Testing for a DNS leak isn't about staring at a settings screen — it's about generating a real DNS query while your VPN is connected and checking who actually answered it. Here's the method and how to read what comes back.

The core idea

A trustworthy DNS leak test needs two independent pieces of information collected at the same moment: which public IP address your regular web traffic is using (your VPN's exit IP, if it's working), and which resolver — by IP, network owner, and country — answered a DNS lookup from your device during that same session. If those two don't plausibly belong to the same network, DNS is taking a different path than your web traffic.

Step by step

  1. Connect your VPN first. Testing before connecting only tells you your baseline, unprotected state.
  2. Trigger a fresh DNS query. Popular domains can be answered from a cached record without ever reaching a live resolver, which tells you nothing. A test needs to generate a query for a name that's guaranteed not to be cached — a unique, single-use hostname is the reliable way to do this, which is what an automated tool is for.
  3. Record which resolver answered. Capture its IP address, the organization it belongs to, and its country.
  4. Compare against your exit IP. Check the country and network owner of the public IP your connection is using for ordinary HTTP traffic at the same moment.
  5. Repeat disconnected. Running the same test with the VPN off gives you a baseline to compare against, and confirms the tool itself is working.

Doing this with NetRiskScan

The DNS Leak Test automates the fresh-query step by generating a unique hostname per session, so a cached answer can't produce a false pass. It reports the resolver's IP, ASN and country next to your exit IP's, and flags a likely leak when they diverge and your exit IP looks like a VPN, proxy or hosting connection.

Reading an ambiguous result

Two outcomes are not leaks even though they can look concerning at first glance:

  • A public resolver like 1.1.1.1 or 8.8.8.8 answers. That's a deliberate configuration, not a bypass — though it does mean that provider sees your queries instead of your VPN.
  • The country matches but the ASN name looks unfamiliar. Large VPN providers often route DNS through infrastructure registered under a different corporate name than their consumer brand. Country and general network category matching is a stronger signal than an exact company name matching.

A genuine leak looks like this: your exit IP is clearly a VPN or proxy in one country, and the resolver that answered your query belongs to a residential ISP in a different country — typically the country you're actually in.

FAQ

Do I need to test on every device?

Yes, if you care about all of them. DNS settings are per-device (and sometimes per-browser, if a browser has its own secure DNS override), so a clean result on your laptop says nothing about your phone or a second browser profile.

What if the test times out instead of returning a resolver?

That usually means the DNS query never left your device in a form the test could observe — often a network that blocks the test's DNS traffic outright, or a very restrictive firewall. It's a different result from "no leak," and worth re-running on a different network to isolate the cause.

How often should I retest?

After any VPN client update, operating system update, or network change. Any of the three can silently reset DNS settings back to a system default.