DNS leak test

Observe the recursive servers that query our test domain from this browser. Compare the evidence with your expected DNS or VPN setup.

This DNS leak test requests unique names from our DNS zone. The observation service temporarily links those names with the recursive servers that contact it. Standard uses 6 names; extended uses 36 and allows about a minute. Nothing runs until you choose a test.

Checking test availability…

Make sense of your result

Run a DNS leak test with a clear expectation

A DNS leak test observes the recursive servers that ask our authoritative service about names created for this run. It helps you investigate whether those observations fit your intended network configuration. The result is evidence from one browser session, not a certificate that every application on your device follows the same route.

Before a DNS leak test, decide which resolver provider you expect. A VPN might supply its own resolver, forward requests to another company, or leave a browser's separately configured secure DNS service in place. Read the relevant settings and provider documentation before treating an unfamiliar address as a failure. Your expected policy is an essential part of the comparison.

Choose the standard DNS leak test for six unique names. The extended option uses thirty-six names to give resolver pools more opportunities to appear. More queries improve sampling opportunities but cannot guarantee discovery of every possible server. The distinction follows a familiar testing pattern described by DNSLeakTest; MyIP.dog runs its own observation service and reports its own measurements.

Keep the connection stable during the DNS leak test. Standard collection allows fifteen seconds after the session is created; extended collection allows forty. Starting, reading and clearing the session add bounded network waits, so allow roughly half a minute for standard and a minute for extended. Stop is available while a run is active. Changing networks halfway through makes the evidence harder to interpret.

The DNS leak test makes up to six browser requests concurrently. Each name is unique to the session, which reduces reuse of a previously cached answer. Requests carry no application cookies to the probe endpoint and omit the page referrer. Browser policy, extensions and network filtering may still prevent some requests, so the report keeps attempted names separate from observed names.

Understand the DNS leak test results

The DNS leak test shows three counts: names attempted by the browser, names observed by the authoritative server, and distinct resolver addresses recorded. These values describe different stages. A browser can attempt a name without a query reaching our service. Conversely, a resolver query can arrive even when the subsequent HTTPS connection fails.

An all-names-observed DNS leak test means every issued name appeared in the available authoritative observations. It does not mean every DNS provider worldwide was checked, every server in a pool appeared, or the observed route meets your privacy policy. The summary deliberately avoids assigning a universal safe or unsafe verdict.

A partial DNS leak test has some observations but incomplete name coverage, or has reached the bounded observation limit. Read the available addresses, then repeat under stable conditions if you need a clearer sample. Do not silently combine several incomplete runs into one apparently complete report; each run has its own names, time window and network conditions.

An empty DNS leak test provides no readable resolver evidence within the collection window. Possible explanations include filtered requests, a failed network path, browser restrictions or service problems. An empty table cannot establish that your DNS traffic is protected. An error or stopped run also remains incomplete even when earlier observations are shown.

Resolver details in a DNS leak test

Each DNS leak test row includes an observed resolver address, query count, record types, and first and last observation times. Addresses come from the DNS socket peer seen by our authoritative service. This is usually an outward-facing recursive layer; it need not equal the address entered in your router or operating system.

The DNS leak test groups repeated queries from the same normalized address. Counts can exceed the number of unique names because a resolver may ask for A, AAAA or HTTPS-related information, retry a query, or use different transports. Several rows can belong to the same provider. One row does not establish that only one server participated internally.

The UDP or TCP value in a DNS leak test describes the final DNS transport to our server. It does not reveal whether your browser communicated with its resolver over HTTPS, TLS, a VPN tunnel or ordinary DNS. RFC 8484 defines DNS over HTTPS for the client-to-resolver exchange; observing a later hop cannot reconstruct that earlier exchange.

For a DNS leak test address you do not recognize, use ASN lookup to inspect routing context and IP WHOIS lookup for registration information. Neither tool identifies a subscriber or proves a resolver's operating policy. This page does not manufacture a company name or country when no verified enrichment has been performed.

