Issue 01 · A guide to getting your internet backFree for 5 days

DNS leak test: how to pass it

Your traffic can be inside the tunnel while your lookups are not. One test page tells you.

What a leak is

Every time you open a site, your device first asks a DNS server for the site's address. With a VPN on, that question belongs inside the tunnel. A DNS leak is when it goes to your own provider's DNS server instead. The provider then has a list of every site name you visit, even though the pages themselves are encrypted. A DNS leak test makes a handful of lookups and shows who answered them.

Pass or fail is easy to see. Your provider's name in the list means a leak. Only VPN side or public resolvers means you are fine.

Running a DNS leak check the right way

1

With the VPN off, run the test once. The names you see are your baseline.

2

Connect the key and wait a few seconds.

3

Run the extended test, not just the quick one. It makes more lookups and catches leaks that come and go.

4

Compare. None of the baseline names should be left.

5

Do it again on mobile data and on any other Wi-Fi you use often.

Why leaks happen

  • Windows asks every network adapter at once and takes the fastest reply.
  • The network offers IPv6, the tunnel carries only IPv4, and IPv6 lookups slip around it.
  • The client runs in proxy mode, so only the browser uses the tunnel.
  • The browser has its own secure DNS setting that points at your provider.
  • Some routers and providers intercept plain DNS no matter what you set.

Closing the leak

Switch the client to TUN mode, which some apps call VPN mode. That puts the whole device in the tunnel and not only the apps that follow a proxy. Turn on the client's own DNS option. Hiddify, v2rayN and v2rayNG all have one. If an IPv6 resolver from your provider still shows up, either enable IPv6 in the client or turn IPv6 off on that network adapter. Then check DNS leak results again. The test is the judge, not the settings screen.

A pass looks like this

  • A short list of servers, none of them your provider's.
  • The same list in the quick test and the extended test.
  • No IPv6 entry from your provider.
  • The same result on Wi-Fi and on mobile data.
  • Still clean after the computer wakes from sleep.

How much it matters

Be realistic. With HTTPS everywhere, a leak exposes site names and not what you did on those sites. That is still a browsing history in someone else's hands, and on a filtered network leaked lookups are often what gets a connection blocked. Treat the test as the last step of setup. It takes a minute and you rarely need to repeat it. If the result is clean on the networks you use every day, you are done, and no extra DNS software or paid add-on is needed.

Q.What does a DNS leak test check?

A.Which DNS servers answer your device's lookups while the VPN is on. Your provider's servers should not be among them.

Q.Is a DNS leak check safe?

A.Yes. The page resolves a few harmless test names and lists the servers that replied.

Q.I see Google or Cloudflare in the list. Is that a leak?

A.No, as long as the request reached them through the tunnel. A leak means your own provider appears.

Q.Do phones leak DNS?

A.Less often, because the system routes all traffic into the VPN interface. Per app routing and IPv6 only networks are the exceptions.

Q.How often should I test?

A.After setup, after changing a client or its settings, and once on each new network.

Q.Does a leak reveal passwords?

A.No. It reveals site names. Passwords and page contents stay encrypted by HTTPS.

5 days free · No card · 5 devices · No auto-renewal

5 days on us.

If it does not hold up on your own connection, you have lost nothing. That is what the free days are for.

Get 5 days freeOpens Telegram