DNS routing
Free DNS Leak Test
Observe the recursive DNS resolvers that look up fresh test hostnames for your browser. Compare a disconnected test with a VPN-connected test.
Run a resolver check
Temporarily unavailableThe active DNS test is temporarily unavailable. You can still compare your public IP and check WebRTC candidates.
Compare before and after connecting
- Disconnect your VPN and run the test. Note the resolver addresses and network owners.
- Connect your VPN and start a new test in the same browser and network.
- Check whether the observed resolvers match your intended VPN or secure DNS configuration.
What the result means
The result identifies recursive resolvers that contacted the test's authoritative DNS service. It does not directly identify every router between your device and the resolver.
A public DNS provider may be selected by your browser's secure DNS setting, your operating system or your VPN. Seeing Google or Cloudflare is not automatically a leak. Compare the result with your VPN documentation and ordinary ISP connection.
Limits of a browser test
Cached responses, DNS forwarding, anycast networks and blocked probes can affect results. A timeout means the test was inconclusive, not that your DNS route is protected. This page cannot verify the VPN's encryption or logging policies.
Short-lived test data
Each run uses a random token and fresh hostnames. Resolver addresses are kept for up to two minutes to return the result, then removed. No account, VPN password or persistent browser identifier is needed.
Follow the complete VPN test checklist or compare free VPN plans.