DNS leak test and how to prevent DNS leaks with a VPN
A DNS leak happens when your VPN is connected but the lookups that turn website names into IP addresses still go to your internet provider instead of through the encrypted tunnel. Your traffic is hidden, but the list of sites you visit is not.
This guide covers how DNS leaks happen, how to run a DNS leak test, and how to prevent DNS leaks on every device you use.
What is a DNS leak?
Every time you open a website, your device first asks a DNS (Domain Name System) resolver for the IP address behind the name, for example eonvpn.com. By default, that resolver is run by your internet service provider (ISP) and is handed to your device by your router.
When you connect to a VPN, those lookups should travel inside the VPN tunnel and be answered by a resolver on the VPN side. A DNS leak is any case where lookups escape the tunnel and reach your ISP’s resolver, or another resolver on your local network, in plain text.
A leak matters for two reasons:
- Your browsing history is exposed. Plain DNS is not encrypted, so whoever runs the resolver, and anyone on the path to it, can see every domain you look up and when. That usually means your ISP, which is exactly who you may be trying to hide your searches from.
- Your location can be inferred. Leaked lookups come from your real network, so a website or service that checks which resolver asked for its address can see a resolver in your home country even when your VPN server is somewhere else.
A DNS leak does not reveal the content of the pages you load. It reveals the domain names, which is often enough to build a detailed picture of your activity.
How DNS leaks happen
The operating system falls back to another resolver
Your device can have several network adapters at once, including the virtual one the VPN creates. If the VPN adapter does not take priority, the operating system may send lookups to the DNS server on your normal adapter. Windows makes this more likely with a feature called Smart Multi-Homed Name Resolution, which can send a query to the DNS servers on every adapter at the same time and use whichever answers first. The request to your ISP’s server leaves outside the tunnel.
IPv6 traffic skips the tunnel
Many connections now have both IPv4 and IPv6 addresses. If a VPN only routes IPv4, any request made over IPv6, including DNS lookups to an IPv6 resolver, can go straight out through your normal connection. This is called an IPv6 leak, and it can expose both your DNS queries and your real IPv6 address.
Manual DNS settings and ISP interception
If you set a DNS server manually on your adapter, some VPN apps do not override it. Separately, some ISPs use a transparent DNS proxy: they intercept any request on DNS port 53 and answer it with their own resolver, even if you picked a different public DNS server. A leak test will then show your ISP’s servers no matter what you typed into your settings.
The VPN drops for a moment
When a VPN reconnects, switches networks or crashes, your device falls back to the normal connection. Any lookups made during that gap go to your ISP. This is the case a VPN kill switch is designed to cover.
WebRTC is not a DNS leak
WebRTC is a browser technology used for video calls and peer to peer connections. It can reveal your real IP address to a website through the browser, which is a different problem from a DNS leak. It is fixed in the browser, not in your DNS settings. You can check it at browserleaks.com/webrtc. In Firefox you can turn WebRTC off by setting media.peerconnection.enabled to false in about:config, which will also stop browser based video calls from working.
How to run a DNS leak test
A DNS leak test makes your browser look up a set of unique, random hostnames and then reports which resolvers asked the test site’s name servers for them. Because the hostnames are new, the answer cannot come from a cache, so you see the resolvers your device really uses.

- Disconnect your VPN and open dnsleaktest.com. Run the Extended test and note the servers and ISP names in the results.
- Connect your VPN and choose a server in another country.
- Run the Extended test again.
- Repeat the check on browserleaks.com/dns to confirm the result with a second tool.
- Check your visible IP address with the EonVPN IP lookup to make sure it shows the VPN server, not your home connection.
How to read the result
- No leak: every server in the list belongs to your VPN provider or to a DNS provider the VPN uses, and none of them carry your ISP’s name.
- Leak: one or more servers belong to your ISP, or are in your real location, while the VPN is connected. Even one ISP server means some lookups are escaping the tunnel.
- Public resolver instead of VPN resolver: if you see Google, Cloudflare or Quad9 servers, your device or browser is configured to use them. Your ISP cannot read those lookups if they travel through the tunnel or over encrypted DNS, but they are not handled by your VPN either, so decide whether that is what you want.
