How to Test for DNS Leaks in Chrome Specifically
Patrick Bushe
November 22, 2024 · 5 min read
A DNS leak happens when the lookups that turn website names into addresses go to your internet provider instead of through your VPN. Your traffic is hidden, but the list of sites you visit isn't. Chrome has its own DNS setting, which can change what a leak test shows.
How to test for a DNS leak
- Connect to your VPN.
- In Chrome, open a DNS leak test such as dnsleaktest.com (use the extended test), browserleaks.com/dns or ipleak.net.
- Look at the DNS servers listed and who runs them.
No leak: the servers belong to your VPN provider, or a DNS service you chose on purpose, in the VPN's location. Leak: you see your internet provider's servers, or servers in your real location.
Run the test again with the VPN off to see what your normal DNS servers look like, so you can tell them apart.
Why Chrome's Secure DNS setting matters
Chrome can send DNS lookups over an encrypted connection (DNS over HTTPS). Find it under Settings → Privacy and security → Security → Use secure DNS.
- If it's set to a provider such as Google or Cloudflare, Chrome sends its lookups to that provider, even with the VPN on. A leak test will then show Google's or Cloudflare's servers. That's not a leak to your internet provider, since the lookups are encrypted, but it means a provider other than your VPN sees which sites you look up.
- If it's set to your system's default (shown as OS default or With your current service provider, depending on your Chrome version), Chrome uses whatever DNS your system uses, which with a VPN should be the VPN's.
If you want your VPN to handle all lookups, choose the system default and test again.
VPN apps vs VPN extensions
- A VPN app routes the whole computer's traffic. Good apps have a DNS leak protection setting. Make sure it's on.
- A VPN browser extension is usually a proxy that covers only Chrome's traffic. Other apps on your computer still use your normal connection and DNS. Test from Chrome to check the extension.
How to fix a DNS leak
- Turn on DNS leak protection in your VPN app, and its kill switch if it has one.
- Set Chrome's Secure DNS to the system default, or to the DNS service your VPN recommends.
- If your VPN doesn't support IPv6, disable IPv6 in the VPN app or your network settings, since IPv6 lookups can go around it.
- Test again after each change.
DNS leaks aren't the only leak
WebRTC, the technology behind video calls in the browser, can reveal your real IP address to websites even when DNS is fine. Leak test sites usually check both. To block that in Chrome, see how to block WebRTC without breaking video calls, or use WebRTC Privacy Shield, which sets Chrome's WebRTC policy for you.