IPv6 and DNS intersect in a way that's worth untangling carefully — the type of record involved, the transport used to fetch it, and whether the resulting address is actually reachable are three separate, independent questions.

AAAA records: the IPv6 answer type

Where a domain's IPv4 address is stored as an A record, its IPv6 address (if it has one) is stored as an AAAA record. A domain can have both simultaneously — this is exactly what enables dual-stack connectivity, letting a dual-stack client choose which protocol to actually use for a given connection.

The transport question: how the query itself travels

Separately from what record type you're requesting, the DNS query itself can travel over IPv4 or IPv6 network transport, and can use plaintext or an encrypted protocol like DNS over HTTPS (see DNS over HTTPS). Which transport carries the query is unrelated to which record type (A vs. AAAA) is being requested — a resolver reachable only over IPv4 can still return AAAA answers just fine.

Why this distinction matters for leak testing

A common point of confusion: getting an AAAA answer back doesn't by itself confirm your device has genuine, working IPv6 connectivity to actually use that address — it only confirms the domain has an IPv6 address on record. Testing actual IPv6 reachability (as NetRiskScan's IPv6 Leak Test does) is a separate, more meaningful check than simply confirming AAAA records resolve.

FAQ

If my DNS returns AAAA records, does that mean I have IPv6?

Not necessarily — it means the domain you looked up has an IPv6 address on file; your own connection's ability to actually reach it is a separate question, confirmed only by a direct connectivity test.