A DNS leak happens when your DNS queries — the requests that translate domain names like google.com into IP addresses — bypass your VPN tunnel and go directly to your ISP servers instead. The result: your ISP can see every website you visit, even though your IP address appears hidden. DNS leaks are one of the most common and most overlooked privacy failures among VPN users, and most people who have one have no idea.
How DNS Works and Why It Leaks
Every time you type a URL into a browser, your device sends a DNS query to translate that domain name into an IP address. By default, this query goes to your ISP DNS server. Your ISP logs every one of these queries — building a complete record of every domain you visit, timestamped and linked to your account.
When you use a VPN, DNS queries should route through the VPN encrypted tunnel and resolve through the VPN private DNS servers. A DNS leak occurs when this routing fails — the query slips outside the VPN tunnel and goes directly to your ISP. Your IP address may appear to be the VPN server IP when websites check it. But your entire browsing history is simultaneously being logged by your ISP through the leaked DNS queries.
Why DNS Leaks Happen
DNS leaks are caused by specific technical conditions that can affect any operating system. Understanding the causes helps you choose the right fix for your situation.
- Windows Smart Multi-Homed Name Resolution — Windows 8 and later send DNS queries to multiple resolvers simultaneously for speed optimization. This sends queries outside the VPN tunnel even when a VPN is actively connected.
- IPv6 leaks — Many VPNs only tunnel IPv4 traffic. If your connection uses IPv6, those DNS queries travel outside the VPN tunnel directly to your ISP.
- Misconfigured VPN software — VPNs that do not properly set themselves as the system DNS resolver create leaks either by design flaw or software bug.
- Router-pushed DNS settings — Your router may push ISP DNS configuration via DHCP that overrides the VPN DNS settings on your device.
- Browser DNS prefetching — Some browsers proactively resolve domain names for performance reasons, bypassing VPN DNS settings in the process.
How to Test for a DNS Leak
Testing for a DNS leak takes under a minute. Connect to your VPN, then visit the SitusProxy DNS Leak Test. The test shows which DNS servers your queries are actually reaching. If you see your real ISP name — Telkom, IndiHome, Biznet, Telkomsel, XL, or whichever provider you use — instead of your VPN provider DNS, you have a confirmed DNS leak. Run the test several times. DNS can occasionally route correctly and then leak on subsequent queries, so a single clean result does not guarantee full protection.
How to Fix a DNS Leak
Fix 1: Use a VPN With Built-in DNS Leak Protection
This is the most reliable and comprehensive fix. A VPN that routes all DNS queries through its own private servers by default eliminates the leak entirely. NordVPN uses its own private DNS servers, has been independently tested to confirm no DNS leaks during normal operation, and blocks IPv6 traffic to prevent IPv6-based DNS leaks. This fix addresses the problem at its source.
Fix 2: Enable DNS-Over-HTTPS in Your Browser
DNS-over-HTTPS encrypts DNS queries and sends them to a private resolver, bypassing your ISP DNS server entirely. In Chrome, go to Settings then Privacy and Security then Security, and enable Use secure DNS with Cloudflare selected. In Firefox, go to Settings then General then Network Settings and enable DNS over HTTPS. This fix works at the browser level and does not require a VPN.
Fix 3: Change System DNS to a Private Alternative
Changing your system DNS to Cloudflare (1.1.1.1 and 1.0.0.1) or Google (8.8.8.8 and 8.8.4.4) routes queries away from your ISP DNS server. This does not encrypt DNS traffic — it only changes which server receives your queries. For full protection against surveillance, combine this with a VPN that encrypts the DNS queries in transit.
Fix 4: Disable Windows Smart Multi-Homed Name Resolution
Open the Group Policy Editor (gpedit.msc), navigate to Computer Configuration then Administrative Templates then Network then DNS Client, and set Turn off smart multi-homed name resolution to Enabled. This stops Windows from sending DNS queries to multiple resolvers simultaneously and keeps DNS within the VPN tunnel.
DNS Leak vs IP Leak vs WebRTC Leak
These are three distinct privacy failures that expose different information and require separate tests. A DNS leak means your ISP can see every domain you visit even though your IP appears masked. An IP leak means your real IP address is directly exposed to websites despite a VPN being active. A WebRTC leak means your browser reveals your real IP through the WebRTC API, bypassing VPN protection entirely at the browser level. A complete privacy check requires testing for all three using the DNS Leak Test, IP Checker, and WebRTC Leak Test together.
Frequently Asked Questions
What is a DNS leak in simple terms?
A DNS leak means your internet provider can see every website you visit even when you are using a VPN. Your IP address may appear hidden, but your browsing history is exposed through DNS queries going directly to your ISP outside the VPN tunnel.
Do all VPNs prevent DNS leaks?
No. Many VPNs, especially free ones, do not properly route DNS through their encrypted tunnel. Always test with a DNS leak tool after connecting to any VPN, and choose a provider with explicitly advertised and independently verified DNS leak protection.
How serious is a DNS leak?
Very serious. A DNS leak exposes your complete browsing history to your ISP despite using a VPN. In Indonesia, ISPs are required to retain certain data and can provide it to authorities on request. A DNS leak defeats the primary privacy purpose of using a VPN.
Does changing DNS to 1.1.1.1 fix a DNS leak?
Partially. Switching to Cloudflare 1.1.1.1 routes DNS queries away from your ISP but does not encrypt them in transit. For full DNS leak protection, use a VPN that encrypts all DNS queries and routes them through its own private servers.

