Use a randomized probe hostname to observe recursive resolvers. The authoritative DNS probe must be deployed and reachable.
DNS leak test
DNS resolvers versus your public IP
Your HTTP egress connects to websites; DNS resolvers look up hostnames. They often differ. Independent DNS providers, VPN DNS and DoH can use separate addresses or networks. A resolver differing from your public IP does not by itself prove a leak.
How to check a VPN DNS path
Record the DNS configuration expected by your VPN provider, connect the VPN, run the test and compare the observed resolvers. If the probe is not configured, times out or produces no observations, treat the result as unknown rather than a pass.
Frequently asked questions
Is it normal to see multiple DNS servers?
It can be normal. Recursion, forwarding and provider networks can involve multiple egress addresses. Compare them with the DNS provider you expect.
Does encrypted DNS hide my browser fingerprint?
No. DNS encryption and browser-visible signals such as Canvas, WebGL and fonts operate at different layers.
Related browser checks
WebRTC Leak Test
Compare WebRTC public ICE candidates with your HTTP IP address. Check VPN or proxy address exposure, local mDNS protection and STUN status.
Browser Privacy Check
Check browser privacy signals including storage, permissions, Canvas, WebGL and language. Understand fingerprint exposure and the limits of each check.
Browser Security Check
Check the current page security context, browser permissions, storage and API support. Review observable settings and the limits of a browser security check.