DNS leak check
Every time you open a website, your device first asks a DNS server "where is this name?". If you use a VPN but those questions still go to your internet provider, your provider can still see every site you visit. That is a DNS leak. This page helps you find out.
What we can and cannot do. A true leak test needs a special DNS server that records who asks it. We do not run one, and we would rather send you to established tests than fake it. What this page does is show the address websites see for you, so you can compare before and after turning your VPN on. It is looked up while the page loads and is not stored or logged.
Step 1: what websites see
| Your address | 216.73.217.139 (IPv4) |
|---|---|
| Name that address resolves to | None found |
The name often shows your internet provider (something like ...comcast.net) or a hosting company (a VPN). Write down the address, turn your VPN on, reload this page, and compare. It should change. If it does not, your VPN is not carrying this traffic.
Step 2: run a leak test
- Turn your VPN on and reload this page. Note the address from step 1.
- Open a leak test in a new tab: dnsleaktest.com (choose the extended test) or am.i.mullvad.net. Both work with any VPN. These are outside sites, and they will see your address and the DNS servers you use, as any website would.
- Look at the list of DNS servers it shows, and read the result below.
Reading the result
| What you see | What it means |
|---|---|
| Only your VPN's servers, or a public resolver you chose (Quad9, NextDNS and so on) | No leak. Your provider does not see the names you look up. |
| Your internet provider's name | Leak. Your provider can see every site you visit despite the VPN. See the fixes below. |
| Your real address shows up, or an IPv6 address you did not expect | Leak. Some VPNs only carry IPv4 traffic. Turn off IPv6 on your device or use a VPN that handles it. |
| Google, Cloudflare or another big resolver you did not choose | Not necessarily a leak, but that company now sees your lookups. Check whether it is your VPN's own choice. |
If it leaks
- Use the VPN's own app, not a hand-made setup. Good VPN apps set the DNS servers for you and have a "block leaks" or kill-switch option. Turn it on.
- Turn off "Secure DNS" or DNS-over-HTTPS in your browser, or set it to your VPN's server, if it points to a different company than you expect (Firefox: Settings > Privacy & Security; Chrome and Edge: Settings > Privacy and security > Security > Use secure DNS).
- Choose your own private resolver if you are not using a VPN, such as Quad9 or NextDNS. That moves the trust from your provider to that company; it does not hide your browsing from it.
- On Android, Settings > Network and internet > Private DNS. On iPhone, use the VPN app or a DNS profile from the resolver you chose.
- Test again after every change, and after updates, because operating systems change how they handle DNS.
What a clean result does not prove
- It shows names are not going to your internet provider. It does not make you anonymous. Websites still see the VPN's address, your logins and your browser fingerprint.
- Even with no leak, your provider can see that you are connected to a VPN and how much data flows.
- Leaks can come and go, for example when your VPN reconnects. A kill switch is the fix.
Read more in About DNS, VPN/TOR and the VPN comparison. You can also check whether you are on Tor. These are best available precautions, not guarantees.