← Blog Blog

What Is a DNS Leak? How It Exposes Your Browsing (And How to Stop It)

August 26, 2026

A VPN icon can say “Connected” while your internet provider still sees every site you visit. That gap is called a DNS leak, and it’s more common than most people assume: a 2026 Tunnelity DNS-leak test found that nearly 80% of VPN users leaked DNS or IPv6 data at least once, even with the app running and reporting a healthy connection.

What a DNS Query Actually Reveals

Every time you type a domain name, your device has to translate it into an IP address before it can connect. That translation request — the DNS query — goes to a resolver, usually one assigned automatically by whoever runs your network. On a home Wi-Fi or mobile connection, that’s typically your internet service provider.

Your web traffic might be encrypted end to end, but the DNS query that happens before that traffic starts is a separate conversation. If it isn’t routed through your VPN’s tunnel, whoever operates that resolver — most often your ISP — can log the domain name of every site you visit, even while your VPN shows as active.

How a Leak Happens While You’re “Protected”

A DNS leak isn’t a single failure mode — it’s usually one of a handful of specific gaps:

  • Misconfigured client: the VPN encrypts general traffic but never explicitly redirects the operating system’s DNS settings, so the OS keeps using its old resolver.
  • IPv6 blind spots: many VPN tunnels were built around IPv4. If the network also carries IPv6, DNS queries sent over IPv6 can slip outside the tunnel unencrypted, even while IPv4 traffic looks fully protected.
  • OS-level “smart” resolution: some operating systems query multiple resolvers at once and use whichever answers fastest — which can bypass the VPN’s resolver entirely.
  • Browser-level encrypted DNS: browsers with their own DNS-over-HTTPS provider can keep using that provider instead of the VPN’s resolver, which hides the leak from basic tests that only check the OS.

A DNS leak test only proves what happened during the seconds you ran it. Because leaks are often triggered by specific conditions — reconnects, IPv6 availability, app restarts — a single clean result doesn’t guarantee the connection never leaks.

Why This Actually Matters

If a DNS leak just meant the raw traffic content is exposed, it wouldn’t be a huge deal — HTTPS already encrypts that. The problem is more specific: the list of domains you visit becomes visible to whoever handles the leaked query, building a timestamped record of your browsing even when the content itself stays private.

This isn’t a theoretical risk. A 2026 University of Michigan study tested 281 popular Android VPN apps and found that 29 leaked DNS and browser traffic outside the tunnel, and 61 sent data outside the tunnel entirely. Separately, 2026 testing of 30 VPN providers found that 23% leaked DNS queries under at least one test condition — meaning the failure rate isn’t limited to obscure, unvetted apps.

How to Check Whether Your Connection Is Leaking

  1. Connect to your VPN and confirm the app reports an active session.
  2. Open a DNS leak test site in your browser while still connected.
  3. Run the extended test, not just the quick one — it checks more resolvers and catches intermittent leaks the quick test misses.
  4. Compare the resolver’s owner and location to your actual ISP. If your ISP’s name shows up instead of the VPN provider’s, the query leaked.
  5. Repeat the test after reconnecting — some leaks only appear right after the tunnel re-establishes, not during a stable session.

Building DNS Leak Protection In From the Start

The most reliable fix isn’t a setting you toggle — it’s a connection that never gives DNS queries a path outside the tunnel in the first place. RunVPN’s Android app is built this way: after you sign in, the app pulls its configuration automatically and routes all traffic, DNS included, through AmneziaWG or VLESS-Reality over the Xray engine — there’s no manual setup step where a misconfiguration could leave DNS exposed.

DNS query path with and without a VPN tunnel Without a VPN Device ISP resolver exposed Website With RunVPN Device Encrypted tunnel DNS inside Website protected
Without a tunnel, the DNS query goes straight to the ISP's resolver. RunVPN keeps that same query inside the encrypted tunnel.
Common causeWhat happensHow it’s avoided
Misconfigured clientOS keeps using its original resolverAutomatic, tunnel-wide setup after login — no manual step
IPv6 blind spotIPv6 DNS queries slip past an IPv4-only tunnelDNS is routed inside the tunnel regardless of IP version
OS “fastest resolver” behaviorDevice picks a resolver outside the VPNAll DNS traffic stays bound to the active tunnel
Browser DNS-over-HTTPS overrideBrowser bypasses the VPN’s resolverNo per-app config for the user to get wrong

What you get with an automatic setup:

  • No config file to import or app settings to double-check
  • One account, up to 5 devices, no-logs policy
  • AmneziaWG by default, VLESS-Reality (XTLS-Vision) as the alternate protocol

FAQ

Does HTTPS alone stop a DNS leak? No. HTTPS encrypts the content of a request, but the DNS lookup that happens before the connection is a separate step. If that lookup isn’t routed through your VPN, it can still reveal which domains you’re visiting.

Can a DNS leak happen even if my VPN app says “Connected”? Yes. A leak often affects only DNS traffic while the rest of your connection routes correctly, which is why the app’s status indicator alone isn’t proof of a leak-free session.

Is IPv6 the main cause of DNS leaks? It’s one of the most common causes, especially on networks and devices that support IPv6 alongside IPv4. A tunnel that only handles IPv4 can leave IPv6 DNS queries exposed while everything else looks fine.

Do I need to configure anything to get DNS leak protection with RunVPN? No manual configuration is needed. After signing in, the app fetches its setup automatically and routes DNS through the same encrypted tunnel as your other traffic.

Protect your DNS queries by default — download RunVPN.