Skip to DNS leak test content
Free privacy diagnostic

DNS Leak Test

See which DNS providers answer for this browser. Compare the result with your VPN or expected provider, then get a clear explanation of anything that looks out of place.

No account10 or 30 fresh lookupsEvidence grouped by network
Choose settings and run the test

Blockify resolver lab

Run your DNS leak test

Ready
Test depth
What should handle your DNS?

Enter at least four characters. The name is used only in this tab to match returned network labels and is never sent to the measurement service.

Plain-English answer

What is a DNS leak?

A DNS leak happens when a lookup reaches a resolver outside the private path you intended—for example, your home ISP's DNS while a VPN is supposed to handle every request.

The short version

DNS translates hostnames such as example.com into network addresses. If those requests bypass your intended VPN or private resolver, the unintended resolver can observe requested hostnames and timing—even when the website connection itself uses HTTPS.

What DNS can expose

Requested hostnames, query timing, and patterns that can reveal services you use. A resolver may also receive lookups for embedded resources and browser prefetches.

What DNS does not normally show

The full HTTPS URL, page path, form content, messages, or every action taken on a site. A DNS lookup also does not prove a person deliberately visited the hostname.

Why expectation matters

A Cloudflare, Google, workplace, or ISP resolver may be right or wrong depending on your setup. Resolver identity alone is evidence; your intended provider supplies the verdict.

Result interpretation

How to read your DNS leak test results

Look for unexpected organizations, not an arbitrary resolver count. Use a saved VPN-off baseline when you can; names and approximate locations alone can mislead.

Observed resultHow to interpret itSignal
VPN on + home ISP resolver appearsIf that ISP was present in your VPN-off baseline and is not approved by the VPN, this is a strong DNS leak signal.Investigate
VPN on + only VPN or approved resolverConsistent with the intended route. Retest after reconnecting and on another network if privacy requirements are strict.Expected
Google, Cloudflare, Quad9, or another public DNSMay be intentional browser Secure DNS, router DNS, or a VPN partner. Confirm the provider you selected.Context needed
Several IPs from the same organizationOften normal load balancing or resolver egress rotation. Group by organization before judging the result.Often normal
Resolver shown in another city or countryAnycast and imperfect IP geolocation can produce a mismatch. Ownership and expectation are stronger signals than location.Weak clue
No resolver observedThe probe may have been blocked or the measurement service may be unavailable. Never treat an empty result as safe.Inconclusive
Open methodology

How this DNS resolver test works

Browser pages cannot read your configured DNS servers directly. Instead, this test observes the resolver that performs a fresh lookup against a diagnostic DNS zone.

Create a one-time session

A fresh identifier is requested only after you press Start and is kept in component memory.

Trigger uncached names

The browser attempts numbered, never-before-used hostnames under the measurement domain.

Observe resolver egress

The authoritative DNS server records which recursive resolver IPs ask for those names.

Return grouped evidence

Resolver IP, ASN organization, and approximate country are returned to this tab and grouped for interpretation.

Directly observed

Resolver egress IPs that reached the authoritative test zone during this browser session.

Enriched and inferred

ASN organization and country are database-derived labels. They can be stale, approximate, or represent an upstream forwarder.

Not measurable here

Whether DNS used DoH or DoT, what every other app uses, past queries, internal split DNS, or protection during a VPN reconnect.

Measurement and data handling

Resolver observation is provided by bash.ws, not Blockify-owned DNS infrastructure. Starting the test sends network identifiers to that provider; its privacy policy and service availability apply. Its published privacy policy says data is kept only as long as necessary, but does not give a fixed retention period specifically for DNS test identifiers. Blockify servers do not receive or store the result payload, and the Google Analytics tag is disabled on this route.

Methodology and content update

Last updated July 27, 2026. This revision clarified the external provider's data-retention disclosure, documented the time-spaced Extended test, and tightened the difference between observed evidence and a guaranteed privacy result.

Troubleshooting

How to fix a DNS leak

Start with the component that is supposed to control DNS—usually your VPN—then remove overrides one layer at a time. Retest after every change so you know what actually fixed the path.

VPN: ISP and VPN resolvers appear together

Turn on the VPN's DNS leak protection and kill switch, reconnect to a different server, and make sure split tunneling does not exclude this browser. Remove a custom DNS entry from the VPN app unless the provider explicitly supports it.

If your VPN documents a third-party DNS partner, that network may be legitimate. If a pre-VPN ISP network remains, save the result summary and contact the VPN provider.

