What is a DNS leak—and how should you check?
DNS helps devices find the network address associated with a domain name. A DNS leak usually means those queries are going somewhere outside the DNS path you expected while using a VPN. The exact meaning depends on your VPN, operating system, and DNS configuration.
DNS looks up names for network connections
When an app needs to reach a domain, a DNS resolver can look up information such as the address associated with that name. Your device may use a resolver supplied by a network, configured in its operating system, or selected by an app or VPN.
Resolvers may receive DNS queries. The exact data visible to any party depends on the resolver, transport protections, network path, caching, and configuration.
Check the VPN’s intended DNS behavior
Read the VPN provider’s DNS documentation
Find out which resolvers or DNS protections the app is expected to use and whether custom DNS or split tunneling changes that behavior.
Connect to the VPN and confirm its status
Use the provider’s supported app or configuration and verify the VPN is connected before checking DNS.
Use a reputable DNS test carefully
If you use an online test, review who operates it and its privacy terms. Avoid entering sensitive domain names during the check.
Compare the result with documented expectations
Check whether the resolver information is consistent with the provider’s stated design. A test result is only a snapshot and may not reveal every app or network path.
Repeat after relevant changes
Network changes, app updates, custom DNS, split tunneling, or operating system settings can affect DNS behavior. Recheck after changes if DNS routing matters to you.
Start with provider guidance
- Confirm the VPN is connected and the app is up to date.
- Review custom DNS, private relay, split-tunnel, or network profile settings that may affect queries.
- Check whether the test recognizes the provider’s resolver infrastructure.
- Contact the VPN provider with the test date, device, operating system, and app version.
- Do not install unfamiliar DNS tools or profiles to “fix” the result.
A test cannot prove complete privacy
An online check can show resolver information observed from that test session. It does not prove that every application uses the same route, that no other data is collected, or that a VPN is anonymous.
DNS is only one part of a network connection. Review the provider’s privacy policy, technical documentation, and app settings.
Assess no-logs claims →DNS and VPN FAQ
Does a VPN always control my DNS queries?
Not necessarily. Behavior depends on the provider app, operating system, configuration, split tunneling, and other DNS features. Check the provider’s documentation for your setup.
Does encrypted DNS mean there is no leak?
Encrypted DNS protects queries in transit to the chosen resolver, but does not by itself determine which resolver is used or who operates it. Consider the full routing and privacy setup.
Can a DNS leak expose every website I visit?
DNS information can reveal domain lookups to the resolver handling those queries, but it does not necessarily show every page, app action, or encrypted content. Visibility depends on the protocol and setup.
What is the standard definition of a resolver?
The IETF describes a resolver as a program that obtains information from name servers in response to client requests. See RFC 7719 DNS terminology.
Review your VPN’s whole privacy setup
Understand VPN basics, read provider privacy claims carefully, and compare options for your devices.