DNS Leak Test & Fix

Stop DNS queries from bypassing your VPN tunnel and exposing browsing metadata to your ISP.

A DNS leak sends domain lookups to your ISP or a locally configured resolver instead of the VPN’s DNS service. HTTPS hides page content, but the resolver still learns which hostnames you looked up — metadata useful for profiling, censorship, and legal requests.

Detect a leak

  1. Connect your VPN.
  2. Open rookvpn.com/check/vpn-leak-test/dns.
  3. Read the resolver list. Pass: only resolvers associated with your VPN or your chosen privacy DNS aligned with the tunnel. Fail: ISP hostnames, router DNS (192.168.1.1), or hard-coded public DNS you configured outside the VPN appear.

Run the test in the same browser where you do sensitive browsing — DoH settings apply per browser.

Client-side fixes

DNS over HTTPS (DoH)

Browsers may force DoH to Cloudflare, Google, or NextDNS independently of VPN DNS. That can be good for encryption yet bad for alignment if the VPN expects its own resolver. Options:

Router and LAN leaks

Smart routers that intercept DNS (parental controls, “security” DNS) can leak metadata even when the laptop VPN is up if LAN DNS is preferred. Test on cellular tethering to isolate router behavior.

IPv6 DNS considerations

AAAA lookups may use different paths than A records. Pair this guide with IPv6 leak fix when dual-stack is enabled.

Verify fixes

After each change, rerun RookCheck DNS and curl IP checks. Keep a short log (date, client version, pass/fail) when supporting remote colleagues.

Check the result

After you change the DNS setting, reload the resolver check. The name should match the VPN, not the ISP you wrote down while disconnected. Browser DNS-over-HTTPS can ignore the VPN resolver. Turn that off when you want the tunnel’s DNS, then test again.

A single resolver is not a verdict until you compare it. Flush the stub resolver if the page keeps showing the old ISP after the client already claims it pushed DNS. Then look at IPv6. Fixing DNS does not fix an IPv6 bypass.