DNS leak test: which resolvers really answer your queries?
Four single-use lookups, and we name the DNS resolvers that answered. If one of them sits outside your VPN exit country, your DNS is leaving the tunnel.
- Observed public IP
- 216.73.217.175
- Connection exits in
- United States
- Distinct resolvers seen
- -
Method: 4 lookups on single-use subdomains of ip-api.com, whose authoritative side reports which resolver queried it - that is the only way a browser can observe a resolver. Your browser sends nothing else, and we store none of it.

Three steps, no install.
A name nobody has resolved
Each run targets a freshly generated subdomain. Because no cache anywhere holds it, the lookup necessarily travels to the authoritative server, which records the resolver that asked.
The resolver is named
The response reports the querying resolver's IP address, its country and the organisation that operates it. We repeat the operation four times to surface secondary resolvers.
Comparison with your exit
Each resolver's country is compared with the country your public IP exits in. A resolver outside that country means the lookup did not travel through the tunnel.
How to read this test
A VPN encrypts your traffic, but the name lookup that precedes it can take a different road. When your system keeps using the resolver handed out by your internet provider, that provider still sees every domain you visit - the encryption gains you nothing on that channel.
The browser itself never learns which resolver answered. The question can only be settled from the authoritative side: resolve a name nobody has ever resolved, and ask the authoritative server who came knocking. That is exactly what this page does, four times, because a machine usually has several resolvers configured and rotates between them.
What this test does not cover
This page looks at DNS resolution only. It says nothing about WebRTC, the browser API that can expose your real IP address through peer-to-peer discovery, entirely outside the DNS question. That leak has its own test.
Run the WebRTC leak testEverything you need to know.
Does the test send anything to a third party?
Yes, and it has to. Your browser resolves single-use subdomains of ip-api.com, so that service necessarily learns your resolver's IP address. It is the only way to observe a resolver from a browser. We receive nothing and store nothing; the whole exchange stays between your browser and ip-api.com.
The resolver shown is not my provider - am I safe?
It means the lookup did not go straight to your provider, which is the main thing you are testing for. It does not mean the resolver is trustworthy: whoever operates it sees every domain you request. If privacy is the goal, prefer a resolver you have chosen deliberately over one you inherited.
How do I fix a DNS leak?
In order of effectiveness: enable your VPN client's DNS leak protection (it forces every lookup into the tunnel), then check that IPv6 is either carried by the tunnel or disabled, since an IPv6 lookup can escape an IPv4-only tunnel. On Windows, also disable the 'smart multi-homed name resolution' policy, which queries every interface in parallel.
Why do results change between two runs?
Because your system rotates between the resolvers it has been given. A leak often appears only on the second or third lookup, which is why this test runs four and lists every distinct resolver it sees rather than the first one.
You've seen the gap. Close it.
30-day money-back guarantee. No card required for tools.