What is a DNS leak?

A DNS leak happens when your device sends its website lookups outside your VPN tunnel, usually to your internet provider’s DNS server. The rest of your traffic stays encrypted, but the lookups reveal every site you visit. A VPN that resolves all DNS inside its own tunnel prevents this.

Also called: DNS leakage

Updated October 2026. Sources are numbered and listed at the end.

On this page

How a DNS leak happens

Before your browser can load a site, it has to turn the name, like example.com, into an IP address. That lookup is handled by the Domain Name System, or DNS.1 Classic DNS queries travel unencrypted, so whoever runs the DNS server, and anyone watching the network in between, can see which names you ask for.2

When you connect to a VPN, your lookups should go through the encrypted tunnel to a resolver the VPN controls. A leak is any case where they don’t. Common causes:

  • System DNS settings win. The device keeps using the DNS server handed out by your Wi-Fi or internet provider instead of the VPN’s.
  • Parallel lookups. Some operating systems send a query out on every network connection at once and take the fastest answer, so one copy skips the tunnel.
  • IPv6 gaps. If the VPN only handles IPv4, lookups over IPv6 can go straight to your provider.
  • The tunnel drops. For a moment, traffic and lookups fall back to the normal connection unless a kill switch blocks them.

Why DNS leaks matter

DNS lookups are a list of every site and app service you use, with times attached. Your connection might be encrypted, but if the lookups leak, your internet provider or the network you’re on can still build that list. The IETF lists DNS queries as a real privacy risk for exactly this reason.2

Leaks are also silent. Pages load normally, so you have no idea anything is wrong unless you check.

How to test for a DNS leak

  1. Connect to your VPN.
  2. Open a DNS leak test site. It makes your device look up random names and records which DNS servers ask for them.
  3. Look at the results. If any server belongs to your internet provider or local network instead of your VPN, you have a leak.

Encrypted DNS, such as DNS over TLS or DNS over HTTPS, hides lookups from the network,34 but the resolver you send them to still sees them. Inside a VPN, the cleanest setup is for the VPN to answer your lookups itself.

DNS in Secria VPN

Secria VPN uses private DNS. It runs its own recursive resolver on its own infrastructure, with DNSSEC validation, and all DNS is resolved through it inside the tunnel, so lookups aren’t handed to your local network’s resolver or to a third-party DNS company.5 An OS-level kill switch blocks all traffic if the tunnel drops.

Sources

  1. IETF, RFC 1034: Domain Names, Concepts and Facilities (November 1987).
  2. IETF, RFC 9076: DNS Privacy Considerations (July 2021).
  3. IETF, RFC 7858: Specification for DNS over Transport Layer Security (TLS) (May 2016).
  4. IETF, RFC 8484: DNS Queries over HTTPS (DoH) (October 2018).
  5. Secria, Secria VPN technical whitepaper, sections on private DNS and leak protection.

Checked October 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about DNS leaks

What is a DNS leak in a VPN?

It is when your device sends website lookups outside the VPN tunnel, usually to your internet provider. Your traffic is still encrypted, but the lookups show which sites you visit.

How do I know if my DNS is leaking?

Connect to your VPN and run a DNS leak test. If the results show DNS servers from your internet provider or local network, your lookups are leaking.

What is DNS leak protection?

A VPN feature that forces every lookup through the tunnel to the VPN’s own resolver and blocks any that try to go elsewhere.

Is a DNS leak dangerous?

It doesn’t expose what you do on a site, but it exposes which sites you visit and when. That alone can reveal a lot about your health, money, beliefs or work.

A VPN built for the quantum era.

Post-quantum on every connection, nothing to switch on.

Get Secria VPN

Explore Secria VPN