7 October 2026 · 2 min read

Building DNS Leak Audit

A DNS leak checker that tells you who resolves your queries in plain terms, instead of selling you a VPN.

DNS Leak Audit — see who resolves your DNS and check for leaks

I have lately been enjoying using AI to improve the UI of tools I already use with custom scripts and CSS. Recently one of those curiosities became more substantial.

I upgraded my home network a few weeks ago and ran a DNS leak test to check it. Many of these tools come from VPN providers. They push their product, or say you have a leak because you're not on their network. Others dump data that a non-technical user can't use.

So I built (or may have slightly over engineered) my own. It shows who resolves your DNS queries, in plain terms.

What does it do differently?

Intelligent, Context-Aware Verdicts

Users can declare whether they're on a VPN (Yes, No, or Not sure) to provide context. If a user visits the site from a recognized consumer ISP (for now, the top ~50 ASNs globally) but they haven't manually answered, the tool intelligently defaults to No, ensuring the audit won't misdiagnose standard home or mobile internet routing as a VPN leak.

Gets the nuance

  • Same-Network DNS: Confirms traffic stays within the ISP or VPN tunnel.
  • Custom DNS in Use: Recognizes when third-party resolvers (DoH, manual router DNS) are active, reassuring the user that this is safe if intentional.
  • Split DNS in Use: Identifies when queries resolve partly through the ISP and partly through an external service (more common with Connectivity Assist on iOS or dual-stack misconfiguration).
  • True DNS Leak Warning: Fires when there is definitive proof, such as a user declaring VPN = Yes while queries leak out through their ISP or a network outside the VPN.

Helps you verify

If you've manually chosen to use a public DNS resolver such as one from Google, Cloudflare, Quad9 or OpenDNS, it verifies whether all (or some) observed queries match that expectation.

Standard vs. Extended Checks

  • Standard Check (6 queries): Fast, lightweight, and completes in ~2–3 seconds for routine checks.
  • Extended Test (36 queries): Optional, to catch intermittent leaks or secondary DNS fallbacks that fewer queries might miss.

If you try it, I would love to hear what you think.