Most of us assume that once a VPN is connected, our browsing activity is completely hidden. Unfortunately, that's not always the case. A DNS leak can quietly expose the websites you visit—even while your VPN appears to be working exactly as it should.
What Is a DNS Leak, and Why Should You Care?
The primary purpose of a Virtual Private Network (VPN) is to create an encrypted tunnel for all of your internet traffic. Ideally, every DNS request is routed exclusively through the VPN provider's own DNS servers, preventing your internet service provider (ISP) or anyone else on the network from seeing which websites you're trying to access.
However, this doesn't always happen. In some cases, the operating system, browser, or even the VPN client itself may bypass these settings. When that happens, DNS requests escape the encrypted tunnel and are sent directly to your ISP's DNS servers or other third-party resolvers outside the VPN connection. This is what's known as a DNS leak.
The tricky part is that your VPN app may still show a reassuring "Connected" status, and your public IP address may appear completely different. Yet your ISP—or anyone capable of monitoring your network traffic—can still see the domains you're visiting. In other words, a DNS leak can significantly weaken the privacy protections a VPN is supposed to provide by exposing an important part of your online activity.
How to Check If Your VPN Has a DNS Leak
Fortunately, checking for a DNS leak is quick, easy, and requires no technical expertise.
Start by connecting to your VPN and visiting DNSLeakTest.com. The site will display your VPN-assigned public IP address along with your apparent location. This quickly confirms that your VPN connection is active.
Next, choose either the Standard Test, which runs six DNS queries, or the more thorough Extended Test, which performs 36 queries across six rounds. While the Standard Test is usually sufficient, the Extended Test is recommended because it is more likely to detect all DNS servers involved in handling your requests.

Once the test is complete, carefully review the results.
If you see only DNS servers belonging to your VPN provider—or servers located in the same region as your VPN endpoint—your DNS traffic is most likely being routed correctly through the VPN tunnel.

However, if the results show DNS servers operated by your internet service provider, you have a clear DNS leak. In that case, your DNS requests are bypassing the VPN, exposing the domains you visit even though your VPN appears to be connected.
How to Prevent DNS Leaks
The first step is to check whether your VPN service includes built-in DNS leak protection. If you're using Surfshark, for example, DNS leak protection is enabled by default, with all DNS requests routed through the provider's own encrypted DNS infrastructure, significantly reducing the risk of DNS leaks.
However, DNS leaks aren't the only privacy issue worth paying attention to. Another well-known privacy risk involves WebRTC, a browser technology that can sometimes expose network information outside the VPN tunnel. Among mainstream browsers, Brave offers some of the strongest built-in privacy protections thanks to its anti-fingerprinting features and additional controls for handling WebRTC traffic.
You can verify this yourself by visiting a WebRTC leak testing website while connected to your VPN. If everything is configured correctly, Brave will typically report "No Leak", indicating that your real IP address is not being exposed through WebRTC.

There's another setting worth checking as well. In recent years, browsers such as Chrome, Edge, and Firefox have adopted a feature called DNS over HTTPS (DoH). The idea behind DoH is sound: it encrypts DNS requests so they can't be intercepted or modified by third parties.
The potential downside is that some browsers may send these encrypted DNS requests directly to their own DNS providers—typically Cloudflare or Google—rather than using the DNS servers supplied by the VPN. As a result, even if your VPN correctly manages your operating system's DNS settings, the browser may silently bypass them.
To check whether this is happening, return to DNSLeakTest.com and run another test. If the results show Cloudflare or Google DNS servers while your VPN provider uses a different DNS infrastructure, then your browser's DNS over HTTPS feature may be overriding your VPN's DNS configuration
How to disable DNS over HTTPS
-
Chrome / Edge:
Go to Settings → Privacy and security → Security and disable Use secure DNS.Firefox:
Go to Settings → Privacy & Security → Network Settings and uncheck Enable DNS over HTTPS.If the option is greyed out
Sometimes the setting appears locked or disabled with a note like “managed by your organization”. In that case, no further action is needed on your side—this usually means another layer of software (such as a VPN client, antivirus suite, or enterprise policy) is already controlling DNS behavior at system or browser level.
Extra privacy layer: alternative DNS resolvers
As an additional measure, you can replace your default ISP DNS with privacy-focused providers using tools like DNS Jumper or manual network settings. Popular options include:
- Cloudflare (1.1.1.1)
- Quad9 (9.9.9.9)
This doesn't replace a VPN, but it does improve your DNS privacy when you're not connected—or if your VPN isn't fully enforcing DNS routing.
Surfshark + Extra Months Included
The most reliable way to stay protected is to use a VPN that doesn’t just encrypt traffic, but also includes built-in DNS leak protection, proper IPv6 traffic handling, and a reliable kill switch that blocks any internet access the moment the tunnel drops.
Surfshark is one of the most affordable premium VPN services currently available. On top of that, it’s one of the few providers that does not log your activity. This has also been independently audited by Deloitte, one of the largest and most reputable auditing firms in the world.
You can also use Surfshark on an unlimited number of devices. Unlike most VPN providers, there's no limit to how many devices you can connect.

Surfshark offers several subscription plans and payment options. More specifically, the VPN service comes in four packages across three billing periods (1 month, 12 months, 24 months), with increasing features and pricing.
It’s worth noting that on the 24‑month plans, Surfshark gives you three extra months for free. In practice, that works out to 27 months of access starting at €1.99 per month.
- Starter: The most affordable plan at €2.49/month including Alternative ID (24 months plus three extra months free).
- One: Includes everything in Starter, plus extra security tools and Surfshark Antivirus. The lowest price is the 24‑month plan at €2.79/month, plus three extra months free.
- One+: Includes all the features of One, plus data removal from data broker sites and people‑search engines. The cheapest option is the 24‑month plan at €4.49/month, plus three extra months for free.
Support PCsteps
Do you want to support PCsteps, so we can post high quality articles throughout the week?
You can like our Facebook page, share this post with your friends, and select our affiliate links for your purchases on Amazon.com or Newegg.
If you prefer your purchases from China, we are affiliated with the largest international e-shops:

