DNS Leak Test
See which DNS resolvers answer for your connection - and whether your VPN is carrying them
A DNS leak cannot be detected inside your browser. This test works the other way round: we hand your browser a one-off hostname we are authoritative for, and record which resolver comes asking us for it. That resolver is the one your connection really uses.
Testing your DNS…
Looking up a one-off hostname and watching which resolver comes asking…
Resolvers that answered for you
Your connection
What this test can and cannot see
- If your browser uses encrypted DNS (DoH), we see that provider's resolver rather than the one your operating system would use. That is a correct result for this browser, but it does not prove the rest of your device is safe.
- Large resolvers query from many addresses, so several may appear for one test. All of them are listed.
- We only ever see the resolvers, never your DNS queries. The only name looked up here is the one-off hostname this page generated.
- Resolver addresses are held in memory for a few minutes and never written to our logs.
A VPN with its own encrypted DNS stops this leak entirely.
Get a leak-proof VPN →Ad - we may earn a commission.
What is a DNS leak?
Every site you visit starts with a DNS lookup. When a VPN is connected, those lookups should travel inside the tunnel and be answered by the VPN's own resolver. A DNS leak is when they escape it and go to your access provider's resolver instead - your traffic is encrypted, but a list of every domain you visit still reaches your ISP.
How do I fix a DNS leak?
Use a VPN that runs its own resolvers and enables DNS leak protection by default, keep that protection switched on, and avoid setting a third-party resolver manually while the tunnel is up. On desktop, closing and reopening the VPN client after changing networks clears most leaks.