Privacy · Plain-English answer
A DNS leak happens when your device sends website name lookups outside the VPN tunnel, usually to your ISP's DNS servers. Your traffic stays encrypted, but the list of every site you visit escapes to your ISP anyway, quietly undoing much of the privacy the VPN was meant to provide.
Every time you visit a website, your device first asks a DNS server to translate the name, like example.com, into an IP address. A properly configured VPN sends those lookups through the tunnel to its own resolvers. A leak occurs when the operating system keeps using its old DNS settings instead, often after a network change, because of manual DNS configuration, or through features like some browsers' own DNS handling.
The result is subtle. Everything appears to work, your IP is hidden, but your ISP still receives a running list of every domain you visit.
Testing takes seconds. Connect your VPN and run the checker at /tools/dns-leak-test/. If the DNS servers shown belong to your ISP rather than your VPN provider, you have a leak.
Fixes include using your VPN app's built-in leak protection, removing manually set DNS servers from your device, and reconnecting after network changes. ROOT VPN routes DNS queries inside the WireGuard tunnel by design, but testing your own setup once is still worth the seconds it takes.
ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.
Get ROOT VPN, free