b2KIT

DNS Leak Tester

Test for DNS leaks that could expose your browsing activity when using a VPN or proxy service.

Tested tool guide Tested browser tools Checked August 16, 2026

What DNS Leak Tester does and how it behaves

DNS Leak Tester reveals which recursive DNS resolvers are visible while your browser uses its current network path. Running the test causes lookups for test-specific hostnames, allowing the resolvers requesting those names to be identified. Compare the reported addresses and operators with the DNS service you expect your VPN, proxy, browser, or operating system to use. The common surprise is that several resolver addresses do not automatically mean a leak. A leak is a mismatch with the routing and resolver policy you intended.

How the result is produced

1

What the test observes

Each test lookup uses a hostname controlled for the test, so the authoritative DNS side can observe which recursive resolver requests that hostname. The reported resolver IP address is the network-facing address seen for the query. It may be a shared address operated by a VPN, internet provider, enterprise, or public DNS service rather than an address assigned directly to your device.

2

How to interpret the result

Establish which resolver or provider your VPN or proxy is supposed to use, then run the test while that service is connected. Resolver addresses belonging to an unexpected ISP or local network can indicate DNS bypass. Repeat after disconnecting for comparison. The expected set depends on split tunneling, browser secure DNS settings, corporate policy, and whether the proxy is designed to carry DNS requests.

Good uses

  • Verify that a full-tunnel VPN replaces the DNS resolvers normally supplied by an ISP.
  • Compare resolver visibility before and after enabling secure DNS in a browser.
  • Check whether a hotel, office, or home network still handles DNS while a privacy proxy is active.

Limits and checks

  • The result covers lookups made for this browser test at that moment, not every application or a later network state.
  • An unfamiliar provider, multiple addresses, or an unexpected location is not proof of a leak; shared and anycast resolver infrastructure can complicate identification.
  • A clean result does not show whether application traffic bypasses the VPN or whether the selected resolver retains requested domain names.

Common questions

Why does the tester show more than one DNS server?

DNS services commonly use pools of recursive resolvers for capacity, reliability, and geographic distribution. A VPN may therefore produce several legitimate addresses during one test. Multiple rows are not themselves a failure. They matter when an address belongs to a network or operator that should not receive DNS requests under your chosen VPN or proxy configuration.

Can this test prove that my VPN or proxy protects all browsing activity?

No. It can reveal which resolvers handled the test's DNS lookups and help identify unexpected DNS routing. It cannot verify all traffic encryption, detect every IP or WebRTC exposure, assess resolver logging, or describe the behavior of other applications. Test again after changing networks, VPN servers, browser DNS settings, or split-tunneling rules.

References and verification

The behavioral notes were checked against the browser implementation. Standards and primary references below define the relevant format, formula, or platform behavior.

Related Tools