🇬🇧 English🇪🇸 Español🇫🇷 Français🇩🇪 Deutsch🇸🇦 العربية🇧🇷 Português
🚀 Explore All Tools
🚀 Explore All Tools

🛰️ DNS Leak Test

Check whether your DNS queries leak outside your VPN: see every resolver that answers unique lookup subdomains.

🛰️

The test resolves four unique subdomains through your normal DNS path and reports which resolver IPs answered.

Test ID-
Probes sent-
Resolvers found-

🔐 Lookups are answered by the 0Appz self-hosted DNS logger, which records only the resolver IP and query name for your unique test id. Nothing is shared with third-party DNS services.

Run leak test
The test resolves four unique subdomains through your normal DNS path and reports which resolver IPs answered.

📋 Resolver IPs that answered

-
📋

How to use this tool

1
⌨️
1. Enter your input
Type, paste or drop your file above.
2
🔒
2. Run in browser
Your files never leave your device.
3
💾
3. Download result
Save or copy instantly, no sign-up.

Overview

DNS Leak Test answers a simple question: when your browser looks up a domain, who actually resolves it? The test loads images from four unique subdomains of a zone served by the self-hosted 0Appz authoritative DNS logger, so every lookup is answered by the resolver your system really uses, router, ISP, VPN or public DNS. The page lists the resolver IPs that answered, with IPv4/IPv6 family and answer counts, and tells you whether one resolver handled everything or several did. With a VPN, more than one answering resolver usually means part of your DNS traffic escapes the tunnel to your ISP. The measurement runs on 0Appz infrastructure. No third-party OOB service sees your queries, and only the resolver IP plus your random test id are kept in memory.

Why DNS leaks matter

A VPN can encrypt your traffic while leaving DNS resolution to your ISP. In that case every domain you type is still visible to the provider, even though the content of the pages is not. DNS leaks typically happen when the system keeps its ISP resolver configured, when IPv6 queries bypass an IPv4-only tunnel, or when the VPN client fails to redirect port 53. This test loads images from unique subdomains and reports which resolver IPs answered, so you can see exactly who resolved what.

Technical specifications

PropertyDNS leak test behavior
MethodUnique subdomain probes against a self-hosted authoritative DNS logger
ReportsResolver IPs, IPv4/IPv6 family, answer counts, number of resolvers
VerdictSingle resolver (expected) vs several (possible leak)
Third partiesNone: measurement runs on 0Appz infrastructure
StoredResolver IP and random test id in memory only
CostFree, no account, no ads

Privacy: no third-party service sees your queries

Most DNS leak tests rely on an external OOB service, which means the tester sees your queries. Here the logger is 0Appz's own and results are held in memory, not written to a database. Treat resolver IPs as ordinary connection metadata.

Fixing a detected leak

  • Enable DNS leak protection in the VPN client and reconnect.
  • Disable IPv6 at the OS level if the VPN only tunnels IPv4.
  • Set the system DNS to the VPN provider's resolver, not the router's.
  • Re-run the test after changing settings, one resolver should answer.
  • Test from the same profile and network you actually browse with.

Related: browse the privacy and security tools for IP, WebRTC and fingerprint checks.

Frequently asked questions

How does the DNS leak test work? +

The DNS Leak Test asks your browser to load images from four unique subdomains such as dl123-2.leak.example.com. Before anything loads, the browser must resolve those names, and it uses whatever DNS resolver your system, router or VPN is configured with. The 0Appz self-hosted authoritative DNS logger records the resolver IP and query name for your unique test id, and the page shows which resolver IPs answered.

Why does it show multiple resolvers? +

A few possibilities: your system has both IPv4 and IPv6 resolvers, your router load-balances across ISP resolvers, a VPN resolver and your ISP resolver are both in use (a real leak), or your OS rotates resolvers. The key question is ownership: with a VPN, all answering resolvers should belong to the VPN provider.

Why did I get zero answers? +

Some resolvers cache aggressively or block unique subdomains (DNS filtering, ad blockers with DNS protection, corporate policy). If nothing resolves, check whether the hostnames resolve at all with a normal browser tab, and whether a DNS filter is intercepting them.

Is this test private? +

Yes. The logger is self-hosted on 0Appz infrastructure. No third-party OOB service sees your queries. Only the resolver IP and the random query name tied to your one-time test id are stored, in memory, and they expire. No cookies, no accounts, no history.

🔒 100% browser-based. Your files never leave your device