Run the test on each device and each browser you use. A clean result on your laptop says nothing about your phone.
How to prevent DNS leaks on Windows
Windows is where most DNS leaks are reported, because of the resolver fallback described above.
- Connect the VPN before anything else. Start the VPN, then open your browser and apps, so their first lookups go through the tunnel.
- Flush the DNS cache after connecting. Open Command Prompt and run
ipconfig /flushdns. This clears old answers that were resolved before the VPN was on. - Remove manual DNS on your normal adapter. In Windows 11 go to Settings, Network and internet, choose Wi-Fi or Ethernet, open your connection and set DNS server assignment to Automatic (DHCP). In Windows 10 go to Control Panel, Network and Sharing Center, Change adapter settings, right click your adapter, choose Properties, then Internet Protocol Version 4 (TCP/IPv4), and select Obtain DNS server address automatically. Your VPN can then set its own DNS on its adapter.
- Turn off Smart Multi-Homed Name Resolution. On Windows Pro, Enterprise and Education, open the Local Group Policy Editor (
gpedit.msc), go to Computer Configuration, Administrative Templates, Network, DNS Client, and set Turn off smart multi-homed name resolution to Enabled. Windows Home does not include this editor. - Deal with IPv6. If your VPN does not route IPv6, open the adapter Properties window from step 3 and untick Internet Protocol Version 6 (TCP/IPv6) on your normal adapter. Turn it back on if a local network feature stops working.
- Run the leak test again to confirm the ISP servers are gone.
If you use the free EonVPN app for Windows, follow the same order: connect to a server first, flush the cache, then run the test.
How to prevent DNS leaks on macOS
- Check for manual DNS servers. Open System Settings, Network, select Wi-Fi or Ethernet, click Details and open the DNS tab. If you see servers you added yourself, remove them with the minus button unless you want them, so the VPN can supply its own.
- Flush the DNS cache after connecting. Open Terminal and run
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder. - Check IPv6. In the same Details window, open the TCP/IP tab. If your VPN does not handle IPv6 and your leak test shows an IPv6 address from your ISP, set Configure IPv6 to Link-local only.
- Retest with both leak test sites.
How to prevent DNS leaks on Android
Android has two built in settings that help a great deal.
- Always-on VPN with blocking. Go to Settings, Network and internet, VPN, tap the gear icon next to your VPN app, and turn on Always-on VPN and Block connections without VPN. Android will then refuse to send traffic, including DNS lookups, when the VPN is not connected. Menu names vary by phone maker.
- Private DNS. Android 9 and later can encrypt DNS with DNS over TLS. Go to Settings, Network and internet, Private DNS, choose Private DNS provider hostname and enter a provider such as
dns.google,one.one.one.oneordns.quad9.net. This protects your lookups from your ISP when the VPN is off. - Retest in the browser you actually use on the phone, on both Wi-Fi and mobile data.
How to prevent DNS leaks on iOS
iPhone and iPad give you fewer controls, so order matters.
- Connect the VPN first, then open apps. Connections that were already open before the VPN started may keep using the normal network until they are closed. After connecting, close and reopen the apps you care about.
- Remove manual DNS on Wi-Fi. Go to Settings, Wi-Fi, tap the info button next to your network, tap Configure DNS and set it to Automatic unless you added servers on purpose.
- Retest in Safari and in any other browser you use.
Turn on secure DNS in your browser
Browsers can send DNS lookups over HTTPS (DoH), which encrypts them so your ISP cannot read them. This is a useful second layer and helps when the VPN is off.
- Chrome: Settings, Privacy and security, Security, turn on Use secure DNS and pick a provider.
- Edge: Settings, Privacy, search, and services, then the Security section, turn on Use secure DNS and choose a provider.
- Firefox: Settings, Privacy and Security, scroll to DNS over HTTPS and choose Increased Protection or Max Protection, then select a provider.
- Brave: Settings, Privacy and security, Security, turn on Use secure DNS.
Browser DoH only covers that browser; other apps still use the system resolver. With DoH on, a leak test in that browser shows the DoH provider’s servers rather than your VPN’s. That is not a leak to your ISP, but your DNS provider, not your VPN, sees the domains you visit.
