DNS leak test

While you are on a VPN or proxy, do your DNS lookups slip past the tunnel to your real ISP's resolver?

Run the test

The test lives under the results on the home page, in "Your browser & connection" → "DNS leak". It only tests your own connection and is hidden when you look up someone else's IP.

What actually counts as a DNS leak

Before your browser loads a site, it asks a recursive resolver for the site's address. A VPN protects the traffic that follows; if the lookup still goes to your real ISP's resolver, your ISP learns which domains you visit, and the sites you visit can see who your real ISP is. That is a leak.

Many leak tests get this wrong:

How n0.wiki tests it

We run our own authoritative DNS server for dl.n0.wiki. The browser requests a few random one-time subdomains, so your recursive resolver has to ask our server, and we see two independent pieces of evidence:

  1. Who the resolver is: a known public resolver, the same network as your exit, a cloud or hosting network, or what looks like your real ISP's access network. Google Public DNS is recognised from Google's published prefix list, not reverse DNS or ASN alone (Google's resolver egress doesn't look like 8.8.8.8, and the same ASN also hosts Google Cloud).
  2. Whether the ECS subnet contains your exit. Some resolvers write the client's subnet (EDNS Client Subnet) into the query itself. If that subnet does not contain your exit address, the lookup came from another network. The resolver wrote this itself, so nothing is inferred. In our measurements Google sends ECS; Cloudflare and Quad9 do not.

What the verdicts mean

VerdictMeaning
No observationThe test did not run (for example it was blocked). This is not "no leak".
Not anonymizedThere is evidence you are connecting directly, so there is nothing to leak.
ConsistentResolver and exit are on the same network, usually the VPN's own DNS.
Public resolverA known public resolver, as expected.
UnclassifiedA third-party resolver we cannot identify. Not the same as safe.
Leak suspectedThe resolver looks like it belongs to your real ISP's access network.
Conditional leakIf you are on a VPN this is a leak, but we cannot confirm that you are anonymizing.

How to fix a DNS leak

Privacy

Test observations live in an in-memory store and are deleted automatically after 15 minutes. The one-time subdomains are random and not tied to any identity. See about & privacy.