A DNS leak happens when your device sends its DNS lookups — the requests that turn example.com into an IP address — outside your VPN tunnel, usually straight to your internet provider. Your traffic is still encrypted, but the list of every site you visit is not. Your ISP ends up with the exact browsing record you installed a VPN to hide.
The frustrating part is that nothing looks wrong. The VPN app says “Connected,” your IP address checks out, and everything works normally. A DNS leak is silent by nature — the only way to find one is to test for it.
Key Takeaway:
A DNS leak doesn’t break your encryption — it bypasses it. The content of your traffic stays private; the destinations don’t. For most people that’s the more revealing half.
A 30-Second DNS Refresher
Every time you type a web address, your device has to look up the numeric IP behind that name. It asks a DNS resolver — normally the one your ISP runs, unless you’ve changed it.
That resolver therefore sees a timestamped list of every domain you ask about. Not the pages, not the content — just the names. Which, in practice, is enough to reconstruct most of what someone does online. If you want the full picture of how this works, see What Is DNS?
What a DNS Leak Actually Is
When you connect to a VPN, two things are supposed to happen:
- Your traffic is encrypted and routed through the VPN tunnel.
- Your DNS lookups are also sent through that tunnel, to the VPN provider’s own resolver.
A DNS leak is when the second part fails. The tunnel is up and carrying your traffic, but your operating system keeps sending DNS queries to your ISP’s resolver over your normal connection — right past the VPN.
The result is a strange split. Your ISP can’t read what you’re doing on example.com, but it knows you asked for example.com at 9:47pm, and again at 9:52pm, and it can build a profile from that alone.
What a DNS Leak Does and Doesn’t Expose
There’s a lot of sloppy writing on this topic, so it’s worth being precise about what’s actually at risk.
| Exposed? | Detail |
|---|---|
| ⚠️ Yes | Every domain you visit, with timestamps, visible to your ISP |
| ⚠️ Yes | Your real ISP and rough location, to anyone running a DNS-based check |
| ⚠️ Yes | That you’re using a VPN, and that it’s misconfigured |
| ✅ No | The contents of your traffic — still encrypted by the tunnel and HTTPS |
| ✅ No | Your real IP to the websites you visit — they still see the VPN server |
That last row matters. A DNS leak is not the same as an IP leak — the site you’re visiting doesn’t suddenly learn your home address. The damage is upstream, with your ISP and your DNS resolver. It’s a privacy failure, not an anonymity collapse — but it defeats the main reason most people run a VPN at home. See what your ISP can see about you for why that record is valuable.
What Causes DNS Leaks
1. The VPN Doesn’t Run Its Own DNS
The most common cause, and the most basic. Cheap and free providers often don’t operate resolvers, so they leave your existing DNS settings untouched and only route your traffic. Everything “works,” and every lookup goes to your ISP. This is one of the recurring problems with free VPNs.
2. Windows Smart Multi-Homed Name Resolution
Windows has a feature that sends DNS queries out of every network interface simultaneously and uses whichever replies first. It’s designed for speed. On a VPN it’s a liability, because your ISP’s resolver is physically closer and usually wins the race — so your lookups go to it even though a perfectly good tunnel is available.
3. IPv6 Escaping the Tunnel
Plenty of VPNs still only tunnel IPv4. If your connection also has IPv6 enabled, IPv6 DNS queries can travel outside the tunnel entirely. The VPN isn’t broken — it simply never took responsibility for that traffic.
4. Transparent DNS Proxying by Your ISP
Some providers intercept all DNS traffic on the network and force it to their own servers, regardless of what you configured. Even a correct setup can be quietly overridden. This is more common on mobile networks and with certain routers.
5. Browser-Level Secure DNS
Chrome and Firefox can run their own DNS over HTTPS independently of your system settings. This is usually good for privacy, but it can conflict with your VPN’s DNS and produce confusing test results — the browser resolving one way while everything else resolves another.
6. Manual DNS Settings or Split Tunneling
If you once hardcoded 8.8.8.8 or your router pushes a fixed resolver, that setting can survive the VPN connection. Similarly, split tunneling deliberately routes some apps outside the VPN — and their DNS goes with them.
7. The Tunnel Dropped Without You Noticing
If the VPN disconnects briefly, everything reverts to normal until it reconnects. Without a kill switch, you may never see it happen.
How to Test for a DNS Leak
The test only means something if you do it in the right order. Follow these steps exactly:
- Disconnect your VPN. Run our DNS Checker and write down which resolver appears — this is your ISP’s, your baseline.
- Connect your VPN. Pick a server in a different country to make the comparison obvious.
- Run the check again. Compare the resolver shown now against your baseline.
- Also run the VPN Leak Test to confirm your IP address is being masked at the same time.
