What Is a DNS Leak? How It Exposes Your Browsing (And How to Stop It)
A VPN icon can say “Connected” while your internet provider still sees every site you visit. That gap is called a DNS leak, and it’s more common than most people assume: a 2026 Tunnelity DNS-leak test found that nearly 80% of VPN users leaked DNS or IPv6 data at least once, even with the app running and reporting a healthy connection.
What a DNS Query Actually Reveals
Every time you type a domain name, your device has to translate it into an IP address before it can connect. That translation request — the DNS query — goes to a resolver, usually one assigned automatically by whoever runs your network. On a home Wi-Fi or mobile connection, that’s typically your internet service provider.
Your web traffic might be encrypted end to end, but the DNS query that happens before that traffic starts is a separate conversation. If it isn’t routed through your VPN’s tunnel, whoever operates that resolver — most often your ISP — can log the domain name of every site you visit, even while your VPN shows as active.
How a Leak Happens While You’re “Protected”
A DNS leak isn’t a single failure mode — it’s usually one of a handful of specific gaps:
- Misconfigured client: the VPN encrypts general traffic but never explicitly redirects the operating system’s DNS settings, so the OS keeps using its old resolver.
- IPv6 blind spots: many VPN tunnels were built around IPv4. If the network also carries IPv6, DNS queries sent over IPv6 can slip outside the tunnel unencrypted, even while IPv4 traffic looks fully protected.
- OS-level “smart” resolution: some operating systems query multiple resolvers at once and use whichever answers fastest — which can bypass the VPN’s resolver entirely.
- Browser-level encrypted DNS: browsers with their own DNS-over-HTTPS provider can keep using that provider instead of the VPN’s resolver, which hides the leak from basic tests that only check the OS.
A DNS leak test only proves what happened during the seconds you ran it. Because leaks are often triggered by specific conditions — reconnects, IPv6 availability, app restarts — a single clean result doesn’t guarantee the connection never leaks.
Why This Actually Matters
If a DNS leak just meant the raw traffic content is exposed, it wouldn’t be a huge deal — HTTPS already encrypts that. The problem is more specific: the list of domains you visit becomes visible to whoever handles the leaked query, building a timestamped record of your browsing even when the content itself stays private.
This isn’t a theoretical risk. A 2026 University of Michigan study tested 281 popular Android VPN apps and found that 29 leaked DNS and browser traffic outside the tunnel, and 61 sent data outside the tunnel entirely. Separately, 2026 testing of 30 VPN providers found that 23% leaked DNS queries under at least one test condition — meaning the failure rate isn’t limited to obscure, unvetted apps.
How to Check Whether Your Connection Is Leaking
- Connect to your VPN and confirm the app reports an active session.
- Open a DNS leak test site in your browser while still connected.
- Run the extended test, not just the quick one — it checks more resolvers and catches intermittent leaks the quick test misses.
- Compare the resolver’s owner and location to your actual ISP. If your ISP’s name shows up instead of the VPN provider’s, the query leaked.
- Repeat the test after reconnecting — some leaks only appear right after the tunnel re-establishes, not during a stable session.
Building DNS Leak Protection In From the Start
The most reliable fix isn’t a setting you toggle — it’s a connection that never gives DNS queries a path outside the tunnel in the first place. RunVPN’s Android app is built this way: after you sign in, the app pulls its configuration automatically and routes all traffic, DNS included, through AmneziaWG or VLESS-Reality over the Xray engine — there’s no manual setup step where a misconfiguration could leave DNS exposed.
| Common cause | What happens | How it’s avoided |
|---|---|---|
| Misconfigured client | OS keeps using its original resolver | Automatic, tunnel-wide setup after login — no manual step |
| IPv6 blind spot | IPv6 DNS queries slip past an IPv4-only tunnel | DNS is routed inside the tunnel regardless of IP version |
| OS “fastest resolver” behavior | Device picks a resolver outside the VPN | All DNS traffic stays bound to the active tunnel |
| Browser DNS-over-HTTPS override | Browser bypasses the VPN’s resolver | No per-app config for the user to get wrong |
What you get with an automatic setup:
- No config file to import or app settings to double-check
- One account, up to 5 devices, no-logs policy
- AmneziaWG by default, VLESS-Reality (XTLS-Vision) as the alternate protocol
FAQ
Does HTTPS alone stop a DNS leak? No. HTTPS encrypts the content of a request, but the DNS lookup that happens before the connection is a separate step. If that lookup isn’t routed through your VPN, it can still reveal which domains you’re visiting.
Can a DNS leak happen even if my VPN app says “Connected”? Yes. A leak often affects only DNS traffic while the rest of your connection routes correctly, which is why the app’s status indicator alone isn’t proof of a leak-free session.
Is IPv6 the main cause of DNS leaks? It’s one of the most common causes, especially on networks and devices that support IPv6 alongside IPv4. A tunnel that only handles IPv4 can leave IPv6 DNS queries exposed while everything else looks fine.
Do I need to configure anything to get DNS leak protection with RunVPN? No manual configuration is needed. After signing in, the app fetches its setup automatically and routes DNS through the same encrypted tunnel as your other traffic.
Protect your DNS queries by default — download RunVPN.