Chrome, Edge, or Brave: an unexpected public resolver appears

In Chrome, open Settings → Privacy and security → Security → Use secure DNS. Automatic mode can follow the current provider; a chosen custom provider can override system or VPN DNS. Match the setting to your intent, or turn it off temporarily to isolate the conflict and retest.

See Google's current Secure DNS guidance. Turning Secure DNS off removes that browser-level encryption, so use it as a diagnostic—not an automatic permanent fix.

Firefox: DNS differs from the rest of the device

Open Settings → Privacy & Security → DNS over HTTPS. Default, Increased, Max, and Custom protection can select different resolver behavior. If you want the VPN to decide, confirm that Firefox is not forcing a separate custom provider.

Mozilla explains the fallback and VPN behavior in its current DoH settings guide.

Windows, macOS, or Linux: check the active DNS configuration

On Windows, inspect every adapter with Get-DnsClientServerAddress, remove stale manual entries when the VPN should manage DNS, and use ipconfig /flushdns after changes. On Linux systems using systemd-resolved, run resolvectl status.

On macOS, use System Settings → Network → your active service → Details → DNS. Apple documents the current Mac DNS settings.

Android, iPhone, router, or suspected IPv6 leak

Android Private DNS, browser Secure DNS, a Wi-Fi DNS profile, the router, and the VPN app can each affect the resolver path. Check the VPN first, then the device-wide setting, then the active Wi-Fi network. On managed devices, consult IT before overriding private DNS.

If the issue appears only on a dual-stack network, confirm that the VPN supports and tunnels IPv6. Disabling IPv6 can isolate the cause, but standards guidance treats it as a temporary workaround rather than the durable fix. See RFC 7359.

DNS leak test FAQ

Questions behind the result

The tricky part is rarely finding an IP address. It is deciding whether that resolver belongs in the path you intended.

How do I know if my DNS is leaking?

Run the test while your VPN is connected, then compare every observed resolver organization with what your VPN provider says it uses. A home ISP resolver appearing during the VPN test is a strong leak signal. For better evidence, save a VPN-off baseline and rerun after connecting.

What should a safe VPN DNS result look like?

You should see only resolver networks that your VPN provider owns or explicitly approves. The visible public connection should also be the VPN exit, not your home ISP. A clean-looking browser snapshot is useful evidence, but it cannot guarantee that other apps or reconnect events never leak.

Why does the test show multiple DNS server IPs?

Large resolver services distribute queries across pools of machines, regions, and egress addresses. Several IPs from one organization are common and are not automatically a leak. The organization mix matters more than the raw server count.

Why do Google, Cloudflare, or another public DNS provider appear?

Your browser, operating system, router, security app, or VPN may intentionally use a public resolver. Chrome and Firefox can also use Secure DNS independently of system settings. A public provider is unexpected only when it differs from the setup you intended.

Why is my DNS resolver shown in another country?

Resolver location is approximate. Anycast routing, centralized egress, and imperfect IP geolocation can place a resolver in a different city or country. Treat geography as a clue, not proof of a DNS leak.

Does Secure DNS or DNS over HTTPS prevent DNS leaks?

DoH encrypts DNS between your browser or device and a resolver. It does not prove that the resolver is the one your VPN intended, and it can override VPN DNS in some configurations. Resolver identity, transport encryption, and intended routing are three separate questions.

What does a DNS leak reveal?

A resolver can observe requested hostnames and timing patterns. DNS does not normally reveal the full HTTPS URL, page path, page content, or whether every lookup became an intentional visit; browsers also resolve embedded resources and may prefetch names.

What is the difference between the standard and extended tests?

Standard mode sends 10 fresh lookups for a quick snapshot. Extended mode sends 30 lookups in three short bursts over roughly 10 seconds, which samples a resolver pool more broadly. It is still a brief test of this browser, not proof of protection during every reconnect or network change.

Why were no DNS resolvers detected?

A content filter, strict firewall, resolver failure, timeout, or unavailable measurement service may block the probes. No observation is inconclusive, never a pass. Retry with extended mode and cross-check with another independent test.

Can my browser DNS differ from the DNS used by other apps?

Yes. Browsers may use their own DoH settings, while native apps use the operating system or a built-in resolver. This page tests the path used for its browser requests; a whole-device audit requires additional app and network testing.

Is a DNS leak the same as an IP, IPv6, or WebRTC leak?

No. A DNS leak exposes an unintended resolver path. An IP or IPv6 leak exposes an unintended network address, and WebRTC can expose connection candidates. Check each signal separately instead of combining them into one automatic verdict.