How to Read the Results
| What You See | Verdict |
|---|---|
| Resolver matches your ISP’s name | ❌ Leaking |
| Resolver is in your real country, VPN says another | ❌ Leaking |
| Resolver belongs to the VPN provider | ✅ Correct |
| Resolver is a public DNS you deliberately set | ⚠️ Not your ISP, but not private either |
| Multiple resolvers, one of them your ISP | ❌ Partial leak — still a leak |
A partial leak counts. If your ISP appears anywhere in that list, some portion of your lookups is reaching it.
How to Fix a DNS Leak
Work through these in order — the first two solve the large majority of cases.
- Enable your VPN’s DNS leak protection. Most decent apps have it in settings, sometimes off by default. Turn it on, reconnect, retest.
- Turn on the kill switch. This closes the window where a dropped tunnel silently exposes you.
- Disable IPv6 — either in your VPN app, or at the OS level — unless your provider explicitly supports IPv6 tunnelling.
- On Windows, disable Smart Multi-Homed Name Resolution. It’s a Group Policy setting under DNS Client. This alone fixes a surprising number of Windows-only leaks.
- Clear stale settings. Remove any manually configured DNS servers, then flush your DNS cache so old results don’t mask the change.
- Check your browser’s Secure DNS setting and either disable it or point it somewhere consistent with your VPN.
- Check the router. If your router pushes a fixed DNS server to every device, that setting can override the VPN. See how to check your DNS settings.
- Switch providers. If a VPN leaks after all of the above, it doesn’t run proper DNS infrastructure. That isn’t a setting you can fix.
🔒 If Your VPN Is the Problem
Leak protection, private DNS resolvers and a working kill switch are table stakes — a provider that lacks them isn’t cutting a corner on a luxury feature, it’s failing at the core job. Two subscription-funded options that run their own DNS:
- PureVPN — own DNS infrastructure, leak protection built in
- IPVanish — private resolvers, kill switch across platforms
More on what separates a serious provider from a well-marketed one: Best VPN for Privacy in 2026.
DNS Leaks vs WebRTC Leaks vs IP Leaks
These three get conflated constantly. They’re different failures with different consequences.
| Leak Type | What Escapes | Who Sees It |
|---|---|---|
| DNS leak | The domains you look up | Your ISP / DNS resolver |
| WebRTC leak | Your real IP address | Any website running the script |
| IP leak | Your real IP, tunnel bypassed entirely | Everyone you connect to |
A WebRTC leak is arguably worse, because it hands your real IP directly to any site that asks. Details and fixes: WebRTC Leak Test. To check all three together, follow How to Check If Your VPN Is Working.
⚠️ Prevention Checklist
- Use a VPN that operates its own DNS resolvers
- Keep DNS leak protection and the kill switch enabled
- Disable IPv6 unless your provider tunnels it
- Retest after every app update — settings do get reset
- Retest on each network you use; a leak can appear on one router and not another
- Don’t rely on browser extensions alone — they only cover the browser
Frequently Asked Questions
Does a DNS leak reveal my real IP address to websites?
Not to the websites you browse — they still see the VPN server. The leak exposes your browsing to your ISP or DNS provider, and reveals your real ISP and rough location to anything specifically testing your resolver. That’s a different problem from a WebRTC leak, which does expose your IP directly.
Can I have a DNS leak without a VPN?
Not in the usual sense. Without a VPN there’s no tunnel to leak out of — your ISP sees your DNS by default. The term specifically describes lookups escaping a tunnel that should have carried them.
Why does my VPN say connected but still leak?
Because the tunnel and DNS resolution are handled separately. The app is reporting the tunnel’s status, which is genuinely fine. Nothing in the interface is monitoring where your lookups go, which is exactly why leaks stay invisible.
Will changing to Google or Cloudflare DNS fix it?
It stops your ISP seeing your lookups, which is an improvement. But you’ve moved that visibility to another company rather than keeping it inside the tunnel. Better than leaking to your ISP; not as good as your VPN’s own resolver.
How often should I test?
After installing or updating a VPN, after any OS update, and whenever you join an unfamiliar network. It takes under a minute with our DNS Checker.
Do free VPNs leak more often?
Considerably. Running DNS resolvers costs money, so free services frequently skip it and leave your ISP’s settings in place. See Are Free VPNs Safe?
Does DNS over HTTPS prevent DNS leaks?
It encrypts your lookups so your ISP can’t read them, which addresses much of the harm. It doesn’t guarantee they travel through your VPN tunnel, and browser-level DoH can conflict with your VPN’s DNS. Useful, but not a substitute for proper leak protection.
Does a DNS leak slow down my internet?
Usually the opposite — your ISP’s resolver is often physically closer and slightly faster. That’s precisely why Windows prefers it, and why leaks go unnoticed.