DNS Leak Test
Check if your VPN is securely routing your DNS queries, or if it's leaking them to your ISP.
Ready to test
This test will perform 10 unique DNS lookups to see which servers are handling your traffic.
What Is a DNS Leak?
Your browser constantly resolves domain names (like google.com) into IP addresses using a Domain Name System (DNS) server. When you connect to a Virtual Private Network (VPN), your operating system should securely route all of these DNS requests through the encrypted VPN tunnel directly to your VPN provider's own secure DNS servers.
A DNS leak occurs when your system ignores the VPN and accidentally sends your DNS requests directly to your Internet Service Provider (ISP) instead. This means your ISP can see a complete log of exactly which websites you are visiting, even if the actual website traffic is technically encrypted by the VPN.
Why Do DNS Leaks Happen?
DNS leaks frequently happen when your computer reconnects to a network (like waking up from sleep or switching Wi-Fi networks) and the operating system resets its default network settings faster than the VPN software can re-establish its protective tunnel. They also occur frequently on Windows machines due to a feature called "Smart Multi-Homed Name Resolution," which aggressively queries all available network adapters to find the fastest DNS response, often bypassing the VPN entirely.
How Does This DNS Leak Test Work?
This test works by forcing your browser to look up completely unique, randomly generated subdomains (e.g., 1.unique_id.bash.ws). Because these domains have never been seen before, your DNS resolver cannot use a cached result. It must query the authoritative name server. We monitor that name server to see which IP address is asking for the domains.
- If you see your ISP's name or location: Your DNS is leaking. Your ISP knows what sites you visit.
- If you only see your VPN provider's servers: Your DNS is secure and not leaking.
Frequently Asked Questions
Is a DNS leak dangerous?
If you are using a VPN to hide your browsing activity from your ISP, government, or local network administrator, a DNS leak completely compromises your privacy. While the contents of your communications remain encrypted, the exact list of websites you visit is fully exposed.
How do I fix a DNS leak?
To fix a DNS leak, ensure your VPN app has "DNS Leak Protection" enabled in its settings. You can also manually configure your network adapter to use secure, third-party DNS servers (like Cloudflare's 1.1.1.1 or Google's 8.8.8.8) instead of your ISP's default servers.
Further reading