Home/Answers/Privacy

Privacy · Plain-English answer

What is a DNS leak?

A DNS leak happens when your device sends website name lookups outside the VPN tunnel, usually to your ISP's DNS servers. Your traffic stays encrypted, but the list of every site you visit escapes to your ISP anyway, quietly undoing much of the privacy the VPN was meant to provide.

How DNS leaks happen

Every time you visit a website, your device first asks a DNS server to translate the name, like example.com, into an IP address. A properly configured VPN sends those lookups through the tunnel to its own resolvers. A leak occurs when the operating system keeps using its old DNS settings instead, often after a network change, because of manual DNS configuration, or through features like some browsers' own DNS handling.

The result is subtle. Everything appears to work, your IP is hidden, but your ISP still receives a running list of every domain you visit.

Detecting and fixing leaks

Testing takes seconds. Connect your VPN and run the checker at /tools/dns-leak-test/. If the DNS servers shown belong to your ISP rather than your VPN provider, you have a leak.

Fixes include using your VPN app's built-in leak protection, removing manually set DNS servers from your device, and reconnecting after network changes. ROOT VPN routes DNS queries inside the WireGuard tunnel by design, but testing your own setup once is still worth the seconds it takes.

Related questions

Does a DNS leak expose the pages I read?
It exposes domains, not full pages. Your ISP would see that you visited a site but not which articles you read there. The domain list alone is still very revealing.
How often should I test for leaks?
Once after installing a VPN, and again after major OS updates or if you change network settings. It is a quick check and leaks are otherwise invisible.

Keep reading

More from the ROOT VPN answers hub.

Private in one tap.

ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.

Get ROOT VPN, free