What a DNS leak test cannot prove

The DNS leak test observes requests associated with this browser's unique names. A mail client, game, operating-system service or another browser may use a different resolver path. Managed settings, split tunneling and proxy behavior can create legitimate differences. One successful browser test cannot establish device-wide routing coverage.

An unexpected country in another DNS leak test is not sufficient evidence of leakage. IP location is an estimate, and resolver services can use distributed infrastructure or anycast. Ownership, location and expected routing are separate questions. Our IP location guide explains why a displayed city should not be treated as a precise observation.

A DNS leak test also cannot prove that a resolver keeps no logs, validates every DNSSEC response, blocks malicious domains or prevents all tracking. Those are different claims requiring different evidence. The absence of a familiar ISP name is not proof of anonymity, and the presence of a public resolver company does not automatically indicate a VPN failure.

Compare the DNS leak test with the WebRTC test and IPv6 test when investigating a specific connection. Each measures a different mechanism. Keep the results separate and record when they were collected. A matching HTTP address does not tell you which recursive server handled a DNS request.

Investigate an unexpected DNS leak test result

First repeat the DNS leak test without changing settings. Note the browser, connection type, VPN mode and time. Check whether the same unfamiliar network returns. A repeatable observation is more useful to support than a screenshot without context, especially when a large provider uses many outward-facing resolver addresses.

Next compare the DNS leak test with your documented configuration. A browser's secure DNS setting may differ from the system resolver. A VPN extension may cover less traffic than a system client. An employer may intentionally route selected traffic through managed services. Confirm which behavior is expected before changing settings that other applications depend on.

If you intentionally change a setting, run a new DNS leak test and compare the separate reports. Explain which provider you expected and which address appeared instead. Avoid publishing account details or a full network history. The IP privacy guide helps distinguish useful troubleshooting evidence from unnecessary disclosure.

DNS leak test privacy and session lifetime

The DNS leak test requires temporary server-side observation. The service links random test names with resolver addresses and query metadata for a session lasting at most two minutes. The application attempts to delete that session after completion, cancellation or leaving the page. If deletion cannot be confirmed, expiry provides the fallback; expired sessions are no longer readable and are periodically removed from memory.

Your DNS leak test report remains in this tab until you clear it or leave. Copying a report is an explicit action and includes the observed addresses and times. It excludes the session's read token and the service's authentication secret. Clipboard copies are outside the tab's control, so review a report before sending or posting it.

The DNS leak test retention window describes the observation session, not a promise that every hosting, network or resolver provider keeps no operational logs. Those systems process their own requests. This tool cannot inspect their retention practices. It collects no browsing history and does not require a microphone, camera, account or remote-control permission.

DNS leak test questions

Why can several resolvers appear?

A DNS leak test can expose a resolver pool, forwarding chain or requests made through more than one permitted path. A configured service address is not necessarily the address it uses when contacting authoritative servers. Investigate ownership and expected behavior before deciding that an additional row is unwanted.

Why do HTTPS responses and DNS observations differ?

The DNS leak test records them independently. Name resolution happens before the browser can complete the connection, so a TLS failure can leave valid DNS evidence. A cached or intercepted answer can affect the opposite direction. The authoritative count is the measurement used for name coverage; an HTTP response never adds a resolver row.

Will extended mode always find more servers?

No. The extended DNS leak test issues more unique names, but a stable resolver pool may return the same addresses throughout. More names provide a broader sample within this run, not a guarantee of more rows. Stop when you have enough evidence for your actual troubleshooting question.

Why is the test unavailable?

The DNS leak test depends on a working observation service, delegated DNS zone and HTTPS endpoints. When the application cannot offer that service, the controls remain unavailable. The explanation stays readable, and no fabricated result is substituted. Retry later; an unavailable measurement says nothing about your connection's privacy.

Can a normal DNS lookup replace this test?

No. A DNS lookup asks a named resolver for records through our application server. A DNS leak test instead triggers fresh names from your browser and observes which recursive servers contact the authority. The two tools answer different questions, even when both display DNS-related addresses.