DNS Leak Test

See which DNS resolvers actually answer for your device. Reveal VPN and encrypted-DNS leaks, resolver interception, and misconfigured clients.

Your public IP

Shown only to you. It never appears in test results.

6 probes · quick check

Privacy

  • Results live in memory only and are deleted within 15 minutes. Nothing is written to disk.
  • The resolver addresses shown may include your own IP if you run your own recursive resolver.
  • EDNS Client Subnet data is shown masked: presence and prefix length only, never the subnet itself.
  • Your public IP is displayed only to you and is not part of the test results.

Resolver locations are approximate. IP Geolocation by DB-IP.

How It Works

1. Hostnames that have never existed

Your browser loads invisible probes from unique hostnames that have never existed before. No cache anywhere can answer them, so every lookup must travel your real resolution path.

2. Authoritative observation

Only our nameserver can answer for those hostnames. Whichever resolver asks it is, by definition, part of how your device resolves names.

3. Observations, not verdicts

Results show exactly what was observed, with uncertainty stated. Multiple resolvers are often normal; the value is seeing which networks answered when you expected only one.

Frequently Asked Questions

What is a DNS leak?

A DNS leak is when your device's name lookups are answered by a resolver you did not intend to use: your ISP's resolver while you are on a VPN, a network middlebox intercepting DNS, or an application bypassing your configured encrypted DNS. This test observes which resolvers actually service your lookups, so you can compare reality against intent.

Why do I see multiple resolver addresses or networks?

Usually because that is how resolvers work. Resolver services run fleets behind anycast, so different queries egress from different addresses, and IPv4 and IPv6 lookups can take different paths. Several addresses within one network is expected; a network you cannot explain is the thing worth investigating.

Why are there more queries than probes?

Each probe hostname triggers several lookups. Browsers request multiple record types per name (IPv4, IPv6, and the newer HTTPS record), resolver fleets spread those queries across different egress addresses, and ordinary retries add more. "Probes observed" counts unique hostnames our nameserver saw; the per-resolver query counts include every arrival. More queries than probes is normal, and the spread across addresses is a useful picture of how a resolver fleet distributes its work.

What does "inconclusive" mean?

If none of the probe lookups reach our nameserver, we say so, and it never means "no leak." Content blockers, browser extensions, hidden tabs, DNS filters, and plain network failures can all suppress the probes. Re-run with the tab visible, or try another network.

Is my data stored?

Results live in memory only and are deleted within 15 minutes; nothing is written to disk. The resolver addresses shown may include your own IP if you run your own recursive resolver, and EDNS Client Subnet data is always shown masked. See our Tools Terms of Service for details.

Is this tool free?

Yes. We rate limit test creation to keep it fair, and the tool has no availability guarantee: it is a free diagnostic. For DNS-layer protection with policy enforcement, that is the ScoutDNS platform.

Understand What You're Seeing

The DNS Library covers the concepts behind this test: how resolution works, what encrypted DNS does and doesn't hide, and how transparent proxies intercept queries.

Browse the DNS Library →