How to detect DNS leaks: judgment of results and common misunderstandings
The presence of a DNS service provider on the detection page does not automatically equal a leak; you need to determine whether it complies with the proxy and DNS policies you are using.
Before you start
Operation steps
- 01
Establish an unconnected baseline first
After closing proxy, record the current export IP and DNS providers to avoid mistaking the existing resolution service for proxy.
- 02
Retest after connecting
Open the connection and refresh the detection page to compare whether the export IP and DNS countries or service providers have changed as expected.
- 03
Check browser encryption DNS
The browser may bypass system DNS to use its own DoH service. In order to locate the problem, you can temporarily turn off the browser security DNS and compare again.
- 04
Check client DNS mode
Verify that the client DNS configuration comes from a valid subscription and has not been overwritten by old configuration or customization.
- 05
Do not expose the credentials in the detection screenshot
The IP address can be used as debugging information, but the subscription URL, account number, node key and QR code must be blocked.
After completion, check like this
- Two sets of results before and after connection are recorded
- Find out if your browser has security enabled DNS
- Client configuration updated
- Subscriptions are not disclosed on public pages
FAQ
Does seeing local operator DNS necessarily leak it?
If only the original operator DNS still appears after connection, it is worth continuing to check; however, browser cache, detection station errors and diversion strategies need to be ruled out.
Is one test enough?
It is recommended to change the browser or test the detection service again to avoid misjudgment on a single site.