Skip to content
VPNmine

DNS leak result

No resolvers observed yet

Your exit IPchecking…Where your traffic leaves. Your DNS queries should leave from the same place.
Exit countryunknown
Resolvers seen0

DNS servers that answered

[DNS_RESOLVER_TEST]

DNS leak test

A DNS leak is when your device sends domain lookups outside the VPN tunnel, so your internet provider still sees every site you visit even though the traffic itself is encrypted. This test asks your browser to resolve random one-time hostnames, then reports which DNS servers actually answered and who operates them.

How this test works

Every time you open a site, your device asks a DNS resolver to turn the domain name into an address. That question is the leak surface. The traffic that follows can be perfectly encrypted while the question itself travels in the clear to a server your internet provider runs, leaving a timestamped list of every domain you opened.

The test above asks your browser to resolve ten hostnames that have never existed before. Because they are new, no cache anywhere on the internet can answer them, so the query has to travel all the way to the nameserver that is authoritative for the domain. We run that nameserver. It records the address of whichever resolver asked, and the panel lists them.

This is the only method that works. A page cannot read your DNS settings, and asking the browser what resolver it uses is not something the web platform allows. Being the authoritative server for a throwaway hostname is how every DNS leak test does it.

What causes a DNS leak

  • A client that adds a resolver without removing the old ones.The tunnel resolver is installed, the provider's resolver stays configured on the physical adapter, and whichever answers first wins.
  • Windows smart multi-homed name resolution. Since Windows 8, the system sends the same query to every interface at once and takes the fastest reply, which is documented behaviour rather than a bug. On a VPN that reliably means the local resolver sees the query too.
  • IPv6 escaping an IPv4-only tunnel. The client captures IPv4 DNS, the system prefers IPv6, and the query leaves over the untunnelled path.
  • Browser DNS-over-HTTPS. Firefox and Chrome can resolve names themselves over HTTPS to their own resolver, ignoring the system setting entirely, including the one your VPN just configured.
  • A split-tunnel rule that excludes port 53. Rare, but it appears in corporate configurations and in hand-written routing rules.

How to fix a DNS leak

  1. Turn on leak protection or the kill switch in your VPN client. Most clients have a setting that forces all queries into the tunnel, and it is not always on by default.
  2. Disable IPv6 on the network adapter if your VPN does not carry it. On Windows this is a checkbox in adapter properties; on macOS it is Configure IPv6: Off in the network settings for that interface.
  3. Turn off secure DNS in the browser so it stops bypassing the system resolver. Firefox calls it DNS over HTTPS under Privacy and Security; Chrome and Edge call it "Use secure DNS" under Privacy.
  4. On Windows, disable smart multi-homed name resolution through the group policy "Turn off smart multi-homed name resolution", which stops queries fanning out to every interface.
  5. Re-run this test. Then run it again after a reboot, because some clients restore the original resolver on start and only fix it once you reconnect.

Reading the result

Judge the list by who owns the addresses, not how many there are. Large resolver operators answer from anycast pools, so one configured server legitimately shows up as several addresses in the same network. What is meaningful is finding your own internet provider there while a VPN is connected, or finding resolvers in the country you are physically in rather than the country you connected to.

A resolver you chose deliberately, such as Cloudflare or Quad9, appearing from a nearby country is not a leak. It means your lookups go to that operator instead of your provider, which is what you asked for.

Where VPNmine stands

The VPNmine apps push their own resolver into the tunnel and route every query through it, so lookups exit at the same server the traffic does. DNS queries are listed under what we never collect, alongside browsing history and traffic content, which is a specific commitment rather than a vague no-logs claim.

If this test is clean, the other two worth running are the WebRTC leak test, which catches the browser handing out your real address through a different mechanism entirely, and the IP address check.

[COMMON_QUESTIONS]

DNS leak test questions

What is a DNS leak?

A DNS leak is when your device resolves domain names through a server outside the VPN tunnel. The traffic to the site is still encrypted, but the lookup that preceded it is not, so whoever runs that resolver, usually your internet provider, holds a timestamped list of every domain you opened. It defeats most of the point of connecting.

How do I know if my VPN is leaking DNS?

Run this test with the VPN connected. If the resolvers that answer belong to your internet provider, or sit in the country you are physically in rather than the country you connected to, your lookups are leaving the tunnel. If every resolver belongs to the VPN operator or to the resolver you deliberately chose, there is no leak.

What causes DNS leaks?

Four common causes: a VPN client that sets a tunnel resolver but does not remove the ones the operating system already had; Windows sending queries to every interface at once and taking the first answer, which is the documented behaviour of smart multi-homed name resolution; IPv6 lookups escaping a tunnel that only carries IPv4; and a browser using DNS-over-HTTPS to its own resolver regardless of what the system is set to.

How do I fix a DNS leak?

Turn on the kill switch or leak protection in your VPN client, which forces every query into the tunnel. If the client has no such setting, disable IPv6 on the adapter, and in Firefox or Chrome turn off secure DNS so the browser stops bypassing the system resolver. On Windows, disabling smart multi-homed name resolution by policy stops queries fanning out to every interface.

Is more than one resolver a leak?

Not by itself. Large resolver operators run anycast pools, so a single configured server can answer from several addresses in the same network. What matters is who owns them. Several addresses belonging to one operator you chose is normal; one address belonging to your internet provider is a leak.

Does VPNmine leak DNS?

No. The apps push their own resolver into the tunnel and route every query through it, so lookups exit at the same server your traffic does. Nothing about the queries is written to disk on our side, which is why our privacy policy lists DNS queries under what we never collect.

Close the leaks these tests find

VPNmine is a free no-logs VPN with its own OpenVPN servers in 19 countries, native apps for Windows, macOS, Android, iOS, Android TV and Apple TV, and browser extensions. No ads and no card required.

GET_VPNMINE