Testing for a DNS leak isn't about staring at a settings screen — it's about generating a real DNS query while your VPN is connected and checking who actually answered it. Here's the method and how to read what comes back.
The core idea
A trustworthy DNS leak test needs two independent pieces of information collected at the same moment: which public IP address your regular web traffic is using (your VPN's exit IP, if it's working), and which resolver — by IP, network owner, and country — answered a DNS lookup from your device during that same session. If those two don't plausibly belong to the same network, DNS is taking a different path than your web traffic.
Step by step
- Connect your VPN first. Testing before connecting only tells you your baseline, unprotected state.
- Trigger a fresh DNS query. Popular domains can be answered from a cached record without ever reaching a live resolver, which tells you nothing. A test needs to generate a query for a name that's guaranteed not to be cached — a unique, single-use hostname is the reliable way to do this, which is what an automated tool is for.
- Record which resolver answered. Capture its IP address, the organization it belongs to, and its country.
- Compare against your exit IP. Check the country and network owner of the public IP your connection is using for ordinary HTTP traffic at the same moment.
- Repeat disconnected. Running the same test with the VPN off gives you a baseline to compare against, and confirms the tool itself is working.
Doing this with NetRiskScan
The DNS Leak Test automates the fresh-query step by generating a unique hostname per session, so a cached answer can't produce a false pass. It reports the resolver's IP, ASN and country next to your exit IP's, and flags a likely leak when they diverge and your exit IP looks like a VPN, proxy or hosting connection.
Reading an ambiguous result
Two outcomes are not leaks even though they can look concerning at first glance:
- A public resolver like 1.1.1.1 or 8.8.8.8 answers. That's a deliberate configuration, not a bypass — though it does mean that provider sees your queries instead of your VPN.
- The country matches but the ASN name looks unfamiliar. Large VPN providers often route DNS through infrastructure registered under a different corporate name than their consumer brand. Country and general network category matching is a stronger signal than an exact company name matching.
A genuine leak looks like this: your exit IP is clearly a VPN or proxy in one country, and the resolver that answered your query belongs to a residential ISP in a different country — typically the country you're actually in.
FAQ
Do I need to test on every device?
Yes, if you care about all of them. DNS settings are per-device (and sometimes per-browser, if a browser has its own secure DNS override), so a clean result on your laptop says nothing about your phone or a second browser profile.
What if the test times out instead of returning a resolver?
That usually means the DNS query never left your device in a form the test could observe — often a network that blocks the test's DNS traffic outright, or a very restrictive firewall. It's a different result from "no leak," and worth re-running on a different network to isolate the cause.
How often should I retest?
After any VPN client update, operating system update, or network change. Any of the three can silently reset DNS settings back to a system default.