DNS Leak Test
See which resolvers
your system actually uses.
Not the ones in your settings. Not the ones you think. The real ones your browser contacted.
No ads
No trackers
No logs
$ ipdia dns-leak
test 5 unique subdomains → each resolves independently
method DNS via
tags → real resolver path
endpoint POST /dns/leaktest
# press Run leak test to begin…
_
DNS leaks are relative to your setup.
A DNS leak result is not an absolute verdict — it depends entirely on what your expected DNS path is. The test shows you which resolvers your system actually contacted. Whether that's a problem depends on you.
If you're on a VPN or proxy and the results show resolver IPs belonging to your ISP's range, your DNS queries are bypassing the tunnel. That means your ISP can see every domain you query.
The expected resolver varies by setup. There is no universal correct answer — it's whatever is part of your intentional privacy stack.
Expected resolver — examples
✓ Your VPN provider's DNS servers
✓ NextDNS / AdGuard DNS
✓ Self-hosted resolver (Pi-hole, Unbound…)
✓ Any resolver inside your tunnel
✗ Your ISP's resolver while on VPN
✗ 8.8.8.8 / 1.1.1.1 outside the tunnel
✗ Unknown resolver you didn't configure
// seeing ISP resolvers on VPN = leak