PublicIPChecker

Guide

What is a DNS leak?

5 min read · Updated 2026-09-28

A DNS leak sends your domain lookups to your ISP's resolvers instead of the VPN's — exposing what you visit even when the traffic is tunneled. How leaks happen, how to check for one, and how to kill it.

The leak in one paragraph

When you use a VPN, your traffic travels through the tunnel — but your name lookups do not have to. A DNS leak is when DNS queries (the requests that turn example.com into an address) go to a resolver outside the tunnel — usually your ISP's — instead of the VPN provider's. The traffic is encrypted; the question "which site did I just try to open" is not.

Why it happens

  • OS-level DNS settings — the operating system keeps using the DNS servers from the network profile instead of the tunnel's.
  • Split tunneling — some apps or protocols are routed around the VPN by design.
  • IPv6 on a v4-only tunnel — the v6 path has no tunnel, and the lookups for v6 destinations go out in the clear.
  • Apps with their own DNS — some media players and games hardcode their own resolvers.

What actually gets exposed

A DNS leak does not reveal page contents — HTTPS encrypts what you read. It reveals which domains you request, and when: the sequence of service names is a surprisingly detailed portrait of a session (banking at 9:02, a pharmacy at 9:07, a streaming app at 21:14). The exposed party is normally your ISP, which correlates it with a subscriber account. That combination — account identity plus a domain timeline — is what makes a DNS leak worth caring about.

Three different leaks, one family: a DNS leak exposes your queries; a WebRTC leak (what is a WebRTC leak) exposes your real IP; an IP leak means the tunnel dropped entirely. A complete check covers all three — see is my VPN working.

How to check for it

  1. Connect your VPN.
  2. Visit a DNS-leak test page (several exist; they ask your browser which resolver the lookup came through).
  3. If the result names your ISP's resolver — or your real country while the VPN is in another — you have a leak. If it names the VPN provider's resolver (or an encrypted resolver the provider runs), you are clean.
  4. Cross-check the checker: the country shown must match the VPN server's country, not yours.

How to fix it

  • Use a VPN client that manages DNS — reputable clients set the tunnel's resolver system-wide and block direct resolver access; this alone fixes most leaks.
  • Enable encrypted DNS (DoH/DoT) through the tunnel — even if a query escapes the tunnel, an encrypted one to the VPN's resolver is not readable by the ISP.
  • Tunnel or disable IPv6 when the VPN only handles IPv4.
  • Kill switch on — if the tunnel drops, the connection should drop with it, not fall back to the open network.
  • Per-app VPN mode (iOS/Android) for apps that insist on their own paths.

Frequently asked questions

Does a DNS leak reveal what I'm reading?

No — not the content. It reveals the domain names you request and their timing, which is a rough but real picture of your activity.

Are free VPNs more likely to leak DNS?

Often, yes. Free clients frequently skip the system-DNS management that paid ones do. A leak check takes a minute — run it.

Does enabling DoH in my browser fix a leak?

Usually, yes — the queries go encrypted to the chosen resolver. Make sure the DoH endpoint is the one you trust (your VPN's, or a public one like 1.1.1.1), and that it is routed through the tunnel.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.