MyIPScan

DNS privacy route

DNS Leak Hub

· by AboutKatia Belokon

Short answer: A DNS leak is a route mismatch: domain lookups use a resolver you did not expect, often ISP DNS, router DNS, browser Secure DNS, or a non-VPN resolver while a VPN is connected. Start with the DNS Leak Test, compare before and after VPN changes, then Use Safe Copy.

Use this hub when the page IP looks correct but DNS results, resolver country, browser Secure DNS, router DNS, or VPN DNS behavior still needs review.

Quick answer

  • Start with DNS Leak Test because it reports which resolver actually answered, and that owner is the only signal that separates a leak from ordinary anycast routing.
  • Read the resolver's owner before its country. A VPN provider's resolver answering from an unexpected country is usually anycast; your own ISP's resolver answering with the tunnel up is not.
  • Browser Secure DNS can override the system resolver for one browser alone, which is why a mismatch often appears in one browser and nowhere else.
  • Dual-stack networks resolve over IPv6 as well, so pair this with the IPv6 check when IPv4 looks correct and the results still disagree.

DNS Leak at a glance

SignalWhat it meansBest next step
Resolver routeThe DNS service that appears to answer browser-visible lookups.Run DNS Leak Test before and after VPN changes.
VPN DNSThe VPN may provide its own DNS or route DNS through the tunnel.Compare expected VPN country, ASN, and provider notes.
Browser Secure DNSChrome, Edge, Firefox, or Brave may use a browser-level resolver.Check browser DNS settings if results differ from the VPN.
Router or ISP DNSThe router or ISP can still influence resolver behavior.Retest on another network or after router DNS changes.
IPv6 DNSDual-stack networks can use IPv6 paths even when IPv4 looks right.Run IPv6 Leak Test and DNS Leak Test together.
ReceiptA safe summary helps compare before and after without exposing raw identifiers.Use Safe Copy after the test.

Guides and next checks

Limits and methodology

MyIPScan topic hubs organize practical checks around observable browser and network signals. Results are snapshots for this browser, device, network, and time. They do not prove full anonymity, do not replace provider documentation, and do not test every app on the device.

For transparent limits, see the MyIPScan methodology, editorial policy, and author profile.