🛰️ DNS Leak Test
Check whether your DNS queries leak outside your VPN: see every resolver that answers unique lookup subdomains.
The test resolves four unique subdomains through your normal DNS path and reports which resolver IPs answered.
🔐 Lookups are answered by the 0Appz self-hosted DNS logger, which records only the resolver IP and query name for your unique test id. Nothing is shared with third-party DNS services.
📋 Resolver IPs that answered
How to use this tool
Overview
DNS Leak Test - See Which Resolvers Your Browser Uses answers a simple question: when your browser looks up a domain, who actually resolves it? The test loads images from four unique subdomains of a zone served by the self-hosted 0Appz authoritative DNS logger, so every lookup is answered by the resolver your system really uses — router, ISP, VPN or public DNS. The page lists the resolver IPs that answered, with IPv4/IPv6 family and answer counts, and tells you whether one resolver handled everything or several did. With a VPN, more than one answering resolver usually means part of your DNS traffic escapes the tunnel to your ISP. The measurement runs on 0Appz infrastructure — no third-party OOB service sees your queries, and only the resolver IP plus your random test id are kept in memory.Frequently asked questions
How does the DNS leak test work? +
The DNS Leak Test - See Which Resolvers Your Browser Uses asks your browser to load images from four unique subdomains such as dl123-2.leak.example.com. Before anything loads, the browser must resolve those names — and it uses whatever DNS resolver your system, router or VPN is configured with. The 0Appz self-hosted authoritative DNS logger records the resolver IP and query name for your unique test id, and the page shows which resolver IPs answered.
Why does it show multiple resolvers? +
A few possibilities: your system has both IPv4 and IPv6 resolvers, your router load-balances across ISP resolvers, a VPN resolver and your ISP resolver are both in use (a real leak), or your OS rotates resolvers. The key question is ownership: with a VPN, all answering resolvers should belong to the VPN provider.
Why did I get zero answers? +
Some resolvers cache aggressively or block unique subdomains (DNS filtering, ad blockers with DNS protection, corporate policy). If nothing resolves, check whether the hostnames resolve at all with a normal browser tab, and whether a DNS filter is intercepting them.
Is this test private? +
Yes. The logger is self-hosted on 0Appz infrastructure — no third-party OOB service sees your queries. Only the resolver IP and the random query name tied to your one-time test id are stored, in memory, and they expire. No cookies, no accounts, no history.