FREE TOOLS

DNS leak test

Which DNS server really resolves the names of the sites you visit? With the VPN on, your internet provider should not appear.

DNS servers

Testing…

Your IP address…

When you open a site, your device first asks a DNS server for its address. If those lookups travel outside the VPN tunnel, your internet provider can see which sites you open even though your traffic is encrypted. That is a DNS leak.

The test makes your browser look up random names created just for this test. We are the authoritative server for those names, so we see who brings the lookup to us: that is the DNS server your device really uses.

Frequently asked questions

I see Google or Cloudflare. Is that a leak?

Not by itself. Your browser's “Secure DNS” setting or the VPN server may use those resolvers. What matters is that your internet provider's resolver, or one in your own country, does not appear while the VPN is on.

What does the “subnet” column mean?

Some DNS servers pass along a rough part of your network (EDNS Client Subnet). If your own network shows here with the VPN on, your lookups are going outside the VPN.

How does Colitu protect my DNS?

The app sends DNS lookups through the tunnel. On Windows, TUN mode gives the strongest protection.

Hide your real address

With Colitu, sites see our server's address instead of your real IP. 10 GB free every month. Download the app →

The tools do not store your results. The DNS test keeps a random ID in memory for ten minutes; the other tools run only in your browser.