GhostTouchTest.com

What Is a DNS Leak?

Last updated: May 2026 · 5 min read

A DNS leak is when your internet requests bypass your VPN's encrypted tunnel and go directly to your ISP's servers — exposing every website you visit, even while your VPN appears to be on. It's one of the most common reasons VPNs fail to protect privacy in practice.

First: What Does DNS Actually Do?

Every time you type a website address — like "google.com" — your device has to translate that name into a numerical IP address before it can connect. That translation is handled by a DNS server.

By default, your internet provider (ISP) runs those DNS servers. That means your ISP sees every domain you look up — every website, every app, every service — even if the actual page content is encrypted.

💡 Think of it like sending a letter in a sealed envelope. The content is private — but the address on the outside is visible to every postal worker who handles it. DNS is the address. A DNS leak means your ISP can read it.

What Is a DNS Leak, Exactly?

When you use a VPN, your DNS requests should go through the VPN's own servers — not your ISP's. The VPN creates an encrypted tunnel that hides both your traffic and your DNS lookups.

A DNS leak happens when that tunnel breaks down. Your device keeps sending DNS requests to your ISP's servers on the side, outside the VPN tunnel. The VPN encrypts your traffic, but your ISP still sees which websites you're looking up. The privacy protection you thought you had isn't actually there.

Want to know if your DNS is leaking right now? Our test checks in seconds — no signup, no install.

Run the DNS Leak Test →

Why Does a DNS Leak Happen?

There are a few common reasons your VPN might be leaking DNS requests without you knowing:

⚙️
Misconfigured VPN VPN not set up to route DNS through its own servers
🪟
Windows behavior Windows 8+ sends DNS to multiple servers at once by design
🌐
IPv6 not supported Many VPNs only tunnel IPv4 — IPv6 traffic leaks outside
📡
ISP forced routing Some ISPs intercept DNS requests regardless of your settings

Free VPNs are especially prone to DNS leaks — many don't run their own DNS servers at all, which means your requests always go to a third party outside the tunnel.

Why Does It Actually Matter?

For most people, a DNS leak means your ISP has a complete log of every site you visited — even if you're using a VPN specifically to prevent that. If you're in a country with strict internet monitoring, or if you're using a VPN for work security, a DNS leak can have serious consequences.

Even for everyday users, it's worth knowing about:

How to Check If Your DNS Is Leaking

The fastest way is a DNS leak test — it checks whether your DNS requests are going through your VPN or leaking to your ISP. The test takes about 10 seconds and doesn't require any software.

What you're looking for in the results: if you see your VPN provider's DNS servers, you're protected. If you see your ISP's servers, you have a leak.

Our DNS leak test shows exactly which servers are handling your DNS requests — and whether your VPN is actually working.

Test for DNS Leaks →

How to Fix a DNS Leak

The short version: switch to a VPN with built-in DNS leak protection, or manually set your DNS to a private provider like Cloudflare (1.1.1.1) or Google (8.8.8.8) and disable IPv6 if your VPN doesn't support it. A kill switch adds an extra layer of protection if the VPN connection ever drops unexpectedly.

See the full fix walkthrough — including which setting to check first and how to confirm the leak is actually gone.

Read the Full Fix Guide →

Frequently Asked Questions

What is a DNS leak?

A DNS leak is when your DNS requests bypass your VPN and go to your ISP's servers instead, exposing the websites you visit even while your VPN is active.

Is a DNS leak dangerous?

For anyone using a VPN for privacy, yes. A DNS leak means your ISP can see your full browsing history despite the VPN being on. For casual users, it's less critical but still a privacy concern.

How do I know if I have a DNS leak?

Run a DNS leak test. If the results show your ISP's DNS servers instead of your VPN's servers, your DNS is leaking.

What causes a DNS leak?

Common causes include a misconfigured VPN, Windows sending DNS queries outside the tunnel, IPv6 traffic not being routed through the VPN, or using a free VPN with no dedicated DNS servers.

Can I fix a DNS leak?

Yes. Switch to a VPN with built-in DNS leak protection, set a private DNS like Cloudflare (1.1.1.1), or disable IPv6 if your VPN doesn't support it. Test again after any change to confirm the fix worked.