// TOOLS · WI-FI TAMPERING

DNS Leak Test

Every site you visit starts with a DNS question, and whoever answers it sees your browsing history. This test finds out who that is on your current connection, whether it is who you think, and whether a VPN or private DNS setting is actually being used.

RUN
6 unique lookups · about 5 seconds · results kept 10 minutes, then gone
ON YOUR PHONE · WI-FI TAMPERING CHECK

This tells you who answers your DNS from a laptop on one network. The app's tampering check does it from your phone on any Wi-Fi, hotel or Airbnb or café, and also tests whether that network rewrites answers or intercepts failed lookups. Get RECON for iPhone — one-time purchase, no account, nothing leaves the device.

What a DNS leak is

When you use a VPN, your traffic is supposed to travel inside the tunnel, including the lookups that turn names into addresses. A leak is when those lookups go outside it: your device keeps asking the resolver your ISP assigned, so the ISP still gets a running list of every site you visit even though the page content is hidden. It happens with misconfigured VPN clients, split tunnelling, IPv6 on a VPN that only handles IPv4, and operating-system features that try every resolver at once to be faster.

How this test works

Your browser requests a handful of names that have never existed before, all under a domain whose DNS server we run. Nothing in the world has those names cached, so the resolver your device is using has no choice but to ask our server for them, and our server writes down who asked. The page then reads that list back. Your own address never reaches the DNS side; only your resolver's does, and that is what we look up in the routing registry to name its owner.

Reading the result

Resolver and connection on the same network: normal without a VPN, a leak with one. Resolver on a different network from your connection: either your VPN is doing its job or you have set a public DNS provider. Many resolver addresses from the same owner: a large provider's anycast fleet, not several leaks. A resolver in a country you did not expect: worth understanding, since that operator sees your lookups and answers under its own laws.

What it does not tell you

Whether the answers you get are honest. A resolver can see your lookups without a leak, and a hostile network can rewrite answers without ever appearing here. Testing for that needs a known-good answer to compare against, which is a different check. It also cannot see DNS-over-HTTPS traffic that a browser sends on its own; if your browser has secure DNS enabled, the resolver shown is the one it chose, not the one your operating system uses.

// OTHER TOOLS
Subnet Calculator
IPV4 · IPV6 · CIDR
MAC Vendor Lookup
OUI · MA-L · MA-M · MA-S
Certificate & CSR Decoder
X.509 · PKCS#10 · PEM · DER
DNS Benchmark
CLOUDFLARE · GOOGLE · QUAD9 · 8 RESOLVERS
Port Lookup
TCP · UDP · WHAT IS PORT…
HAR Analyzer
HTTP ARCHIVE
What Is My IP
PUBLIC IP · FINGERPRINT