DNS leak explained: what it is, how to test it and how to fix it
What a DNS leak is, why it reveals the sites you open, how to check with the Colitu DNS leak test and how to fix it with TUN mode and browser settings.
A VPN encrypts your traffic between your device and the server. But before your browser can open a site, it has to ask a DNS server for that site's address. If those questions travel outside the tunnel, your internet provider still sees the name of every site you visit, even though it cannot see the content. That is a DNS leak, and it is one of the most common ways a VPN quietly does less than you think.
What DNS does
DNS is the internet's address book. When you type a site name, your device sends a lookup to a resolver, usually your provider's, and gets an IP address back. Classic DNS is sent unencrypted, so anyone on the path can read which names you look up. Newer variants, DNS over TLS and DNS over HTTPS, encrypt the lookup, but whoever runs the resolver still sees every name.
What counts as a leak
With the VPN on, your lookups should go through the tunnel and be answered by a resolver on the VPN side. A leak means at least part of them goes another way, usually straight to your provider's resolver. The consequences:
- your provider can build a list of the sites you open, with timestamps;
- you may get local answers that point to a block page instead of the real site;
- some resolvers pass a rough part of your network (EDNS Client Subnet) on to the sites' own DNS servers.
Why leaks happen
- Proxy mode on Windows. In system proxy mode, browsers send traffic through the proxy, but programs that ignore the proxy resolve and connect on their own.
- Browser Secure DNS. Chrome, Edge and Firefox can use their own DNS over HTTPS provider. That provider is not your ISP, but it bypasses the system DNS settings the VPN set up.
- Custom DNS settings on the network adapter, the router or in another app.
- A second VPN or proxy running alongside, which changes how lookups are routed.
How the Colitu DNS leak test works
Our DNS leak test makes your browser look up random names created only for that test. Colitu is the authoritative server for those names, so it sees which resolver brings each lookup in: that is the DNS server your device really uses. The page also shows whether a resolver passed along part of your network address (the "subnet" column). The random ID and the resolvers that asked about it are kept in memory for ten minutes and then deleted; they are never linked to your account.
Test it in four steps
- Turn the VPN off and run the test. Note the resolver you see: usually your provider's, or a public one you set yourself.
- Turn the VPN on, wait until it says Connected, and run the test again.
- Compare. Your provider's resolver, or any resolver in your own country, should not appear now. Seeing a large public resolver such as Google or Cloudflare is not a leak by itself.
- Check the subnet column. If your own network shows there with the VPN on, lookups are leaving outside the tunnel.
The VPN connection test checks IP, DNS and WebRTC together if you want everything on one page.
How to fix a leak
Windows: use TUN mode. Colitu for Windows offers system proxy mode (the default) and TUN mode. TUN mode routes all traffic and DNS lookups of the whole system through the tunnel and gives the strongest protection. Switch it on in the app's settings and run the test again. On Linux (beta), TUN mode does the same and asks for sudo.
Browser Secure DNS. If the test shows a resolver you did not expect, check the browser:
- Chrome: Settings → Privacy and security → Security → Use secure DNS. Set it to your current service provider, or turn it off.
- Edge: Settings → Privacy, search and services → Security → Use secure DNS. Same choice.
- Firefox: Settings → Privacy & Security → DNS over HTTPS. Choose Default Protection or Off.
The same setting often helps when a streaming or AI service does not open, because a resolver in another country can contradict the server's location.
Android Private DNS. If you set a custom provider under Settings → Network → Private DNS, the test will show that provider. It is not your ISP, but if you want lookups answered on the VPN side, set Private DNS to Automatic.
Other checks. Remove custom DNS servers from the adapter or router for a test, close other VPN and "security" apps, and run the test again.
What is not a leak
- Russian sites. On Windows and Android, Colitu sends Russian sites directly, not through the tunnel; since version 2.5.3 the only exception is the Moscow server. This is built in and has no switch, so on other servers those sites see your normal connection by design. Our tests run on colitu.com and are not affected.
- A public resolver. Google, Cloudflare or a resolver in the server's country is normal.
Quick reference
| What the test shows with the VPN on | Meaning | Action |
|---|---|---|
| Resolver in the server's country or a large public one | No leak | Nothing |
| Your provider's resolver | Leak | TUN mode on Windows, check browser DNS |
| Your own network in the subnet column | Leak | Same as above |
| A DoH provider you chose in the browser | Browser bypasses system DNS | Set Secure DNS to automatic or off |
Related: WebRTC leak explained and the help centre on connection tests.
Sources
- RFC 1035: Domain names, implementation and specification
- RFC 9076: DNS privacy considerations
- RFC 7858: DNS over TLS
- RFC 8484: DNS queries over HTTPS
- RFC 7871: Client subnet in DNS queries
- Chromium Blog: Secure DNS in Chrome
- Mozilla Support: DNS over HTTPS in Firefox
- Android Developers Blog: DNS over TLS support in Android