Test my connection

Ping Argus › What is a DNS leak, and does it matter?

What is a DNS leak, and does it matter?

Every time you open a website, something has to translate the name into an address. That something is your resolver, and unless you have deliberately changed it, it belongs to your internet provider — and it sees the name of every site anyone in your house visits.

Last updated 29 August 2026

What a leak actually is

A DNS leak means your name lookups are reaching a resolver you did not choose. Nothing breaks. Nothing is stolen. What happens is that a complete list of every site your household visits, with timestamps, accumulates somewhere you have no visibility into.

It matters most on a VPN. People pay for a VPN precisely so their provider cannot see where they go — and then their lookups keep going to the provider's resolver anyway, outside the tunnel. The traffic is hidden; the list of destinations is not.

In several countries that list is retained by law, and in some it is sold. Whether that bothers you is a personal decision. The point is that it should be a decision.

How a leak test works

Checking your settings proves nothing, because a router, a piece of software, or the network itself can override them. The only honest test is to ask for a name that nobody on earth has looked up before, on a domain whose nameserver you control, and then watch which servers come asking.

Whoever queries that nameserver is your real resolver, whatever your settings claim. That is how this site does it, and it is why the result sometimes surprises people who were sure they had already changed it.

ECS: the other half nobody mentions

Some resolvers attach part of your IP address to every question they forward on, so that the servers being asked can send you to a nearby copy of the site. It is called EDNS Client Subnet, and it exists for a good reason.

The side effect is that servers you never visited learn roughly where you are. A privacy-focused resolver will not do this. A good leak test tells you whether yours does.

Choosing a resolver, and what each one actually does

  1. Cloudflare (1.1.1.1) — usually the fastest almost anywhere, and audited not to keep a record of your lookups.
  2. Quad9 (9.9.9.9) — a Swiss non-profit. Known malware and phishing domains simply fail to resolve, which is a real layer of protection for a household.
  3. AdGuard DNS (94.140.14.14) — advert and tracker domains stop resolving on every device, including televisions and consoles that cannot run an ad blocker.
  4. DNS4EU (86.54.11.1) — EU-funded and operated inside the EU, blocking malicious domains under EU law.
  5. NextDNS or Control D — you build your own blocklists and see a query log only you can read. Both need a free account.

How to change it

On a router, so the whole house follows: search for “change DNS servers” plus your router's make and model. It usually lives under Internet, WAN or DHCP settings. Enter a primary and a secondary address.

On an Android phone: Settings, Network and internet, Private DNS, then the provider's hostname. This follows you onto mobile data too.

On an iPhone or iPad: providers publish one-tap configuration profiles — search the provider's name plus “iOS profile”.

Nothing here is permanent, and nothing can break your connection. The worst case is that names stop resolving and you set it back.

Does it make my internet faster?

It changes zero megabits. What it changes is the wait before a download starts, and that can be substantial: a page making sixty lookups against a resolver 150 ms away spends several seconds asking questions before anything appears.

Be aware of the trade in the other direction. A filtering resolver checks each name against a blocklist and often sits in fewer cities, so it can be slightly slower — and occasionally it blocks something you wanted, in a way that is hard to diagnose because a blocked site does not say “blocked”, it just fails.

Measure it on your own line

One run, about ninety seconds. Speed, latency under load, jitter, packet loss, NAT behaviour, DNS and global reach — then an honest grade and the one thing worth fixing. Nothing to install.

Run the test

Common questions

What is a DNS leak?

A DNS leak means your name lookups are being answered by a resolver you did not choose, most often your internet provider's — even when you are using a VPN. The result is that a full list of the sites you visit accumulates somewhere you did not intend.

How do I test for a DNS leak?

Checking your settings is not a test, because the router or the network can override them. A real test asks for a name nobody has ever looked up, on a domain whose nameserver the tester controls, then records which servers come asking. Those are your actual resolvers.

Does changing DNS make my internet faster?

It does not change your bandwidth at all. It changes how long you wait before a page starts loading. A single page can trigger dozens of lookups, so a resolver that is 100 ms slower adds up quickly — but the download itself runs at exactly the same speed.

Is 1.1.1.1 better than 8.8.8.8?

Usually faster, and Cloudflare commits to keeping no record of your lookups, which Google does not. Which is best for you depends on where you are — the fastest resolver is the one nearest you, and that is worth measuring rather than assuming.