Find out which resolver answers your lookups, whether you’re protected by DNSAFE, and whether your browser leaks your IP. Takes about 10 seconds.
Looking up test addresses and watching which resolver asks for them.
| Resolver IP | Provider | Location | DNSAFE? |
|---|---|---|---|
| Waiting for lookups… | |||
Point your router or device at DNSAFE and register this network in your dashboard.
3.12.124.91https://dns.dnsafe.net/dns-querydns.dnsafe.netYour browser looks up a few unique, one-time addresses. Only DNSAFE’s servers can answer them, so we can see exactly which resolver asked — your ISP, Google, Cloudflare, or DNSAFE itself. We also check your public IP and whether WebRTC exposes a different one.
A DNS leak is when your lookups go to a resolver you didn’t intend — usually your ISP — even though you’re using a VPN or a private DNS service. Whoever runs that resolver can see every site you visit.
Check for a backup DNS server (like 8.8.8.8) on your router or device, and turn off your browser’s own “secure DNS” setting, which sends lookups straight to Google or Cloudflare. Then run the test again.
The test addresses and the resolver IPs that asked for them are kept for 15 minutes to show your result, then only in normal service logs. Nothing is linked to your identity.
Every DNSAFE plan filters threats and keeps your lookups off your ISP’s resolver.