New. DNS Leak Test. Is your VPN really hiding your DNS? Find out in seconds.
Find every DNS server your connection is really using, and whether any of them leak your network via EDNS Client Subnet.
Ready to test
We run the lookup 25 times to reveal every DNS server your connection rotates through.
A single check only shows one DNS server. But your connection often spreads lookups across a whole pool of them. This test is powered by edns.upset.dev and repeats the check many times so you can see every DNS server answering for you, catch unexpected ones, and spot any that share part of your network with the sites you visit.
The test runs in three steps.
Start the test and we run a lookup many times in a row, straight from your browser.
Each lookup uses a fresh address, so we see whichever DNS server answers. Repeating it reveals the whole pool your connection rotates through.
You get every DNS server we caught, how often each one answered, and whether any leaked part of your network.
A DNS leak happens when your DNS lookups go to a server you did not expect, often your ISP instead of the private resolver your VPN or custom DNS is supposed to use. That can expose which sites you visit.
Large providers run pools of servers behind a single address. Running the lookup many times lets us catch the different servers your connection actually uses, instead of just the first one.
EDNS Client Subnet. When a DNS server forwards it, part of your network address is shared with the websites you visit so they can route you to a nearby server. It is convenient, but it gives away roughly where you are.
Use a trusted resolver over an encrypted protocol like DoH or DoT, and make sure your VPN routes DNS through its own tunnel. Then run the test again to confirm only the servers you expect show up.