A VPN DNS leak has a short list of usual suspects. Working through them in order, rather than randomly changing settings, gets to the actual cause faster and avoids breaking things that weren't the problem.
Cause 1: operating-system "smart" DNS
Windows in particular can query multiple configured resolvers simultaneously and use whichever answers first — meaning even with a VPN active and correctly configured, your ISP's resolver might occasionally win the race. Fix: check your VPN client's DNS settings specifically, and where available, enable any "force DNS through tunnel" or similar option, or configure your network adapter to use only the VPN-provided resolver.
Cause 2: unprotected IPv6 DNS
Many VPN clients only reconfigure IPv4 DNS settings, leaving IPv6 DNS servers (if your connection has a working IPv6 path) to bypass the tunnel entirely. Fix: check whether your VPN client has explicit IPv6 support or a "block IPv6" option, and confirm via an IPv6 Leak Test whether your connection actually has IPv6 in the first place.
Cause 3: browser-level secure DNS
Browser-configured DNS-over-HTTPS can override your system's resolver setting entirely, sometimes routing queries to a resolver your VPN never intended to use. Fix: check your browser's privacy/security settings for a "secure DNS" or "DNS over HTTPS" option and confirm it's either disabled or explicitly pointed at your VPN's resolver rather than a default public one.
Verifying the fix worked
After making a change, re-run NetRiskScan's DNS Leak Test to confirm the resolver now matches your VPN's exit network rather than your ISP's. Test in a fresh browser session, since some settings only apply to newly opened windows.
FAQ
Do all three causes need separate fixes?
Potentially — they're independent settings at different layers (OS, VPN client, browser), so fixing one doesn't guarantee the others are also correctly configured. Check all three if a leak persists after the first fix.