Set DNS at the router level
Router DNS covers every device on your network, including smart TVs and consoles that cannot run a VPN app.
- Open your router’s admin page, usually at an address like
192.168.0.1or192.168.1.1, and sign in. - Find the DNS fields in the Internet, WAN or DHCP section.
- Replace the ISP servers with a public resolver you trust. Our guide to the best DNS servers for gaming compares Cloudflare, Google, Quad9 and others on speed and filtering.
- Restart your devices or reconnect them to Wi-Fi so they pick up the new settings.
Router DNS is a fallback, not a replacement for VPN DNS: plain lookups on port 53 are still unencrypted and can still be intercepted. If a site stops loading after the change, our guide to fixing DNS server not responding walks through the checks.
VPN features that stop DNS leaks
These are the VPN settings that decide whether your DNS stays private:
- DNS leak protection. The app forces all lookups through the tunnel and blocks DNS requests to other servers while it is connected.
- Its own DNS servers. A VPN that runs its own resolvers answers your lookups inside the tunnel, so no third party DNS provider sees them.
- IPv6 handling. The app should either route IPv6 through the tunnel or block it while connected.
- Kill switch. It blocks all traffic if the VPN connection drops, which closes the gap where lookups fall back to your ISP.
EonVPN is a free VPN for Windows that encrypts your traffic and follows a no-logs policy, with 40+ servers across 8+ countries. How DNS is handled while connected is set on the provider’s servers, so whichever VPN you use, run the leak test below after connecting, because the result on your own device is what counts.
DNS leak troubleshooting
If a test still shows your ISP’s servers while the VPN is connected, work through these checks in order:
- Flush the DNS cache and retest in a fresh browser window.
- Switch VPN server. If only one server leaks, report it to the provider.
- Update the VPN app and your operating system.
- Disconnect other VPNs, proxies and security tools. A second VPN, a corporate VPN or an antivirus with web filtering can add its own adapter and DNS settings.
- Check for IPv6. If the leak test shows an IPv6 address from your ISP, follow the IPv6 step for your system above.
- Test on a different network. If the leak disappears on mobile data or another Wi-Fi, your router or ISP is likely intercepting DNS. Change the router DNS and test again.
- Rule out WebRTC. If a site sees your real IP address but the DNS test is clean, the cause is probably WebRTC, not DNS.
- Contact support with a screenshot of the result. EonVPN users can reach the team through the contact page.
Conclusion
A DNS leak lets your ISP see the sites you visit even while a VPN is on. Connect the VPN first, remove manual DNS from your normal adapter, handle IPv6, and on Windows turn off the behaviour that queries every adapter at once. Add secure DNS in your browser and phone, set a better resolver on your router, then run a DNS leak test on every device and repeat it after updates or network changes.
If you are on Windows and want a free VPN to test with, download EonVPN, connect to a server and run the leak test from this guide.
FAQs
How do I know if I have a DNS leak?
Connect your VPN and run the extended test on dnsleaktest.com or the test on browserleaks.com/dns. If any listed server belongs to your ISP or sits in your real location, you have a DNS leak.
Does a VPN prevent DNS leaks?
A VPN prevents DNS leaks only if it routes your lookups through the tunnel and your device does not fall back to another resolver. Settings such as DNS leak protection, IPv6 handling and a kill switch make this far more reliable, but you should still confirm it with a leak test.
Is a DNS leak dangerous?
A DNS leak does not give anyone access to your device or accounts. It does expose the domain names you visit to your ISP or network operator, and it can reveal your real location to services that check which resolver made the request.
Can changing my DNS server stop a DNS leak?
Not on its own. Using Cloudflare, Google or Quad9 instead of your ISP changes who answers your lookups, but plain DNS is still unencrypted and can still be intercepted by your ISP. Combine it with a VPN or with encrypted DNS such as DoH or DNS over TLS.
Is a WebRTC leak the same as a DNS leak?
No. A WebRTC leak exposes your IP address through the browser, while a DNS leak exposes the domain names you look up. They need different fixes, so test for both.

