Solutions
Home & FamilyBusinessMSP / MSSP
Tools
Domain CheckerDNS Leak TestThreatDNS
Company
PricingGuidesDocsAboutContact
Home / Tools / DNS Leak Test

Who can see your DNS?

Find out which resolver answers your lookups, whether you’re protected by DNSAFE, and whether your browser leaks your IP. Takes about 10 seconds.

About this test

How it works

What does this test check?

Your browser looks up a few unique, one-time addresses. Only DNSAFE’s servers can answer them, so we can see exactly which resolver asked — your ISP, Google, Cloudflare, or DNSAFE itself. We also check your public IP and whether WebRTC exposes a different one.

What is a DNS leak?

A DNS leak is when your lookups go to a resolver you didn’t intend — usually your ISP — even though you’re using a VPN or a private DNS service. Whoever runs that resolver can see every site you visit.

It says “not protected”, but I set up DNSAFE.

Check for a backup DNS server (like 8.8.8.8) on your router or device, and turn off your browser’s own “secure DNS” setting, which sends lookups straight to Google or Cloudflare. Then run the test again.

Is any of my data stored?

The test addresses and the resolver IPs that asked for them are kept for 15 minutes to show your result, then only in normal service logs. Nothing is linked to your identity.

Stop the leak.

Every DNSAFE plan filters threats and keeps your lookups off your ISP’s resolver.