Click "Run Test" to check for DNS leaks

Run this DNS leak test to check whether your DNS queries are being routed through your VPN’s secure servers or leaking to your ISP. Results show all DNS servers handling your requests within seconds.

FreeGuard Internal Test Results

FreeGuard VPN routes all DNS queries through its private DNS servers with zero leaks detected across Windows, macOS, Android, and iOS in our testing.

View testing methodology →

What Is a DNS Leak and Why Does It Matter for Your Privacy?

A DNS leak occurs when your DNS queries bypass your VPN tunnel and are sent to your ISP’s DNS servers, revealing every website you visit despite VPN encryption.

The Domain Name System (DNS) translates human-readable website names (like google.com) into IP addresses that computers use to connect. Every time you visit a website, a DNS query is sent first.

When you use a VPN, these DNS queries should travel through the encrypted VPN tunnel to the VPN provider’s DNS servers. A DNS leak happens when some or all queries bypass the tunnel and go to your ISP’s DNS servers instead.

This is a serious privacy issue because your ISP can see every domain you visit, even though the actual page content is encrypted. In many countries, ISPs are legally required to log this data and may share it with government agencies or sell it to advertisers.

DNS leaks typically occur due to misconfigured VPN software, operating system DNS settings that override the VPN, or IPv6 DNS queries that fall outside the IPv4 VPN tunnel.

Common Causes of DNS Leaks and How to Prevent Them

DNS leaks are most commonly caused by OS-level DNS fallback settings, IPv6 misconfiguration, and VPN clients that fail to override system DNS on all network interfaces.

Understanding the root causes of DNS leaks helps you prevent them effectively:

Operating System DNS Fallback: Windows, macOS, and Linux all have built-in DNS resolution that can bypass VPN tunnels. Windows is particularly prone to this with its Smart Multi-Homed Name Resolution feature, which queries all available DNS servers simultaneously.

IPv6 DNS Queries: If your VPN only tunnels IPv4 traffic, DNS queries over IPv6 will go directly to your ISP. This is increasingly common as ISPs deploy dual-stack (IPv4 + IPv6) networks.

Router-Level DNS: Some routers have hardcoded DNS servers that intercept and redirect DNS queries regardless of device-level settings. This is common on ISP-provided routers.

Prevention: Use a VPN with built-in DNS leak protection that forces all DNS through the VPN tunnel, disables IPv6 when not tunneled, and blocks DNS traffic on all non-VPN interfaces. FreeGuard VPN implements all three protections by default.

How to Protect Yourself in 3 Steps

  1. Step 1: Connect to your VPN and run the DNS leak test above
  2. Step 2: Check the results — if only your VPN provider’s DNS servers appear, you are protected
  3. Step 3: If your ISP’s DNS servers appear, enable DNS leak protection in your VPN settings or switch to FreeGuard VPN

Frequently Asked Questions

What exactly happens during a DNS leak test and how does it detect if my queries are being exposed and what are the most important things I should know about this?

The test sends multiple DNS queries to unique subdomains. By checking which DNS servers resolve these queries, it determines whether your VPN or your ISP is handling your DNS traffic.

Why would my DNS queries leak outside the VPN tunnel even when my VPN connection shows as active and what are the most important things I should know about this?

Common causes include OS-level DNS fallback settings, IPv6 DNS queries not covered by the VPN, and router-level DNS interception. Some VPN clients fail to override all system DNS settings.

Can my internet service provider see which websites I visit if my VPN has a DNS leak and what are the most important things I should know about this?

Yes. DNS leaks expose every domain name you visit to your ISP’s DNS servers, even though the actual page content remains encrypted by your VPN.

What is the difference between a DNS leak and a WebRTC leak in terms of privacy exposure to ensure my personal data and browsing activity remain fully private?

A DNS leak exposes the websites you visit (domain names). A WebRTC leak exposes your real IP address. Both bypass VPN protection but reveal different types of information.

How do I fix a DNS leak on Windows if my VPN client does not have built-in DNS leak protection when I am using a VPN service?

Disable Smart Multi-Homed Name Resolution in Group Policy, manually set your DNS to your VPN provider’s servers, and disable IPv6 on your network adapter if your VPN does not tunnel it.

Does using a custom DNS provider like Cloudflare or Google DNS protect me from DNS leaks when using a VPN and what should I be aware of?

No. Custom DNS servers still receive your queries in plain text. Only routing DNS through your VPN’s encrypted tunnel prevents your ISP from seeing your DNS traffic.

Is it possible to have a DNS leak on my mobile phone and how can I test for it on Android or iOS?

Yes, mobile devices are susceptible to DNS leaks, especially when switching between Wi-Fi and cellular. Run this test on your phone’s browser while connected to your VPN to check.

How frequently should I run a DNS leak test to make sure my VPN continues to protect my DNS queries when I am using a VPN service?

Test after VPN installation, after OS updates, when switching networks, and periodically (monthly). OS and VPN updates can change DNS routing behavior without warning.

DNS queries account for the initial step of nearly every internet connection, making DNS leaks one of the most common VPN privacy failures. — ICANN (2024)

Approximately 25% of VPN users experience DNS leaks without knowing, exposing their browsing history to ISPs despite VPN encryption. — Electronic Frontier Foundation (2023)

Over 85% of DNS queries globally are still sent unencrypted using traditional DNS, rather than DNS-over-HTTPS or DNS-over-TLS. — APNIC (2024)

ISPs in at least 48 countries have been documented logging DNS queries for government surveillance or data retention compliance. — Freedom House (2024)

Last verified: 2026-04-15