What Is a DNS Leak?

Last updated: October 2026

Disclosure: LeakCheck currently has no affiliate relationships and earns nothing from any link on this page. Provider links below are non-affiliate placeholders (marked #AFFILIATE-PLACEHOLDER-* in our code) until we join programs — at which point every affected page gets a clear, conspicuous disclosure. Full disclosure.

A DNS leak happens when your domain-name lookups — the requests your device makes to translate a website name like example.com into an IP address — travel to your ISP's DNS servers instead of through your VPN tunnel. Your traffic is encrypted, your IP may be hidden, but your ISP can still see every website you visit — which defeats much of the point of using a VPN. One analysis of 10,000 real leak tests found DNS leaks were the most common leak of all (67%), ahead of WebRTC (42%) and IPv6 (23%) (ExamineIP; Medium, April 2026).

Related: what is a WebRTC leak? · how to check if your VPN is working

What DNS does, in 30 seconds

When you type a web address, your device asks a DNS resolver: "what IP is this domain?" Normally that request goes to your ISP's resolver, which logs it. A properly configured VPN pushes its own DNS resolver through the tunnel, so those requests are encrypted and handled by the VPN provider instead. A leak means the request escaped the tunnel and went to the ISP (or another outside resolver) anyway (MakeUseOf; myvpnhub).

What causes a DNS leak?

How to test for a DNS leak (2 minutes)

  1. Note your baseline: with the VPN off, visit a leak-test site (e.g. dnsleaktest.com or ipleak.net) and record which DNS servers appear.
  2. Connect your VPN to your chosen server.
  3. Re-run the test. Run the standard and extended tests and compare the resolver lists.
Reading the result: if the detected resolvers belong to your VPN provider (or a privacy resolver you've chosen), you're clean. If your ISP's resolvers appear, you have a leak. Seeing Google (8.8.8.8) or Cloudflare (1.1.1.1) is not automatically a leak — it may be your browser's Secure DNS setting or the resolver your VPN uses; check your VPN's docs before panicking (cyberpanel.net; dev.to, 2026).

Run our free VPN leak test →

How to fix a DNS leak

DNS leak vs. IP leak vs. WebRTC leak

What leaksWho sees it
DNS leakThe list of websites you visit (domain names)Your ISP or a third-party resolver
IP leakYour real public IP addressThe websites you visit
WebRTC leakYour real IP via browser WebRTC requestsThe websites you visit (stun/turn requests)

They're independent: you can have a DNS leak with a perfectly hidden IP, and vice versa. That's why a full test checks all three — ours does.

FAQ

Is a DNS leak dangerous?

It's a privacy problem, not a virus. It lets your provider log the domains you visit even while your traffic content is encrypted — undoing much of the reason you turned the VPN on. It's also one reason a "working" VPN can fail at streaming: services cross-check your IP's country against the resolver's and serve the wrong catalog (myvpnhub).

Do free VPNs leak DNS?

Far more often — many free VPNs don't run their own DNS resolvers at all, so leaks are structurally likely rather than a settings bug (myvpnhub). See the honest free-VPN guide.

How often should I test?

Test once after setup, again after VPN app updates and OS feature updates (Windows updates can re-enable SMHNR), and before anything sensitive (dev.to, 2026).

Can my VPN provider see my DNS requests?

Yes — the VPN's resolver handles them inside the tunnel. That's the tradeoff: you move trust from your ISP to the VPN provider, which is why an independently audited no-logs policy matters (MakeUseOf).

Sources