DNS leak test

Who actually answers your DNS?

Every site you visit starts with a DNS lookup, and it can go somewhere you never chose. We watch from the other end and name whoever answered.

216.73.217.111

Columbus, United States · Amazon.com, Inc.

4,475 tests run so far

Your connection216.73.217.111Columbus, United States · Amazon.com, Inc.

What it checks

  • Who answered

    The resolvers that handled your lookups, with city and network. Providers like Quad9 and NextDNS are named, so you can tell yours at a glance.

  • Leaks that come and go

    Lookups go out over several seconds, and Run deeper sends up to 90 more for a leak that only shows now and then.

  • IPv6

    Half the lookups ask for IPv6 addresses, and the result says whether your resolver reached us over IPv6.

  • WebRTC

    Whether your browser shows a web page a different address than your connection does.

  • DNSSEC

    Whether your resolver asks for DNSSEC records. That shows it’s aware of DNSSEC, not that it checks signatures.

  • Time zone

    Whether your device’s time zone matches where your IP address puts you.

  • No trackers
  • No analytics
  • No cookies
  • No accounts
  • Nothing loaded from anyone else

Free API

Run it from a script.

No key, no account. Your code resolves a few hostnames and reads back who answered.

  • GET /api/new

    A test ID and the hostnames to resolve.

  • GET /api/result/<id>

    Who answered, and the verdict. Kept for ten minutes.

  • Text or JSON

    curl and wget get readable text. Ask for JSON and you get JSON.

  • /llms.txt

    The whole contract in one file, written for agents.

Read the API docs

Common questions

What is a DNS leak?

A DNS leak is when your lookups go to a resolver you didn’t choose. Often that’s your internet provider’s, while a VPN is meant to be covering them. It happens without a VPN too, when your provider, your router or a device overrides the DNS you set.

How does the test know who answered?

Your browser looks up a few hostnames nobody has used before. Your resolver has to ask our nameserver about them, so we see which resolver asked and name it. Your device can only tell you what it’s set to use, not who actually answered.

Do I need a VPN to have a DNS leak?

No. Internet providers that intercept DNS, devices with DNS built in, router overrides and browsers with their own DNS over HTTPS can all send lookups somewhere you didn’t choose.

Why doesn’t every result say leak or no leak?

Because we can’t see what you configured. When a resolver answers from another country, it could be one you chose or one you didn’t, so we name it and let you decide. A partial leak, where some lookups went somewhere the rest didn’t, is flagged either way.

Will changing my DNS provider fix a leak?

No. It changes who receives the leaked lookups. The fix belongs wherever they’re being diverted: your VPN app, your operating system, your router, or a device that ignores all of them. The guide to fixing a DNS leak covers each one.

What does DNS Leak keep about me?

Test results stay in memory for ten minutes, then they’re discarded. Nothing about your visit is kept after that, apart from a daily count of tests with no addresses attached. There are no cookies, no accounts and no analytics, and the page loads nothing from anyone else. The privacy page has the whole of it.

Is there an API?

Yes. It’s free, needs no key or account, and gives plain text to curl and JSON to scripts and agents. The API docs cover every field.

What does Run deeper do?

It sends up to 90 more lookups over a longer run, which helps catch a leak that only happens now and then. It’s more lookups to the same nameserver, not more locations.

DNS Leak: the DNS leak test that names your resolver