNS leak is when they escape it and go to your access provider's resolver instead - your traffic is encrypted, but a list of every domain you visit still reaches your ISP.

How do I fix a DNS leak?

Use a VPN that runs its own resolvers and enables DNS leak protection by default, keep that protection switched on, and avoid setting a third-party resolver manually while the tunnel is up. On desktop, closing and reopening the VPN client after changing networks clears most leaks.

4.7 out of 5 · 41 ratings
Rate this page

DNS Leak Test FAQ

How the test works and how to read the result

What is a DNS leak?

Opening any website begins with a DNS lookup that turns a name into an address. If those lookups leave your device outside the VPN tunnel, your internet provider still sees every domain you visit even though the traffic itself is encrypted. The tunnel is working and your browsing is still being logged somewhere you did not choose.

How does this test detect one?

A leak cannot be detected inside the browser, so we run a nameserver of our own. The page asks for a hostname that has never been looked up before, your resolver has to come to us to resolve it, and we record the address the query actually arrives from. That address is the resolver you are really using, whatever your settings say.

Why does the test show more than one resolver?

That is normal. Providers and public services run pools of resolvers and forward queries between them, so a single lookup often reaches us from several addresses. What matters is not how many appear but which networks they sit on - all on your VPN's network is the good outcome, one on a third network is the one to look at.

Why is my resolver in a different country to my VPN?

Usually because the big public resolvers are anycast: the same address is answered from whichever data centre is nearest, so the country we see is where the query surfaced, not where you are. A country mismatch alone is not flagged as a leak for exactly this reason. A resolver on a network that is neither your VPN's nor a known public service is the case that matters.

Do you store the resolver addresses?

Only in memory, for five minutes, tied to the one-off hostname your test used. They are never written to our request logs, never shown to another visitor, and discarded when the token expires. We treat them as personal data because on some networks the resolver is the visitor.