Troubleshooting · Plain-English answer
A DNS leak means your name lookups bypass the VPN tunnel and go to your internet provider, revealing which sites you visit. To fix one, make sure your VPN handles DNS itself, remove manual DNS settings on the device, disable smart multi homed resolution on Windows, then run a leak test again.
Every website visit starts with a DNS lookup that turns the name into an address. When those lookups slip outside the tunnel, your ISP receives a running list of every domain you contact, timestamped, even though the page content itself stays encrypted. That defeats a large part of the reason for running a VPN.
Leaks happen when the operating system clings to its old DNS servers after the VPN connects, when someone has set manual DNS on the adapter, or when Windows helpfully queries every interface at once.
Start with a test at /tools/dns-leak-test/ while connected. If your ISP's servers appear, remove any manual DNS entries on your network adapter, reconnect the VPN, and test again. On Windows, the smart multi homed name resolution feature is a known leak source and can be disabled via group policy.
A good VPN app forces all lookups to its own resolvers inside the tunnel, so an up to date app on default settings should test clean. If leaks persist after that, raise it with your provider's support rather than living with it.
ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.
Get ROOT VPN, free