Check your expected DNS
Review the DNS provider configured by your VPN, browser or network. Those settings define the route you expect.
Check which DNS resolver paths answer a fresh lookup, then compare with your VPN or secure DNS settings.
Start the test to create a temporary hostname and observe its DNS queries.
This tool shows privacy-preserving resolver IDs, rather than provider names or raw IPs. A completed test alone cannot confirm or rule out a VPN DNS leak.
DNS turns a website name into an IP address. A DNS leak occurs when those lookups take a route you did not expect, such as bypassing the DNS resolver configured by a VPN.
This test creates a fresh hostname and observes the resolver paths that query Localtonet's authoritative DNS service. Review your VPN and browser secure DNS settings alongside the result; the resolver IDs shown here cannot identify a provider. Use the WebRTC leak test separately to check browser-exposed IP addresses.
Review the DNS provider configured by your VPN, browser or network. Those settings define the route you expect.
A provider may use multiple servers, and browser or network fallback can add paths. A higher count alone is not proof of a leak.
Filtering, delegation delays or an unavailable collector may stop the test. Check again before drawing a conclusion.
These pseudonymous IDs do not reveal the resolver operator. Check your VPN’s own DNS diagnostics when you need provider-level confirmation.
Run the test to see its detected details.
It is DNS traffic using a route or resolver you did not expect, such as traffic bypassing the resolver provided by your VPN.
No. The ID is a pseudonymous egress identifier, not a provider name. It needs an expected baseline before it can support a leak claim.
Yes. A browser’s encrypted DNS setting can select a resolver independently of your operating system, router or VPN.
No. The collector returns pseudonymous identifiers and limited query metadata.