DNS Leak Test

Test Your VPN for DNS leaks

Please turn off your VPN, Select your preferences and 'TEST'

Audio Permission
Video Permission

Other DNS details

Recommended VPN to avoid DNS leaks

Express VPN Nord VPN IP Vanish VPN Vypr VPN

First, run the test with your VPN off. Make a note of the IP addresses and locations listed in each of the test results. Next, turn your VPN on and run the test again. If your VPN does not leak DNS requests, the DNS servers reported should belong to your VPN provider (or another DNS provider you've intentionally configured), rather than your ISP. Their locations will usually match -- or at least be consistent with -- the VPN server you're using.

If your VPN does leak DNS requests, one or more of the IP addresses will be the same in both tests. This happens when the VPN fails to route a DNS request to its own server, instead of the default DNS server specified by your ISP or in your internet settings.

A DNS leak exposes your DNS requests outside the VPN. Although websites will usually still see your VPN IP address, your ISP or another DNS provider can monitor the domains you visit, and the DNS server's location may reveal your approximate location.

The fix depends on the root cause. Run the test again after each step below to check whether it patched the leak (see the next section for WebRTC leaks specifically):

  1. Check your VPN app's settings for an option to route DNS requests through the VPN's own servers, or a "DNS leak protection" toggle. Turn it on if available. This resolves the issue for most users.
  2. Change your DNS servers. Manually replace the preferred and alternate DNS nameservers in your device's internet settings. Some VPN providers publish DNS server addresses, while others automatically assign them whenever you connect. Check your provider's documentation before changing DNS manually.

    Some reliable public options (IPv4 unless noted):

    • Cloudflare: preferred 1.1.1.1 / alternate 1.0.0.1
    • Google Public DNS: preferred 8.8.8.8 / alternate 8.8.4.4 (IPv6: 2001:4860:4860::8888 / 2001:4860:4860::8844)
    • OpenDNS: preferred 208.67.222.222 / alternate 208.67.222.220 (IPv6: 2620:0:ccc::2 / 2620:0:ccd::2)
    • Comodo Secure DNS: preferred 8.26.56.26 / alternate 8.20.247.20
    • OpenNIC: addresses vary by region — check opennic.org for the nearest server to you
  3. Confirm Teredo is disabled. Teredo is a Windows feature that tunnels IPv6 traffic over IPv4, and it can take priority over your VPN's own tunnel — sometimes routing traffic outside it. It's disabled by default on current versions of Windows, but it's worth confirming, especially after a Windows update or a fresh VPN install:
    • Search for Command Prompt in your taskbar, right-click it, and select "Run as administrator."
    • Enter and run: netsh interface teredo set state disabled
    • Reboot your PC.
  4. Flush your DNS cache. Old entries can corrupt your DNS settings.
    • Windows: open Command Prompt as administrator and run: ipconfig /flushdns
    • Mac: open Terminal (Applications > Utilities > Terminal) and run the command for your macOS version.
      • For versions after v10.10.4 use: sudo killall -HUP mDNSResponder
      • For v10.10 through v10.10.3 use: sudo discoveryutil mdnsflushcache
      • For Snow Leopard, use: sudo dscacheutil -flushcache
  5. Consider a VPN monitoring utility as a last resort. Paid tools like the Pro version of VPNCheck or OpenVPN Watchdog can alert you to connection failures and DNS leaks in real time. Since these cost extra, it's often more effective to fix the root cause above, or switch to a VPN with reliable built-in leak protection.

WebRTC can expose your device's local or public IP address to websites under certain conditions, even while you're connected to a VPN. WebRTC is used by browsers for video calls, voice chat, and peer-to-peer file sharing — it's a legitimate feature, not a bug, which is exactly why it's easy to overlook as a leak source.

  • Firefox is the only major browser with a direct, built-in toggle: type about:config into the URL bar, and search for media.peerconnection.enabled. Click to set it to False. How to fix WebRTC leaks
  • Chrome and Edge don't expose a reliable built-in option. A browser extension is the more dependable fix. Google's own WebRTC Network Limiter is the current recommendation, since it specifically blocks the public-IP-revealing WebRTC candidates.
  • Android Chrome has no extension support, so the practical fix is a VPN app with its own WebRTC leak protection, or switching to Firefox for Android.

Disabling WebRTC entirely will break browser-based video calls and screen sharing, so it's worth running a leak test first. If your real IP doesn't show up while connected to your VPN, you may not need to disable it at all.

Internet Protocol version 6 (IPv6) is the successor to IPv4. Every device that connects to the internet needs an IP address, and IPv4 is running out of available addresses as more devices come online. IPv6 solves that by creating a far larger address range, but the internet is still transitioning, and much of it still runs primarily on IPv4.

Some VPNs still tunnel only IPv4 traffic or disable IPv6 rather than tunneling it, allowing IPv6 traffic to bypass the VPN if it isn't handled correctly.

If that's the case, you have two options: use a VPN that explicitly supports IPv6 tunneling, or disable IPv6 on your device and force all requests to IPv4. On Windows, this can be done through your network adapter settings (uncheck "Internet Protocol Version 6") or via PowerShell if you prefer a command-line approach.

How to prevent IPv6 leaks

On a Mac, run:

networksetup -setv6off Wi-Fi

Repeat for Ethernet (if used).

DNS, WebRTC, and IPv6 leaks are three different failure points, so a "clean" result on one test doesn't mean you're covered on the others. We recommend testing all three whenever you set up a new VPN, switch networks, or update your OS or browser.

Most DNS leaks are solved by turning on your VPN's own leak protection or switching DNS servers; most WebRTC leaks are a browser-level fix; and IPv6 leaks come down to either disabling IPv6 or picking a VPN that handles it properly. None of these require paid third-party software — they're all fixable with settings you already have access to.

© 2026 Comparitech Limited. All rights reserved.
Comparitech.com is owned and operated by Comparitech Limited, a registered company in England and Wales (Company No. 09962280), Suite 3 Falcon Court Business Centre, College Road, Maidstone, Kent, ME15 6TF, United Kingdom. Telephone +44(0)333 577 0163