See which DNS resolver your browser's queries actually use. Compare that IP and network to your VPN's documented DNS. A single resolver is not automatically a leak.
RookCheck asks an EDNS echo service which recursive resolver handled the lookup. That is your DNS server identity — not your VPN egress IP and not a list of every resolver on the path.
Match the reported resolver IP/network to what your VPN client says it uses (or a privacy DNS you chose). ISP-branded DNS while the VPN is connected is a reason to check the VPN's DNS setting. We do not auto-fail a single resolver.
DoH encrypts queries but can still use a resolver outside the VPN if the browser targets a public DoH endpoint.
DNS Resolver Check exists to show which recursive resolver answered a lookup from this browser so you can compare it to the VPN DNS. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.
Work through DNS Resolver Check in order. 1. Read the resolver IP and the network name on the page. 2. Read the DNS server printed in the VPN client. 3. They should be the same provider. 4. If the page shows your ISP, turn off split DNS and test again. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.
The check does not list every resolver on the path. DNS over HTTPS in the browser can ignore the VPN DNS on purpose. One resolver is not a verdict until you compare it. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.
Example: the VPN says it uses 10.8.0.1 and the page shows your home ISP resolver. Queries for normal sites are leaving the tunnel even though the IP check looks clean. Disable split DNS, flush the stub resolver, and reload until the name matches the VPN.
After you finish DNS Resolver Check, open the IPv6 test, which is a separate bypass if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.
It identifies your DNS resolver so you can compare it to your VPN's expected DNS. It does not declare a leak from a single resolver IP.
Enable the VPN's DNS protection or kill switch, set system DNS to the VPN resolvers, then re-run this check and confirm the resolver matches.
It identifies the resolver. You decide if that resolver is the one the VPN promised.
The browser may send DNS to Cloudflare or Google outside the VPN DNS setting. Turn that off when you want the VPN resolver.
The echo service reports the resolver that asked it, not a full traceroute of every forwarder.