DNS Leak Test

Find out which DNS servers resolve your lookups and whether they are in the same country as the IP address websites see. A VPN or proxy that leaves DNS on your local line gives your real location away.

Testing your DNS…

Sending test queries and waiting for your DNS servers to reveal themselves.

0/9 test queries finished · 0 failed

Your connection

IP address
Checking…
ISP
Checking…
Country
Checking…

DNS servers that answered

Each test query uses a fresh random domain, so it must be resolved from scratch by the DNS servers your device actually uses.

Sending test queries…

Frequently asked questions

What is a DNS leak?

Every website visit starts with a DNS lookup that turns a name into an address. A DNS leak happens when those lookups bypass your VPN or proxy and go to your internet provider's DNS servers, revealing the sites you visit and your real location even though your traffic is tunneled.

How does this test work?

Your browser requests nine random subdomains that no cache has seen before. The authoritative server records which DNS server asked for each one and reports it back along with that server's country and ISP. Each DNS server's country is then compared with the country of the IP address this page arrived from.

Why "possible leak" and not "leak"?

Public DNS services such as Google, Cloudflare and Quad9 use anycast: your query goes to whichever site is closest, and that is often in a neighbouring country. A public DNS server in another country is therefore reported as a possible leak, while an ISP's own DNS server in another country is reported as a leak.

How do I fix a DNS leak?

Enable your VPN's DNS leak protection or its own DNS servers, disable IPv6 if your VPN does not tunnel it, turn off Secure DNS (DNS-over-HTTPS) providers that bypass the tunnel, and with proxies make sure DNS is resolved on the proxy side, for example SOCKS5 with remote DNS.