Sign In

Sign in to manage your subscription

Bessy Connect

6 min read

DNS Leaks: What They Are and How to Check Your VPN Isn't Exposing You

You switch on your VPN, the connection icon lights up, and it feels like you've gone completely invisible. But there's a catch: even with an active VPN, some requests can "leak" outside the tunnel. This is about DNS — the system that translates website names into IP addresses. If your DNS requests go straight to your internet provider, it still sees the list of sites you open, even when the rest of your traffic is encrypted. That is a DNS leak.

In this guide we'll explain in plain words what a DNS leak is, how it threatens your privacy, how to run a dns leak test, and how to close the gaps so your VPN really hides your activity.

What Is a DNS Leak in Simple Terms

Every time you visit a website, your device asks a DNS server: "what is the IP address of example.com?" Normally that question goes to your internet provider's DNS. When you turn on a VPN, all requests — DNS included — should travel through an encrypted tunnel to the VPN server. Then your provider only sees that you connected to a VPN, not which sites you visit.

A DNS leak is when your DNS requests still slip around the tunnel — straight to your provider or to a public DNS in your country. There are several causes:

  • System DNS bypassing the VPN. Your operating system or router is set to its "own" DNS server and keeps using it, ignoring the tunnel.
  • WebRTC in the browser. This calling and video technology can discover your real IP and DNS directly, going around the VPN.
  • IPv6. If you have IPv6 but the VPN only routes IPv4 through the tunnel, some requests leak over IPv6.
  • Quick reconnects. The moment the VPN connection drops, your device falls back to the normal DNS for a few seconds.

Why does it matter? Because the whole point of a VPN — privacy — is lost. Your provider (and therefore anyone who can request its data) sees the list of domains you opened. Your real IP and country can show up on websites. In short, you think you're hidden, but you're still visible.

How to Check Your VPN for Leaks: dns leak test

The good news: a dns leak test takes a minute and costs nothing. Here's the order:

  1. Turn on your VPN and pick a server in another country.
  2. Open a leak-test site in your browser — for example, dnsleaktest.com or browserleaks.com/dns. Any similar "dns leak test" service works too.
  3. Run the check (on dnsleaktest, use the Extended test button).
  4. Read the result.

What to look at:

  • IP address and country. The top of the test shows your visible IP. It should match the VPN server's country, not your real one.
  • DNS servers. The list should show servers from the VPN's country or the VPN provider itself. If you see servers from your internet provider or your real country — that's a DNS leak.
  • Country match. A good sign is when both the IP and all DNS servers point to the same "foreign" country. A mismatch (IP in the Netherlands, DNS in your home city) means something is leaking.

While you're at it, open browserleaks.com and check the WebRTC section: your local or real IP should not appear there.

How to Close DNS Leaks

If the test showed a leak, don't panic — almost everything is fixed in settings.

Turn On the Kill Switch (Block Connections Without VPN)

A kill switch is a feature that blocks all internet traffic if the VPN connection drops. Until the tunnel is restored, no request — DNS included — goes out onto the open network. This is your main defense against leaks during disconnects. Look for an option named something like "block connections without VPN" in the app settings.

Use Encrypted DNS

A good VPN wraps DNS requests into the tunnel and serves them from its own servers. On top of that you can enable encrypted DNS (DoH/DoT) in your system so requests can't be read along the way. The key is that DNS is handled by the VPN, not your provider.

Disable WebRTC in the Browser

  • Chrome/Edge: install an extension that limits WebRTC (for example, WebRTC Leak Prevent/Control).
  • Firefox: open about:config, find media.peerconnection.enabled, and switch it to false.
  • Brave: in privacy settings, pick the mode that hides your local IP.

Choose a Protocol That Doesn't Leak

A lot depends on the VPN itself. BessyConnect runs on the VLESS + Reality (XTLS) protocol: both regular traffic and DNS requests travel through one encrypted tunnel, and the traffic itself is indistinguishable from ordinary HTTPS. So your provider sees neither the sites you visit nor the fact that you use a VPN at all. Visit logs are not kept.

If your VPN still misbehaves after all the settings, see the breakdown of why a VPN doesn't work — the reason is often blocking or wrong settings. And if you're up against DPI technology and heavy filtering, the guide on how to bypass blocks will help.

WebRTC and IPv6 Leaks in Brief

  • WebRTC leak — the browser reveals your real IP through video-call technology, even with a working VPN. Fixed by disabling WebRTC (see above).
  • IPv6 leak — if your provider gives you IPv6 but the VPN only handles IPv4, part of the traffic goes out directly. Fix: enable IPv6 protection in the VPN app or disable IPv6 in your system. In apps with a full tunnel this is closed automatically.

Not sure which service fits your needs? A criteria-based comparison is in the article which VPN to choose.

FAQ

How do I know I have a DNS leak?

Turn on your VPN and open dnsleaktest.com or browserleaks.com/dns. If your real country or your internet provider appears among the DNS servers or in the IP field — you have a leak. If everything points to the VPN's country, you're protected.

Does a VPN protect against DNS leaks?

A good one does. With a proper tunnel, all DNS requests go through the VPN and your provider can't see your sites. Weak or misconfigured services may let DNS slip around the tunnel — which is why you should run the test yourself.

What is a kill switch?

It's a feature that instantly blocks the internet if the VPN connection drops. Without it, traffic and DNS spill onto the open network for a couple of seconds during a drop. With a kill switch, leaks at those moments are ruled out.

Does a leak affect speed?

Not directly, but it cancels out your privacy. Test speed separately, and leaks with a separate test.

A Private VPN Without Leaks — BessyConnect

Want to be sure your provider can't see your sites? BessyConnect builds one encrypted tunnel on VLESS + Reality, routes DNS through the VPN server, and keeps no visit logs. Over 100 servers in 15 countries, unlimited traffic, sign-in with Apple, Google, or email — one account works on all your devices at once.

Run a dns leak test right now — and make sure your VPN really isn't exposing you.

Related articles

WhatsApp & Telegram Alternatives for Video Calls 2025

Best video calling messengers instead of WhatsApp & Telegram. Review of Zoom, Teams, Signal, FaceTime. Bypass blocks with BessyVPN - bessy.my More

Does a VPN Keep Logs, and What Can Your ISP See?

Does a VPN keep logs and what can your ISP see? An honest look at VPN privacy and anonymity. BessyConnect on VLESS+Reality keeps no browsing logs. More

Public Wi-Fi Security: Why You Need a VPN Traveling

How public Wi-Fi in cafés, airports and hotels puts your data at risk, and how the BessyConnect VPN (VLESS+Reality) protects your traffic on any open network. More