What DNS is doing every time you browse
Every time you type a domain name into a browser, your device needs to resolve that name to an IP address before it can connect. That resolution request — a DNS query — is normally sent to a DNS resolver, usually one supplied by your ISP by default, or a third-party one like 1.1.1.1 or 8.8.8.8 if you’ve configured it manually. Whoever handles that query can see, at minimum, the domain names you’re looking up, even if they can’t see the page content itself.
What a DNS leak actually is
When you connect to a VPN, a properly configured client routes your DNS queries through the encrypted tunnel to a DNS resolver the VPN provider runs, rather than the queries going out to your ISP’s resolver as normal. A DNS leak is when some or all of those queries bypass the tunnel and go to your default (usually ISP) resolver anyway, even though the rest of your traffic is correctly routed through the VPN. The practical effect: your IP address might show up as the VPN server’s, but your ISP can still see every domain you’re resolving, and in some leak scenarios your real IP is exposed to the DNS resolver itself.
Why it happens
- Operating system DNS behaviour. Some OS network stacks (this has historically been a particular issue on Windows with multiple active network adapters) query all available DNS servers in parallel and use whichever responds first, rather than exclusively the VPN’s.
- IPv6 leaks. If your VPN only tunnels IPv4 traffic but your device also has IPv6 connectivity, IPv6 DNS queries can go out unencrypted over the untunneled IPv6 path. This is a well-documented and common leak category.
- Manually configured DNS. If you’ve set a custom DNS resolver at the OS or router level, some VPN clients don’t override it, so your queries keep going to that resolver instead of the VPN’s.
- Smart DNS / transparent proxying features that some routers and ISPs use to intercept DNS requests regardless of what resolver you’ve specified.
How to test for one yourself
- Disconnect your VPN, go to a DNS leak testing site (e.g. dnsleaktest.com or the equivalent test most VPN providers host on their own domain), and run the extended/standard test. Note the IP addresses and DNS server locations shown — this is your baseline.
- Connect your VPN, then run the same test again on the same site.
- Compare results: if none of the DNS resolvers shown match your baseline (ISP) results, and they instead show servers associated with your VPN provider or its chosen resolver, DNS isn’t leaking. If any of the same ISP-associated servers reappear in the connected test, that’s a leak.
- Repeat with the IPv6 leak test specifically if the site offers one separately, since it’s a distinct failure mode from the standard IPv4 test.
How it’s fixed, when it’s fixable by you
Most reputable VPN apps today run their own DNS resolver inside the tunnel and configure your device to use only that while connected, plus a ‘DNS leak protection’ or ‘block untunneled traffic’ toggle that also blocks IPv6 leaks by disabling or tunneling IPv6 specifically. If you’re seeing a leak on a specific app, checking for that setting is the first step; on some platforms, manually setting your DNS to a fixed resolver at the OS level can override what the VPN app is trying to do, so leaving DNS on automatic while the VPN is active is usually the safer default.
FAQ
Does a kill switch stop DNS leaks?
Not directly — a kill switch responds to the VPN tunnel going down entirely, while a DNS leak can happen even while the tunnel is technically up and other traffic is correctly routed. They’re separate failure modes with separate fixes; see our kill switch explainer.
Are DNS leaks common in 2026?
Less common in mainstream paid VPN apps than a few years ago, since most now bundle DNS leak protection by default, but IPv6-specific leaks and leaks on less-maintained free VPN apps or manually configured VPN protocols (e.g. a self-set-up WireGuard or OpenVPN connection without explicit DNS configuration) are still realistic.
Can a website itself detect a DNS leak?
Not directly in the way a dedicated leak-testing site can, since that requires seeing which resolver actually handled the query. A site can only see the IP address your traffic arrives from.
Compare VPN providers side by side