A VPN encrypts your traffic and changes your visible IP address, but if DNS requests bypass the tunnel, your ISP can still see the list of sites you visit. This is called a DNS leak — one of the most common reasons a VPN doesn't deliver the privacy you expect, even when the tunnel itself is working fine.
What happens during a DNS request
Before a browser can open a site, your device has to look up which IP address its domain name maps to — that's a DNS request. Without a VPN, that request normally goes to your ISP's DNS server, which ends up with a history of the domains you visit even if the traffic itself later goes elsewhere. A properly configured VPN should route DNS requests through its own encrypted tunnel, but configuration mistakes — in the app or the OS — can let some requests slip past it.
How to check your VPN for a DNS leak
The check takes a couple of minutes and needs no special software. First, open a dedicated site (dnsleaktest.com or browserleaks.com/dns, for example) with the VPN off and note which DNS server it shows — usually tied to your ISP. Then turn on the VPN, wait for it to connect, refresh the same page, and run the extended test. If the results list a DNS server tied to your ISP rather than your VPN provider, that's a leak.
Common causes of leaks
- Mishandled IPv6 traffic — some VPN apps only tunnel IPv4, letting IPv6 DNS requests go out around the VPN.
- Using the system's default DNS server instead of the VPN provider's in Windows, macOS, or home-router settings.
- "Smart" DNS resolver selection in the OS, which prefers a faster response outside the active VPN tunnel.
- Browser extensions with their own DNS-over-HTTPS, which conflict with the VPN client's DNS settings.
How to protect yourself
Most reputable VPN apps include built-in DNS-leak protection and an option to disable IPv6 in settings — check whether they're on by default and enable them manually if not. A kill switch also helps: a feature that blocks all of a device's internet traffic if the VPN connection suddenly drops, instead of silently falling back to an unprotected connection.
Our catalog flags services with a no-logs policy and a privacy focus — the same cards usually note whether a given provider supports built-in DNS-leak protection and a kill switch.