What Is a DNS Leak?
Last updated: October 2026
Disclosure: LeakCheck currently has
no affiliate relationships and earns nothing from any link on this page. Provider links below are non-affiliate placeholders (marked
#AFFILIATE-PLACEHOLDER-* in our code) until we join programs — at which point every affected page gets a clear, conspicuous disclosure.
Full disclosure.
A DNS leak happens when your domain-name lookups — the requests your device makes to translate a website name like example.com into an IP address — travel to your ISP's DNS servers instead of through your VPN tunnel. Your traffic is encrypted, your IP may be hidden, but your ISP can still see every website you visit — which defeats much of the point of using a VPN. One analysis of 10,000 real leak tests found DNS leaks were the most common leak of all (67%), ahead of WebRTC (42%) and IPv6 (23%) (ExamineIP; Medium, April 2026).
Related: what is a WebRTC leak? · how to check if your VPN is working
What DNS does, in 30 seconds
When you type a web address, your device asks a DNS resolver: "what IP is this domain?" Normally that request goes to your ISP's resolver, which logs it. A properly configured VPN pushes its own DNS resolver through the tunnel, so those requests are encrypted and handled by the VPN provider instead. A leak means the request escaped the tunnel and went to the ISP (or another outside resolver) anyway (MakeUseOf; myvpnhub).
What causes a DNS leak?
- DNS leak protection is switched off. The most common case: the VPN's anti-leak setting exists but is disabled — sometimes by default on older installs (dev.to, 2026).
- Your OS answers first. Windows' Smart Multi-Homed Name Resolution (SMHNR) can send DNS queries to every available resolver at once, including your ISP's, even while the tunnel is up (dev.to, 2026).
- Your browser does its own DNS. Chrome and Firefox's Secure DNS / DNS-over-HTTPS (DoH) settings can route lookups to a third-party resolver outside the tunnel (dev.to; cyberpanel.net).
- IPv6 traffic escapes the tunnel. If your VPN doesn't handle IPv6, those requests bypass it entirely (cyberpanel.net).
- The VPN drops for a second. Without a kill switch, a brief disconnect sends traffic — including DNS — over your regular connection (MakeUseOf).
- Free VPNs that don't run their own resolvers. Providers without private DNS simply can't keep your lookups in the tunnel (myvpnhub).
How to test for a DNS leak (2 minutes)
- Note your baseline: with the VPN off, visit a leak-test site (e.g. dnsleaktest.com or ipleak.net) and record which DNS servers appear.
- Connect your VPN to your chosen server.
- Re-run the test. Run the standard and extended tests and compare the resolver lists.
Reading the result: if the detected resolvers belong to your VPN provider (or a privacy resolver you've chosen), you're clean. If your ISP's resolvers appear, you have a leak. Seeing Google (8.8.8.8) or Cloudflare (1.1.1.1) is not automatically a leak — it may be your browser's Secure DNS setting or the resolver your VPN uses; check your VPN's docs before panicking (cyberpanel.net; dev.to, 2026).
Run our free VPN leak test →
How to fix a DNS leak
- Enable DNS leak protection in your VPN app. On the major providers the option exists but may be off — find it in connection/DNS settings and reconnect. This clears the leak in the large majority of cases (dev.to, 2026; MakeUseOf).
- Fix Windows SMHNR. If the leak persists on Windows 10/11, disable Smart Multi-Homed Name Resolution (run PowerShell as administrator:
Set-DnsClientGlobalSetting -SmartMultiHomedNameResolution $false) and reboot (dev.to, 2026).
- Disable browser DoH. Firefox:
about:config → network.trr.mode = 5. Chrome: Settings → Privacy and security → Security → turn off "Use Secure DNS" (or point it at your VPN's DoH endpoint) (dev.to, 2026).
- Block or fix IPv6. Either use a VPN with IPv6 support, or disable IPv6 on the device if the provider's documentation is unclear (cyberpanel.net).
- Turn on the kill switch. It stops all traffic — including DNS — the moment the tunnel drops (MakeUseOf; see our kill switch explainer).
- Set a fallback private resolver. Manually setting your device's DNS to 1.1.1.1 (Cloudflare) or 9.9.9.9 (Quad9) means even a non-VPN moment doesn't expose lookups to your ISP (ExamineIP, 2026).
DNS leak vs. IP leak vs. WebRTC leak
| What leaks | Who sees it |
| DNS leak | The list of websites you visit (domain names) | Your ISP or a third-party resolver |
| IP leak | Your real public IP address | The websites you visit |
| WebRTC leak | Your real IP via browser WebRTC requests | The websites you visit (stun/turn requests) |
They're independent: you can have a DNS leak with a perfectly hidden IP, and vice versa. That's why a full test checks all three — ours does.
FAQ
Is a DNS leak dangerous?
It's a privacy problem, not a virus. It lets your provider log the domains you visit even while your traffic content is encrypted — undoing much of the reason you turned the VPN on. It's also one reason a "working" VPN can fail at streaming: services cross-check your IP's country against the resolver's and serve the wrong catalog (myvpnhub).
Do free VPNs leak DNS?
Far more often — many free VPNs don't run their own DNS resolvers at all, so leaks are structurally likely rather than a settings bug (myvpnhub). See the honest free-VPN guide.
How often should I test?
Test once after setup, again after VPN app updates and OS feature updates (Windows updates can re-enable SMHNR), and before anything sensitive (dev.to, 2026).
Can my VPN provider see my DNS requests?
Yes — the VPN's resolver handles them inside the tunnel. That's the tradeoff: you move trust from your ISP to the VPN provider, which is why an independently audited no-logs policy matters (MakeUseOf).
Sources