What Is DNS?
DNS is a distributed naming system, not a single lookup table — understanding the distributed part explains why lookups involve multiple servers and why DNS behavior can differ between networks.
Practical DNS guides covering resolvers, leaks, encrypted DNS, caches, authoritative servers, and VPN behavior.
DNS is a distributed naming system, not a single lookup table — understanding the distributed part explains why lookups involve multiple servers and why DNS behavior can differ between networks.
A single DNS lookup passes through several distinct layers — browser cache, OS cache, recursive resolver, and often root/TLD/authoritative servers — and knowing which layer answered a given query matters for diagnosing DNS behavior.
A DNS leak sends your domain lookups outside your VPN's tunnel, usually straight to your ISP's resolver, even while your regular traffic looks protected. Here's what actually happens and why it matters.
A reliable DNS leak test compares the resolver actually handling your queries against your VPN's exit IP — here's the method, step by step, and how to read an ambiguous result.
The most common causes of a VPN DNS leak are OS-level smart DNS, unprotected IPv6 resolvers, and browser secure-DNS overrides — each with a specific, checkable fix.
DNS visibility spans your device, local network, ISP, resolver, VPN provider and the domain's own authoritative operators — mapping who can see what at each layer is more useful than treating DNS privacy as one binary question.
Public DNS resolvers trade the convenience of your ISP's default for potential gains in speed, privacy policy, and encryption support — with tradeoffs in filtering behavior and jurisdiction worth weighing.
Your ISP's default DNS resolver is convenient and often fast for local content, but comes with a logging and filtering policy you may never have reviewed — worth checking against the alternatives.
DNS over HTTPS encrypts the trip to your resolver by disguising DNS traffic as ordinary web traffic — it protects query content in transit, but the resolver itself, and everything after the DNS step, remain visible as before.
DNS over TLS uses a dedicated port for encrypted DNS traffic rather than disguising it as web traffic — a different deployment model than DNS over HTTPS with its own tradeoffs.
Cloudflare's 1.1.1.1 resolver is straightforward to set up and supports encrypted DNS modes — worth pairing any switch with a direct check that the new resolver is actually active.
Google Public DNS (8.8.8.8) offers broad protocol support and strong infrastructure — evaluate it, as with any resolver, on its actual published privacy policy rather than general brand reputation.