A DNS leak happens when domain-name lookups use a resolver outside the route you expected while connected to a VPN. That resolver can see the names being requested even when a website’s HTTPS content remains encrypted.
Test before and after connecting
- Disconnect the VPN and note your current public IP and provider.
- Use a reputable DNS test and record the resolver names and countries.
- Connect the VPN and repeat both checks in a fresh private tab.
- Compare the results. A resolver belonging to your normal provider while the VPN is connected may warrant investigation, but unfamiliar resolver names are not automatically proof of a leak.
Common causes
- A manually configured or “private DNS” resolver that does not follow the VPN route.
- Two VPN, proxy, filtering, or security apps competing for network configuration.
- Browser secure-DNS settings using a separate resolver.
- An outdated VPN app or operating-system networking bug.
- IPv6 or split-tunnel traffic using a path different from IPv4.
Fix DNS leaks on Android or iPhone
On an organization-managed device, consult your administrator before changing VPN or security settings.
- Update the VPN app and operating system, then restart the device.
- Disconnect other VPN, proxy, DNS-filtering, or security apps temporarily.
- Return custom DNS and proxy settings to automatic unless your VPN provider documents another configuration.
- Reconnect to another available VPN location and retest.
- If the unexpected resolver remains, save the test details and contact the VPN provider before assuming traffic is protected.
DNS privacy is only one layer
A clean DNS test does not prove every app uses the tunnel, and DNS encryption does not replace HTTPS. Also check the visible IP and understand the limits of IP masking. Avoid disabling IPv6 or changing advanced network settings permanently unless you understand the impact and have a documented reason.