Skip to content
Clearward

DNS Leak Test: How to Check Your VPN Actually Works

Published Jul 30, 2026✓ Fact-checked Aug 20, 2026

A DNS leak is when your device's DNS lookups — the requests that turn a domain name like example.com into an IP address — escape your VPN tunnel and go to your internet provider's servers instead. When that happens, your ISP can still see every site you visit even though the VPN appears to be connected. The good news is that you can test for it in about two minutes, and most leaks have a straightforward fix. Here is exactly how.

What a DNS leak is

Every time you load a website, your device first asks a DNS resolver for that site's address. When your VPN is working correctly, that request travels through the encrypted tunnel and is answered by the VPN's own DNS servers, so no one outside can see what you looked up. A DNS leak means the request took a shortcut outside the tunnel — usually straight to your ISP's resolver — quietly revealing your browsing even while the rest of your traffic is encrypted. It is one of the most common ways a VPN silently fails to do the one job you wanted it for.

How to test for a DNS leak

Run this quick check with your VPN connected:

  1. Connect your VPN and confirm it shows as connected to a server in another region.
  2. Open a testing site such as dnsleaktest.com, ipleak.net or browserleaks.com/dns in your browser.
  3. On dnsleaktest.com, run the “Extended test”, which queries multiple resolvers and is more thorough than the standard one.
  4. Note the IP address and the DNS servers the site reports, along with the country and network owner shown for each.

How to read the results

You are looking for consistency. The public IP address shown should belong to your VPN's server, not your home connection, and the DNS servers listed should belong to the VPN provider or a resolver in the server's country — not your ISP. If your real country, your ISP's name, or a resolver back home appears anywhere in the results, that is a leak. A clean result shows the VPN's location for both the IP and the DNS, with no trace of your actual provider.

What causes DNS leaks

A few things commonly cause leaks. The operating system may send DNS requests outside the tunnel because of how it handles multiple network interfaces. IPv6 traffic can escape a VPN that only routes IPv4, taking DNS with it. Some networks run a transparent DNS proxy that intercepts requests regardless of your settings. And split tunnelling, if misconfigured, can route some apps or lookups around the VPN by design. None of these mean your VPN is malicious — they usually mean a setting is off.

How to fix a DNS leak

Start with the VPN's own settings. Enable any option called “DNS leak protection” or “use VPN DNS only,” which forces every lookup through the tunnel. Turn on the kill switch so traffic is blocked if the connection drops. If IPv6 is the culprit, either use a VPN that fully handles IPv6 or disable IPv6 on your device. Reconnect, or switch to a different server, and run the test again. If a reputable, up-to-date VPN still leaks after all that, that is a serious mark against it — a provider that cannot reliably route its own DNS is not doing the basic job.

WebRTC and IPv6 leaks — the cousins

DNS leaks have two relatives worth testing at the same time. A WebRTC leak happens inside your browser: the WebRTC feature used for video calls can reveal your real local and public IP address to a site even with a VPN active. You can check it on browserleaks.com and mitigate it by disabling WebRTC or using a browser extension that blocks it. An IPv6 leak is the address-level version of the DNS problem — your real IPv6 address slips out because the VPN only covers IPv4. Testing sites report both, so a single visit tells you whether any of the three are exposing you.

Choosing a VPN that won't leak

Leak protection is a baseline, not a premium feature. A trustworthy VPN runs its own DNS, forces all lookups through the tunnel, handles or blocks IPv6, and includes a working kill switch — and the audited providers in our no-logs comparison all do. Whatever you use, test it yourself when you install it and again after any big update, because a leak you never checked for is the same as no VPN at all for the sites you cared about hiding.

How often should you re-test?

You do not need to check every day, but there are three moments that matter. Test right after you install or switch a VPN, so you start from a known-good baseline. Test again after any major app or operating-system update, because updates routinely reset network settings and can quietly reintroduce a leak. And test whenever you connect on a new kind of network — a corporate Wi-Fi running its own DNS proxy, or a mobile hotspot — since those can behave differently from your home connection. On phones this is especially worth doing, because DNS handling often differs between Wi-Fi and mobile data, so a VPN that passes on your home network can still leak on cellular. It takes under a minute each time. It helps to remember which resolvers your VPN normally shows, so that an unexpected new one stands out immediately, and if you run a custom DNS provider for ad-blocking or parental filtering, be aware it can interact with the VPN's DNS in ways that produce confusing results — when in doubt, let the VPN handle DNS and test again.

DNS leak testing, answered

How do I test my VPN for a DNS leak?
Connect your VPN, then open dnsleaktest.com, ipleak.net or browserleaks.com and run the extended test. Check that the IP address and DNS servers shown belong to the VPN's server and country, not your real ISP. If your home ISP or country appears anywhere, you have a leak.
What does a DNS leak reveal?
It reveals which websites you visit to your internet provider, because your DNS lookups are escaping the VPN tunnel and going to their servers. The rest of your traffic may still be encrypted, but the record of what you browsed is exposed, which defeats the main privacy reason for using a VPN.
How do I fix a DNS leak?
Enable the VPN's DNS leak protection and kill switch, disable IPv6 or use a VPN that fully supports it, and reconnect or switch servers before testing again. If a reputable, updated VPN still leaks, that is a strong reason to switch providers.
Is a WebRTC leak the same as a DNS leak?
No. A DNS leak exposes the sites you look up; a WebRTC leak happens in your browser and can expose your real IP address to a website even with a VPN on. Both are worth testing together, and testing sites report them side by side.

The through-line to everything here: a VPN shifts trust to its provider. See which no-logs claims are actually audited, or read the honest threat model.