Test for DNS leaks
Web traffic and DNS traffic can take different paths. If a VPN encrypts websites but DNS still goes to a local resolver, sites you resolve can be visible to that resolver even while the browser looks connected to another country.
This test asks several leak-test services to see which DNS exits resolve newly generated names. Use it after connecting a VPN, corporate proxy, or privacy DNS service to confirm the resolver matches what you configured.
The test contacts third-party DNS leak endpoints from your browser. Resolver identities and regions are displayed to you; NetScope does not store the result unless you create a report.
How to use this tool
- Connect to the VPN, proxy, or DNS service you want to verify.
- Run the DNS leak test and wait for each source to return.
- Compare resolver networks and regions with your provider documentation. A local ISP resolver while a VPN is “connected” is the usual leak signal.
Run DNS leak test
Frequently asked questions
Does a different DNS resolver always mean a leak?
No. Many VPNs intentionally use their own resolvers or a public resolver such as Cloudflare or Quad9. Compare the result with the resolver your client is supposed to use.
Can browser DNS-over-HTTPS hide a leak?
Sometimes. If the browser sends DNS over HTTPS to a configured provider, OS-level leak tests can look clean while the browser still uses a specific resolver. Check both the browser DNS setting and this test.
When should I run the extended test?
Use the standard test first. Run the extended test if you need a fuller list of recursive servers, especially with anycast DNS, because extra unique names give more nodes a chance to appear.
Related tools