What a DNS leak test really proves (and how to fix it)
Learn what a DNS leak test really proves, common causes of leaks, and how to fix them with encrypted, no-logs DNS like AEU DNS.
When you run a DNS leak test, you see a list of servers that supposedly handled your DNS queries. But what does that actually prove? A DNS leak test checks whether your device is sending DNS queries to your configured resolver or to some other server, such as your ISP's resolver. It does not prove that your DNS traffic is encrypted, nor does it guarantee that your resolver keeps no logs. Understanding what a leak test can and cannot tell you is the first step to fixing leaks and protecting your privacy.
A DNS leak occurs when your device sends DNS queries outside the private or encrypted resolver you configured. For example, you might set your VPN to use a secure DNS, but due to a misconfiguration, your device still sends queries to your ISP. Those queries are unencrypted, visible to anyone on the network path, and can reveal every website you visit. A leak test detects such leaks by sending a query to a test server and then checking which resolver actually received it.
However, a leak test has limits. It only shows the resolver that answered the test query. It does not prove that all your DNS traffic is encrypted. Even if the test shows your configured resolver, your queries could still be sent in plaintext on port 53, visible to your ISP or a network observer. A leak test also does not prove that your resolver is no-logs. A resolver could be logging your queries while still passing a leak test. So, a clean leak test is necessary but not sufficient for privacy.
Common causes of DNS leaks include VPN split tunneling, IPv6, OS resolver overrides, and browser DoH. Split tunneling routes only some traffic through the VPN, leaving other DNS queries to go directly to your ISP. IPv6 can bypass your VPN if your VPN doesn't handle IPv6 DNS, causing leaks. Operating systems often have their own resolver settings that can override your configured DNS. And browsers with built-in DoH (DNS over HTTPS) may use a different resolver than your system, potentially leaking queries.
To fix a DNS leak, you need to ensure that every DNS query from every application goes through your chosen encrypted resolver. One way is to disable split tunneling or configure it to route all DNS traffic through the VPN. Another is to disable IPv6 or configure your VPN to handle IPv6 DNS. You can also set your OS resolver to a specific DNS server and disable browser DoH or set it to use the same resolver.
But the most robust fix is to force all DNS queries through an encrypted, no-logs resolver like AEU DNS. AEU DNS is a European, privacy-first service that strictly does not log your queries. It supports encrypted DNS over HTTPS (DoH), over TLS (DoT), and over QUIC (DoQ). By configuring your devices to use AEU DNS, you ensure that every query is encrypted and that no logs are kept. This closes the leak at the source, regardless of VPN or browser settings.
Encrypted DNS works by wrapping your DNS queries in a secure connection. DoH uses port 443, the same port as web traffic, making it hard to block. DoT uses a dedicated port 853, which is simple but easy for a network to spot. DoQ uses UDP and offers low latency. All three prevent eavesdropping and tampering. With AEU DNS, you can choose the protocol that fits your needs, and because it is under EU jurisdiction, your data is protected by GDPR.
In addition to fixing leaks, a no-logs resolver like AEU DNS can help with other privacy issues. For example, it can enforce SafeSearch network-wide, filtering explicit results for all devices on your network. It can also block malicious domains, reducing the risk of phishing and malware. And because it is no-logs, you don't have to worry about your browsing history being stored or sold.
To test for leaks, use a reputable leak test website. Run the test with your VPN on and off, and with IPv6 enabled and disabled. If the test shows your ISP's resolver, you have a leak. If it shows AEU DNS, you are likely leak-free. But remember, a leak test is just a snapshot. For continuous protection, configure your router to use AEU DNS, so all devices on your network are covered.
In conclusion, a DNS leak test is a useful diagnostic tool, but it only shows one thing: which resolver answered a test query. It does not prove encryption or no-logs. To truly fix leaks, you need to ensure all DNS traffic is encrypted and sent to a trustworthy resolver. AEU DNS offers that with strict no-logs, EU jurisdiction, and support for modern encrypted DNS protocols. By taking control of your DNS, you can close leaks and protect your online privacy.
Terms explained
- DNS leak
- When your device sends DNS queries outside the configured private or encrypted resolver, exposing the sites you visit.
- DNS leak test
- A tool that checks which DNS resolver actually handles your queries to detect leaks.
- DoH (DNS over HTTPS)
- Encrypted DNS that uses port 443, blending with web traffic and making it hard to block.
- DoT (DNS over TLS)
- Encrypted DNS that uses a dedicated port 853, simple but easy for a network to spot.
- DoQ (DNS over QUIC)
- Encrypted DNS that uses UDP, offering low latency and modern performance.
- No-logs
- A policy where a DNS service does not store any records of your queries.
How to protect yourself
- Run a DNS leak test with your VPN on and off to identify leaks.
- Disable IPv6 on your devices or configure your VPN to handle IPv6 DNS.
- Set your OS resolver to AEU DNS and disable browser DoH or align it with your system resolver.
- Configure your router to use AEU DNS to cover all devices on your network.
- Use a no-logs, encrypted DNS service like AEU DNS to ensure all queries are private.
References
- RFC 8484: DNS Queries over HTTPS (DoH)
- RFC 7858: Specification for DNS over Transport Layer Security (TLS)
- RFC 9250: DNS over Dedicated QUIC Connections (DoQ)
