First: What Does DNS Actually Do?
Every time you type a website address — like "google.com" — your device has to translate that name into a numerical IP address before it can connect. That translation is handled by a DNS server.
By default, your internet provider (ISP) runs those DNS servers. That means your ISP sees every domain you look up — every website, every app, every service — even if the actual page content is encrypted.
💡 Think of it like sending a letter in a sealed envelope. The content is private — but the address on the outside is visible to every postal worker who handles it. DNS is the address. A DNS leak means your ISP can read it.
What Is a DNS Leak, Exactly?
When you use a VPN, your DNS requests should go through the VPN's own servers — not your ISP's. The VPN creates an encrypted tunnel that hides both your traffic and your DNS lookups.
A DNS leak happens when that tunnel breaks down. Your device keeps sending DNS requests to your ISP's servers on the side, outside the VPN tunnel. The VPN encrypts your traffic, but your ISP still sees which websites you're looking up. The privacy protection you thought you had isn't actually there.
Want to know if your DNS is leaking right now? Our test checks in seconds — no signup, no install.
Run the DNS Leak Test →Why Does a DNS Leak Happen?
There are a few common reasons your VPN might be leaking DNS requests without you knowing:
Free VPNs are especially prone to DNS leaks — many don't run their own DNS servers at all, which means your requests always go to a third party outside the tunnel.
Why Does It Actually Matter?
For most people, a DNS leak means your ISP has a complete log of every site you visited — even if you're using a VPN specifically to prevent that. If you're in a country with strict internet monitoring, or if you're using a VPN for work security, a DNS leak can have serious consequences.
Even for everyday users, it's worth knowing about:
- Your ISP can sell or share your browsing history with advertisers
- Geo-restricted content won't work if the DNS request reveals your real location
- Anyone monitoring your network can profile your online habits
- A VPN that leaks DNS is essentially not doing its primary job
How to Check If Your DNS Is Leaking
The fastest way is a DNS leak test — it checks whether your DNS requests are going through your VPN or leaking to your ISP. The test takes about 10 seconds and doesn't require any software.
What you're looking for in the results: if you see your VPN provider's DNS servers, you're protected. If you see your ISP's servers, you have a leak.
Our DNS leak test shows exactly which servers are handling your DNS requests — and whether your VPN is actually working.
Test for DNS Leaks →How to Fix a DNS Leak
The short version: switch to a VPN with built-in DNS leak protection, or manually set your DNS to a private provider like Cloudflare (1.1.1.1) or Google (8.8.8.8) and disable IPv6 if your VPN doesn't support it. A kill switch adds an extra layer of protection if the VPN connection ever drops unexpectedly.
See the full fix walkthrough — including which setting to check first and how to confirm the leak is actually gone.
Read the Full Fix Guide →Frequently Asked Questions
What is a DNS leak?
A DNS leak is when your DNS requests bypass your VPN and go to your ISP's servers instead, exposing the websites you visit even while your VPN is active.
Is a DNS leak dangerous?
For anyone using a VPN for privacy, yes. A DNS leak means your ISP can see your full browsing history despite the VPN being on. For casual users, it's less critical but still a privacy concern.
How do I know if I have a DNS leak?
Run a DNS leak test. If the results show your ISP's DNS servers instead of your VPN's servers, your DNS is leaking.
What causes a DNS leak?
Common causes include a misconfigured VPN, Windows sending DNS queries outside the tunnel, IPv6 traffic not being routed through the VPN, or using a free VPN with no dedicated DNS servers.
Can I fix a DNS leak?
Yes. Switch to a VPN with built-in DNS leak protection, set a private DNS like Cloudflare (1.1.1.1), or disable IPv6 if your VPN doesn't support it. Test again after any change to confirm the fix worked.