Try for $3.50

DNS Leak Test

Run a free browser-based DNS leak test for VPN and proxy connections. See which resolvers answer your requests and check for signs of unexpected DNS exposure

6 or 18 DNS test queries
Resolver IP, provider, ASN, location and type
No signup, browser-based results in seconds

Check your connection for DNS leaks

See which DNS resolvers answer your browser’s requests. Choose a standard 6-query check or an extended 18-query test to view each resolver’s IP, provider, ASN, country, and type.

Your connection (HTTP)

IP address
Detecting on live endpoint
ISP
Waiting for test
Location
Waiting for test
Reverse DNS
Waiting for test

Your DNS servers

Choose a mode and start the test. No signup required.

What is a DNS leak?

A DNS leak happens when DNS requests are handled by a resolver outside the VPN or proxy setup you intended to use. As a result, your ISP or another DNS provider may see the domain names your device looks up, even when websites see your VPN or proxy IP instead of your original address.

The test on this page sends DNS queries from your browser and reports which resolvers answer, including their IP address, provider, ASN, country, and resolver type. Compare these results with the DNS resolver expected for your VPN, proxy, browser, or network configuration.

Seeing a resolver operated by your real ISP can indicate a DNS leak. However, an unfamiliar provider or a resolver in another country does not prove a leak by itself, especially when public DNS services are used.

DNS Leak Test

Do proxies leak DNS?

Proxy DNS leaks depend mainly on how your browser, application, or automation tool resolves hostnames.

Some clients resolve domains locally, while others pass them to the proxy for remote resolution

Connection setup
DNS leak risk
What it means
HTTP/HTTPS proxy
Depends on the client
Many clients pass the hostname to the proxy, but browser DNS prefetching, DoH, extensions, or proxy bypass rules may still create DNS requests outside the proxy route
SOCKS5 with local DNS
Higher
The connection uses the proxy, but your device resolves the destination hostname through its configured DNS resolver
SOCKS5 with remote DNS
Lower
The client passes the hostname to the proxy for resolution. In curl and compatible clients, this is commonly enabled with socks5h://
Browser proxy profile
Depends on browser settings
Check the browser’s proxy DNS, secure DNS, extensions, and bypass settings. Test WebRTC exposure separately
Automation tools
Depends on client configuration
Browser engines and HTTP libraries handle proxy DNS differently. Enable remote DNS where supported and verify the setup with a DNS leak test

What causes a DNS leak

A DNS leak happens when DNS requests bypass the VPN or proxy route you intended to use.

It is usually caused by browser, application, operating-system, or tunnel settings

01
Local DNS resolution
The browser or application resolves hostnames using the device’s DNS settings instead of passing them through the intended proxy or VPN route
02
Secure DNS outside the route
Browser-based DoH may contact a public resolver directly instead of following the intended VPN or proxy configuration
03
IPv6 bypass
The setup protects IPv4 traffic but allows IPv6 DNS requests or connections to use the device’s normal network interface
04
SOCKS5 with local DNS
Some SOCKS5 clients resolve hostnames locally. In curl-compatible clients, socks5h:// passes the hostname to the proxy
05
Split-tunneling misconfiguration
Apps or domains excluded from a VPN tunnel may also send their DNS requests through the default network connection
06
VPN connection fallback
If a VPN disconnects without a kill switch, traffic and DNS requests may return to the device’s normal connection

How to fix a DNS leak

  • Enable remote DNS in your browser or application. With curl and compatible clients, use socks5h:// so the proxy resolves hostnames instead of your device.
  • For HTTP and SOCKS5 proxies, check whether your browser or automation tool supports proxy-side DNS resolution.
  • If you use a VPN, enable its DNS leak protection and kill switch to prevent traffic from escaping when the tunnel disconnects.
  • Make sure IPv6 follows the protected connection. Disable IPv6 only when your VPN or proxy setup cannot route it safely.
  • If you use encrypted DNS, confirm that DoH or DoT traffic follows the intended VPN or proxy route. Encryption alone does not prevent routing leaks.
  • Run the DNS leak test again. Your real ISP’s DNS resolver should no longer appear, although public resolver locations may differ from your proxy location.
DNS Leak Test

