FAST PLUSVPNGet Fast Plus
← All guides
PRIVACY / THE FAST PLUS JOURNAL

DNS leaks explained: what they are and how to test

DNS can reveal which names your device is trying to resolve. Learn what a DNS leak means and how to test without jumping to conclusions.

DNS is a separate part of reaching a site

Before a device connects to a domain such as example.com, it usually asks a DNS resolver for an address. A VPN may send those DNS requests through the tunnel to a resolver selected by the VPN provider, but operating-system settings, browser features, split tunneling, or a broken configuration can change that path.

Define a leak before testing

A DNS leak generally means DNS requests that you expected to travel through the VPN are instead reaching a resolver outside that protected route. Seeing an unfamiliar resolver is not automatically proof of a leak; providers can use third-party or anycast DNS infrastructure. First determine what resolver behavior the VPN claims to provide.

Test with and without the VPN

Record your normal DNS behavior, connect the VPN, then repeat the same test. Compare resolver organizations and addresses, and test after reconnecting or changing networks. Browser encrypted-DNS settings can make results different from system DNS. A single web test is useful evidence, not a complete audit.

Fix the configuration, not the screenshot

If results conflict with the VPN documentation, update the app and operating system, disable conflicting network tools temporarily, reconnect, and retest. If the mismatch remains, send the provider the device version, VPN version, network type, and test results. Avoid changing several DNS settings at once because that makes the cause harder to identify.

Sources & further reading

This guide is general educational material. Platform behavior, provider policies, and network conditions can change. Check current documentation before relying on a specific configuration.

Report an error or suggest a clarification ↗