DNS leak test

A DNS leak means your device sends lookups outside the tunnel, so your ISP can still see which sites you resolve even with a VPN on.

Your current exit IP & location
checking…

How to use the dns leak test

  1. Note your exit IP and country with the VPN off.
  2. Connect the VPN and reload.
  3. If the location still shows your real country/ISP, your connection is leaking.

How to run a full check

  1. Note your exit IP and country above with the VPN off.
  2. Connect your VPN and reload — the IP and country should change to the exit hole's.
  3. If the location still shows your real country/ISP while the VPN is on, your connection is leaking.

How vpn.golf prevents DNS leaks

Every hole runs its own DNS resolver inside the tunnel with query logging disabled, so your lookups never reach your ISP and aren't recorded. More on the how it works page.

Code & API examples

Use this from the command line or your code.

Check exit IP (curl)
curl https://vpn.golf/api/tools/ip
Who's resolving you (dig)
dig +short whoami.akamai.net

See all endpoints at /api/tools/.

Frequently asked questions

When DNS queries bypass the VPN tunnel and go to your ISP's resolver, exposing the domains you visit even though the rest of your traffic is encrypted.

Every hole runs its own resolver inside the tunnel with query logging off, so lookups never reach your ISP and aren't recorded.

It triggers lookups to unique hostnames and records which resolvers answer them. If a resolver belonging to your ISP shows up, your DNS is leaking outside the tunnel.

You should see the VPN's resolver — and only that one. Seeing your ISP's resolver, or a mix that includes it, means some lookups are escaping the tunnel.

Usually a device that's hardcoded to use a specific resolver, IPv6 DNS leaking around an IPv4-only tunnel, or Windows sending lookups to all interfaces at once (smart multi-homed name resolution).

No, but it exposes every domain you resolve — which sites, apps, and services you contact. That browsing history is often as revealing as the content itself.

A resolver can forward queries to upstream servers, so seeing several IPs from one provider is normal. The problem is only when one of them belongs to your ISP or your real network.

No. A leak is your queries going to the wrong (but legitimate) resolver. A hijack is a resolver returning false answers to redirect you. This tool detects leaks, not hijacking.

An IP leak exposes your address directly; a DNS leak exposes the names you look up. You can have one without the other, which is why a full check tests both separately.

Sometimes — disabling IPv6, turning off Windows smart multi-homed resolution, or forcing your system DNS to the VPN's resolver can help. A VPN that pushes its own resolver and blocks others is the cleaner fix.

It encrypts the lookups so your ISP can't read them, but they may still leave the tunnel and reach a third-party resolver. Encryption hides the content; it doesn't guarantee the query stays inside your VPN.

No. The hole's in-tunnel resolver runs with logging off, and the test itself stores nothing — it only reports which resolver answered so you can confirm there's no leak.
Want to hide your IP for real?

vpn.golf is a no-logs WireGuard VPN. Pick a hole, take the shot.

Step up to the tee — free