Dangers of a DNS leak

  • Browsing-history exposure. Your ISP can record and sell a list of every domain you visit.
  • Location de-anonymisation. The resolver location reveals your country and ISP.
  • MITM and DNS spoofing. Unencrypted DNS queries can be intercepted or poisoned.
  • Censorship and content filtering. A leak means you are still subject to DNS-layer blocks.
  • Ad tracking and profiling. Third-party resolvers can log queries and sell behavioural data.
  • Account-correlation risk. For automation and multi-account work, one leak can link sessions to a single real IP.
IP Lookup Tool

DNS leak test vs IP leak test vs WebRTC leak test

Leak type
What is exposed
How to test
Common cause
DNS leak
List of domains you visit
DNS Leak Test
OS resolver bypassing tunnel
IP leak
Your real public IP
IP Lookup
Proxy/VPN disconnection, split tunneling
WebRTC leak
Real public and local IP via browser API
Browser WebRTC enabled without proxy override
Proxy connection or usage issue
Check whether the proxy works, returns the correct location, and how much bandwidth each request uses
Dead proxy, authentication failure, blocked port, or unexpectedly large data transfers

Use NodeMaven proxies with the right DNS setup

Step 1

Choose residential, mobile, or ISP proxies for your workflow

Choose residential, mobile, or ISP proxies for your workflow

Step 2

Configure remote DNS in your browser or client where supported

Configure remote DNS in your browser or client where supported
Access residential and mobile proxies across 190+ countries with country, city, ISP, and ZIP targeting
Access residential and mobile proxies across 190+ countries with country, city, ISP, and ZIP targeting
Use pre-screened proxy IPs to reduce blocks and unstable sessions
Use pre-screened proxy IPs to reduce blocks and unstable sessions
Rotate residential or mobile IPs, use sticky sessions, or choose static ISP IPs for long-term consistency
Rotate residential or mobile IPs, use sticky sessions, or choose static ISP IPs for long-term consistency

Choose the right NodeMaven proxy for your workflow

Compare proxy types by IP source, session model, targeting, and traffic needs. All support HTTP and SOCKS5, while remote DNS must be configured separately in your browser or client

Residential Proxies

Residential Proxies

Real household high-quality IPs trusted by websites, supported by a quality filter and 99.4% business success rates.

Recommended for:
Mobile Proxies

Mobile Proxies

Real 5G/4G/LTE IPs for mobile-first workflows, social platforms, CPA, crypto, and e-commerce

Recommended for:
ISP proxies

ISP proxies

Static residential IPs with fast response times, long sessions, and unlimited traffic. Best for stable identity and always-on workflows

Recommended for:
Not sure which proxy type to choose?

Start your proxy trial for $3.50 and test 750MB with your browser setup

Start your proxy trial for $3.50 and test 750MB with your browser setup

Frequently asked questions

A DNS leak test checks which DNS resolvers answer your browser’s DNS requests. If the resolvers are outside your VPN or proxy route, your DNS may be leaking.

The tool sends DNS queries from your current browser setup and shows the resolver IP, ISP, ASN, country, and resolver type. You can run a standard or extended test.

 

You may have a DNS leak if the test shows DNS resolvers from your local ISP, router, or another unexpected provider while you are using a VPN or proxy.

Proxy DNS leaks usually happen because of browser, app, or automation tool settings, not because of proxy IP quality. If your tool sends traffic through a proxy but resolves domains locally, your DNS resolver may still see the domains you visit.

 

Use a setup that sends DNS through the proxy route, such as socks5h://, HTTP CONNECT where supported, or remote DNS settings in your browser or automation tool.

Local DNS means your device or network resolves domains before the proxy is used. Remote DNS means the domain lookup follows the proxy route, reducing local DNS exposure.

 

It can help check VPN DNS exposure, but it focuses specifically on DNS resolvers. For a full VPN check, also test your public IP and WebRTC exposure.

NodeMaven supports HTTP and SOCKS5 proxy setups that can work with remote DNS, but DNS leak protection also depends on how your browser, app, or automation tool is configured.

This site uses cookies to enhance your experience. By continuing, you agree to our use of cookies.