Hurry up! Deal ends in:
02Days
14Hours
07Minutes
53Seconds

What is a DNS leak?

A DNS (Domain Name System) leak happens when your DNS queries — requests sent to translate a website's domain name into an IP address — are exposed.

Think of DNS as the internet's phonebook, translating website names into IP (Internet Protocol) addresses. A DNS leak is like someone overhearing every number you dial. Usually, your ISP (Internet Service Provider) handles these translations and, without protection, can see and log your activity.

How to prevent DNS leaks

If you've used a DNS leak checker and discovered a leak, don't worry. Here are some steps you can take:

  • Use a VPN: use a reliable VPN service with built-in DNS leak protection. This will help route all your DNS requests through the VPN tunnel, preventing leaks;
  • Configure your DNS settings: manually set your DNS servers to those provided by your VPN or use a trusted third-party DNS service, like Surfshark’s*;
  • Disable IPv6: some VPNs do not support IPv6, which can lead to leaks. Turning off IPv6 on your device can help prevent this issue;
  • Clear DNS cache: clear your DNS cache to remove any old or potentially incorrect DNS entries.
  • Update your router’s firmware: ensure your router's firmware is up to date to protect against vulnerabilities that could cause DNS leaks.

*Disclaimer: DNS service shouldn't be used instead of a VPN and doesn't provide the same security level.

Five numbered panels showing: 1) hand holding a shield, 2) hand with a wrench, 3) IPv6 plus icon, 4) hand holding a brush, 5) router with a chip icon.

Don't let DNS leaks expose you

Safeguard your browsing history, location, and personal information from being sold.

Get Surfshark
30-day money-back guarantee

Why should I test for DNS leaks?

Because DNS leaks can expose your personal information and online habits, causing many risks:

Revealed browsing history

Exposed DNS can reveal your browsing history and allow every website and app you use to be logged.

Exposed ISP and location

By knowing your exact internet provider and location details, scammers can create compelling targeted attacks.

Online tracking

Advertisers, websites, and even your ISP can monitor your activity when browsing unprotected.

Targeted attacks

The more data is known about you, the more compelling the hacking attempts or phishing attacks are.

Profiling

Your browsing history, likes and dislikes, and exact location can be used to build a detailed profile about you.

Data selling

All the data with a detailed profile about you could be sold to advertisers and data brokers.

How to perform a DNS leak test

You can easily check for DNS leaks by running a DNS leak test using online tools. Here’s how to use Surfshark’s DNS leak test:

  1. Turn off your VPN and run the DNS leak test.
  2. Turn on your VPN and run the same test again.
  3. See if your DNS changed after connecting to a VPN.
Three steps showing a finger sliding a toggle switch from red to green to activate the DNS setting.

What causes DNS leaks?

Network settings issues

Incorrect device settings can expose your DNS queries, so check them in case of DNS leaks.

VPN or proxy setup errors

When a VPN (Virtual Private Network) or proxy isn't set up correctly, it might not hide your activity and protect your DNS requests.

Malware or malicious apps

Malicious software can alter your DNS settings, expose your activity, and even spy on you.

ISP DNS proxy interference

Some ISPs reroute your DNS requests, even if you have an active VPN connection.

DNS spoofing

Hackers can redirect your device to fake DNS servers, causing DNS leaks and data exposure.

IPv6 leaks

If your VPN doesn't cover IPv6, DNS requests might bypass it and be leaked.

What are the types of DNS leaks?

  • Standard DNS leaks: this occurs when your DNS queries are sent to an unintended DNS server, such as an unsafe public server or an untrusted third-party server;
  • IPv6 DNS leaks: devices using IPv6 can sometimes bypass VPNs that do not fully support this protocol, leading to potential leaks;
  • WebRTC leaks: this type of leak happens when the WebRTC protocol, used by browsers for voice and video calls, exposes your IP address or DNS information;
  • Router DNS leaks: if your router is not configured correctly, it might send DNS queries outside of the VPN tunnel, leading to a DNS leak.
Server tower with floating www bubbles and a cursor clicking on one.

Skip the manual fixes

Use a trusted VPN with WebRTC leak protection.

Get Surfshark
30-day money-back guarantee

How does Surfshark VPN prevent DNS leaks?

Because Surfshark VPN offers top-notch security and more:

Private encrypted DNS

Each Surfshark server uses its own secure DNS, ensuring your requests remain private.

Queries stay secure

All DNS requests are kept within the encrypted tunnel, safeguarding your data.

No external DNS providers

Surfshark handles all DNS traffic internally, never relying on third-party providers.

Audited no-logs policy

Independent audits have confirmed that we do not track or log your online activity.

Protection that goes beyond DNS leaks

Unlimited simultaneous devices

24/7 live expert support via chats and emails

Fast and stable 10 Gbps server network

4500+ servers in 100 countries

Integrated ad blocker and ad blocker extension

30-day money-back guarantee

Protect your privacy online
Get Surfshark
30-day money-back guarantee

Frequently asked questions

What is a DNS leak?

A DNS leak is a security flaw that occurs when your DNS requests are sent outside the secure VPN tunnel. This means that your ISP or other third parties can see the websites you visit, even if you're using a VPN.

What is a DNS leak test?

A DNS leak test is a tool used to determine whether your DNS requests are being securely routed through your VPN or if they are leaking to your ISP.

How do I test for DNS leaks?

To test for DNS leaks, you can use an online DNS leak test tool. Simply connect to your VPN and visit a trusted DNS leak test website. The tool will analyze your DNS requests and inform you if any leaks are detected.

You can perform the test with and without the VPN and compare the results to see whether your VPN changes your DNS.

How often should I run a DNS leak test?

You should run a DNS leak test regularly, for example, once a month, especially after setting up a new VPN connection or changing your network settings.

Can my ISP see my activity if my DNS is leaking?

Yes, if your DNS is leaking, your ISP can potentially see your online activity. DNS leaks expose your browsing history and the websites you visit, compromising your privacy. Using a reliable VPN with DNS leak protection can help prevent this issue.

Does a VPN fix DNS leaks?

Yes, a VPN can fix DNS leaks by routing your DNS requests through its secure servers. Choose a VPN with built-in DNS leak protection features, like Surfshark, to ensure all-around protection.