Your VPN can hide your IP address on every website you visit and still let your ISP see the domain names behind that traffic. That gap is a DNS leak, and because DNS translates the address bar into a request an ISP can log — not the encrypted VPN tunnel — it can undo a large part of what the VPN was for.

What a DNS lookup normally does

Every time you visit a site, your device needs to turn a name like example.com into an IP address. That translation is a DNS query. On an unprotected connection, your operating system sends that query to whatever resolver your network handed it — almost always your ISP's own servers. A VPN is supposed to change this: once connected, DNS queries should route through the VPN's tunnel to a resolver the VPN controls, alongside your regular traffic.

Where the leak actually happens

A leak means that handoff didn't happen. Your regular web traffic goes through the encrypted tunnel — that part is fine — but the DNS queries slip out a different path, usually straight to the ISP's default resolver. Three things commonly cause this:

  • Operating-system "smart" DNS. Windows and some routers will query multiple resolvers at once and use whichever answers first, which can mean the ISP's resolver wins even with a VPN active.
  • IPv6 DNS servers the VPN doesn't touch. Many VPN clients only reconfigure IPv4 DNS settings. If your connection also has a working IPv6 path, IPv6 DNS queries can bypass the tunnel entirely.
  • Browser-level secure DNS. Chrome, Firefox and Edge can each be configured with their own DNS-over-HTTPS resolver, which overrides the system setting the VPN just changed — sometimes routing queries somewhere unexpected rather than fixing the leak.

What a leak actually exposes

DNS queries reveal every domain you look up — not the page content, but the destination itself, in order, with timestamps. To whoever handles the leaked query, that's a fairly complete picture of your browsing even if they can't see what happens once you're connected. It also reveals your real network location: a resolver that sits in your ISP's network (rather than the VPN's) is itself a signal that something isn't routed the way you think it is.

How to tell if you have one

The only reliable way is a live test, not guesswork: connect your VPN, then check which resolver is actually answering your DNS queries and compare its location and network owner against your VPN's exit IP. If they don't match — and especially if the resolver traces back to your ISP rather than your VPN provider — that's a leak. NetRiskScan's DNS Leak Test automates exactly this comparison; see How to Test for DNS Leaks for the full walkthrough.

FAQ

Does every VPN have this problem?

No. A properly configured VPN client routes DNS through its own tunnel by default. Leaks tend to show up with manually configured VPN protocols (like a raw WireGuard or OpenVPN config that doesn't set DNS), IPv6-unaware clients, or after an operating system update changes network defaults.

If my resolver is Cloudflare or Google, is that a leak?

Not necessarily. If you deliberately configured a public resolver like 1.1.1.1 or 8.8.8.8 — whether system-wide or through your VPN client — that's a routing choice, not a leak. It does mean that provider, rather than your ISP or VPN, can see your queries.

Can a leak happen even with a kill switch enabled?

Yes. A kill switch typically blocks non-tunneled traffic if the VPN disconnects — it doesn't necessarily catch a DNS query that was never routed through the tunnel in the first place, because to the operating system that query never looked like a policy violation.