LE59TOOLS
製品
Network ToolsKnow your network edgeLottery & Random ToolsFair & verifiable drawsLink & QR ToolsShort links & QR codes
ツール
リソース
ガイドサービス状況更新履歴
概要
言語
简体中文繁體中文日本語한국어English
← LE59 ホームに戻る

Updated:2026-09

What Is a DNS Leak?

The Domain Name System (DNS) translates human-readable names such as example.com into the IP addresses that servers actually use. Every time you visit a website, your system performs one or more DNS lookups along the way. When those lookups do not travel through the network path you expect — for example, outside your VPN or proxy tunnel, exposed directly to your local network or ISP — that is called a DNS leak.

DNS leaks are more common than most people assume. Connecting to a VPN encrypts your traffic, but it does not automatically mean your DNS queries follow the same path.

How a DNS query travels

A typical lookup passes through three stages:

  • System resolver: the operating system (or browser) reads your local DNS configuration and decides which recursive server receives the query;
  • Recursive server: usually run by your ISP or a public DNS provider, it follows the chain on your behalf and caches the answer;
  • Authoritative server: the final source of truth that holds the domain’s real records and returns the resolved IP address.

For privacy, the most important step is the first one: who receives your query. If your queries go to your ISP’s recursive servers, the ISP can observe every domain you visit.

Why VPNs and proxies still leak

Even with a VPN or proxy connected, DNS queries can keep taking the old path. Three common causes:

  • Split tunneling: only part of your traffic enters the tunnel; DNS queries stay outside and go straight to your ISP;
  • The system resolver is not taken over: the VPN client never rewrites your system DNS settings, so queries still go to the originally configured recursive servers;
  • Applications resolve on their own: some apps implement their own DNS logic or use hard-coded servers (for example DoH), bypassing system settings entirely.

What a DNS leak exposes

  • Observable browsing: even when HTTPS encrypts the content, the lookups themselves are visible, revealing every domain you visit;
  • Location hints: if the resolution differs from your exit IP, it can indirectly hint at your real location;
  • Filtering and redirection: a local network that can see your domain names can filter, redirect, or poison responses.

How to detect a DNS leak

The idea is to compare the resolver’s exit. A leak test generates unique random subdomains, lets your system resolve them, and records which IPs reach the test service’s authoritative DNS. If those IPs differ from your current public exit (the VPN or proxy), your DNS queries are leaking.

LE59’s DNS Leak Test tool works exactly this way: it relies on real callbacks of random subdomains arriving at LE59’s authoritative DNS, and the results may show real-ip callbacks. One important caveat: receiving no DNS query does not mean there is no leak. Queries can be cached or intercepted in some environments, so an empty result should never be treated as proof of safety.

How to fix a DNS leak

  • Make sure your VPN or proxy client takes over the system DNS configuration and points resolvers inside the tunnel;
  • Disable unnecessary split tunneling, or ensure DNS traffic enters the tunnel as well;
  • Use a trustworthy public DNS (including DoH/DoT) and check whether apps bypass system settings;
  • Re-run the test after changing networks or configuration to confirm the exit stays consistent.

Want to know whether your current connection is leaking? Open the DNS Leak Test tool — no login required, and the result is only for that check.

Related toolhttps://ip.le59.com/ja/dns-leak ↗
LE59TOOLS

小さなツールを、丁寧に。

すぐに使えて、プライバシーを優先。

Products

Network ToolsLottery ToolsLink Tools

Tools

URL Safety AnalysisShort-link ResolverURL ParserRedirect CheckerQR Parser

Company

About LE59Service statusChangelogContact

Legal

PrivacyTermsSecurityResponsible use
© 2026 LE59 Tools