← Back to account

DNS leak test

Your VPN can hide which sites you visit two different ways: by tunnelling the traffic, and by tunnelling the lookups (DNS). This test checks the second one — whether the names you look up reach YMR's resolver inside the tunnel, instead of leaking to your network provider or ISP.

Run this on the device you want to test. The browser you are reading this in is the device being measured. To test a phone, open this page on the phone.

What this test can and cannot tell you

It answers: did my lookup reach YMR's resolver through the tunnel? That is the property that hides your browsing from your provider.

It does not list every resolver the outside world can see. For that extended view, run the external test below from this same device — it is a third-party service, not affiliated with YMR, and it sees the IP you run it from.

Open the extended test (dnsleaktest.com) →

If the result says your DNS is not protected

  1. Is the tunnel actually on? Open the WireGuard app on this device and check the tunnel is activated. Offline devices leak by definition.
  2. Is this a "Pipe" device? Pipe only tunnels your traffic — it deliberately leaves your DNS with your network. Re-add the device as Privacy or Security to route DNS through YMR.
  3. Browser "Secure DNS" / DoH. If your browser or OS is set to use DNS-over-HTTPS (Chrome "Secure DNS", Firefox "DNS over HTTPS", or a system DoH setting), it bypasses the VPN's resolver by design. Turn it off for this device, or set it to use the system resolver.
  4. Still failing? Email info@ymrtech.com with the result above.