DNS leak test — person checking a VPN connection on a tablet

Free DNS Leak Test Tools Compared: How to Check Your VPN

Amar Ghafir
Written by Amar GhafirUpdated October 6, 2026 · published September 28, 2026 · how we review

Turning on a VPN and seeing a green checkmark in the app tells you the connection succeeded. It doesn’t tell you whether your DNS requests, your real IP address, or your browser’s WebRTC feature are quietly leaking outside the encrypted tunnel. That takes a separate check, and the tools that do it are free. This guide compares the ones we actually link to across our VPN reviews, including our NordVPN review and ExpressVPN review, and explains what each one is checking for.

Our view in brief: run a DNS leak test and a WebRTC leak test every time you set up a new VPN, and again after any major app update. It takes about two minutes and it’s the only way to confirm a VPN is doing what its marketing page claims.

Key Takeaways

  • DNS leak tests and WebRTC leak tests check different things — running only one can miss a real leak.
  • All the tools in this guide are free, require no signup, and take under two minutes each.
  • A single leaked result while connected to a VPN is a real problem worth reporting to your provider, not something to ignore.

How We Put This Guide Together

This dns leak test guide lists widely used free tools and links to each tool’s own site and documentation. Each tool listed is free to use without an account. We link out to the tools’ own sites rather than embedding results, since a leak test needs to run live in your browser to mean anything.

DNS leak test — person checking a VPN connection on a tablet

DNS Leak Tests: dnsleaktest.com and ipleak.net

Every time you type a web address, your device asks a DNS server to translate it into an IP address. A properly configured VPN routes that request through its own encrypted DNS servers. A leak happens when some of those requests slip out to your ISP’s DNS servers instead, which lets your provider see which sites you’re visiting even though the traffic itself is encrypted.

dnsleaktest.com offers a standard test and an extended test. The standard test is fast but only checks a handful of servers; the extended test takes closer to a minute and checks more thoroughly. Run the extended version — the standard one can miss an intermittent leak. A clean result shows only servers belonging to your VPN provider. If your ISP’s name shows up in the list while you’re connected, that’s a leak.

ipleak.net checks DNS the same way and adds your public-facing IP address and, in most browsers, a WebRTC check on the same page. It’s a reasonable one-stop option if you want both checks without opening two tabs, though we’d still recommend cross-checking with dnsleaktest.com’s extended test since no single tool catches everything.

WebRTC Leak Tests: browserleaks.com

WebRTC is a browser feature used for video calls and file sharing directly between browsers, and it has a long-standing quirk: it can reveal your real IP address even while a VPN is active, because some browsers let WebRTC bypass the VPN’s routing entirely. This is a browser-level leak, not necessarily a flaw in the VPN itself, which is why it needs a separate check from a DNS leak test.

browserleaks.com/webrtc shows your local and public IP addresses as WebRTC sees them. If it displays your real public IP while you’re connected to a VPN, most VPN apps have a setting or extension-level fix for it — check your provider’s support pages for “WebRTC leak” specifically. Firefox and Chrome handle this differently, so a leak in one browser doesn’t necessarily mean the same leak exists in another on the same device.

Checking If Your Own Data Has Already Leaked: Have I Been Pwned

This is a different kind of check — not about your VPN connection, but about whether your email address or password has appeared in a known data breach. haveibeenpwned.com, run by security researcher Troy Hunt, lets you search an email address against a large, regularly updated database of breach dumps, free, with no account required. It won’t show you the leaked password itself, only which breach your address appeared in and when.

If your email shows up against a breach, the practical response is the same regardless of which service was breached: change that password, and change it everywhere else you reused it. This is also the strongest argument for a password manager with unique, generated passwords per site — see our Bitwarden review if you’re not using one yet, or our Qustodio review if it’s a family device you’re checking, since a breach only matters for the accounts sharing that same password.

How to Actually Run These Checks

  1. Connect to your VPN as you normally would — the first step in any dns leak test.
  2. Open dnsleaktest.com and run the extended test. Confirm only your VPN provider’s servers appear.
  3. Open browserleaks.com/webrtc in the same browser. Confirm the public IP shown matches your VPN’s IP, not your real one.
  4. Disconnect the VPN and run both again as a baseline, so you know what a leak actually looks like on your connection versus a clean result.
  5. Repeat the check after any major VPN app update, since a routing change can reintroduce a leak that a previous version didn’t have.

What to Do If You Find a Leak

A single confirmed leak doesn’t necessarily mean the VPN is fraudulent — it can be a browser setting, an app bug, or a misconfigured network adapter. Start with your VPN provider’s own kill switch and leak-protection settings, since most have a dedicated toggle for exactly this. If the leak persists after checking those settings, it’s worth reporting to the provider’s support team with your test results attached, and worth treating as a factor in whether to keep using that VPN if it isn’t fixed within a reasonable time — our best VPN rankings are a reasonable place to compare alternatives.

Final Verdict

None of the tools in this dns leak test guide require payment, an account, or any technical skill beyond opening a browser tab and reading a result. Running a DNS and WebRTC leak check takes about two minutes total and is the only real way to confirm a VPN is protecting what it claims to protect, rather than taking a provider’s word for it.

Free Security Tools: Frequently Asked Questions

What is a DNS leak?

A DNS leak happens when some of your website lookup requests bypass your VPN’s encrypted DNS servers and go directly to your internet provider’s DNS servers instead. It lets your provider see which sites you’re visiting even though your actual traffic stays encrypted.

Is dnsleaktest.com safe to use?

Yes. It only reads information your browser and network already expose during a normal connection — which DNS servers handled your request — and doesn’t require an account, payment, or any software installation.

Why do I need a separate WebRTC leak test if I already ran a DNS leak test?

They check different things. A DNS leak test checks which servers are resolving your website lookups. A WebRTC leak test checks a separate browser feature that can reveal your real IP address independently of DNS, even when your DNS is leak-free. Running only one test can miss the other kind of leak entirely.

What should I do if Have I Been Pwned shows my email in a breach?

Change the password for the breached account, then change it anywhere else you reused the same password, since that’s the account a leaked password actually threatens. Using a password manager to generate a unique password per site limits how far any single breach can spread.

Sources: dnsleaktest.com, ipleak.net, browserleaks.com, haveibeenpwned.com — the tools’ own sites.

Scroll to Top