DNS Leak Test & Fix
Stop DNS queries from bypassing your VPN tunnel and exposing browsing metadata to your ISP.
A DNS leak sends domain lookups to your ISP or a locally configured resolver instead of the VPN’s DNS service. HTTPS hides page content, but the resolver still learns which hostnames you looked up — metadata useful for profiling, censorship, and legal requests.
Detect a leak
- Connect your VPN.
- Open rookvpn.com/check/vpn-leak-test/dns.
- Read the resolver list. Pass: only resolvers associated with your VPN or your chosen privacy DNS aligned with the tunnel. Fail: ISP hostnames, router DNS (192.168.1.1), or hard-coded public DNS you configured outside the VPN appear.
Run the test in the same browser where you do sensitive browsing — DoH settings apply per browser.
Client-side fixes
- Enable Use VPN DNS or Block outside DNS in Hiddify / your VPN app.
- Remove manual DNS entries on Windows, macOS, or Linux until testing completes.
- On Linux, inspect
systemd-resolvedand NetworkManager — stub resolvers often override VPN Pushed DNS until reconnect. - Reboot or cycle airplane mode after changing DNS — stale caches cause false negatives.
DNS over HTTPS (DoH)
Browsers may force DoH to Cloudflare, Google, or NextDNS independently of VPN DNS. That can be good for encryption yet bad for alignment if the VPN expects its own resolver. Options:
- Disable DoH while testing VPN DNS.
- Configure DoH to the same provider your VPN documents.
- Use RookCheck after each browser update — vendors change defaults silently.
Router and LAN leaks
Smart routers that intercept DNS (parental controls, “security” DNS) can leak metadata even when the laptop VPN is up if LAN DNS is preferred. Test on cellular tethering to isolate router behavior.
IPv6 DNS considerations
AAAA lookups may use different paths than A records. Pair this guide with IPv6 leak fix when dual-stack is enabled.
Verify fixes
After each change, rerun RookCheck DNS and curl IP checks. Keep a short log (date, client version, pass/fail) when supporting remote colleagues.
Related
Check the result
After you change the DNS setting, reload the resolver check. The name should match the VPN, not the ISP you wrote down while disconnected. Browser DNS-over-HTTPS can ignore the VPN resolver. Turn that off when you want the tunnel’s DNS, then test again.
A single resolver is not a verdict until you compare it. Flush the stub resolver if the page keeps showing the old ISP after the client already claims it pushed DNS. Then look at IPv6. Fixing DNS does not fix an IPv6 bypass.