Building DNS Leak Audit
A DNS leak checker that tells you who resolves your queries in plain terms, instead of selling you a VPN.

I have lately been enjoying using AI to improve the UI of tools I already use with custom scripts and CSS. Recently one of those curiosities became more substantial.
I upgraded my home network a few weeks ago and ran a DNS leak test to check it. Many of these tools come from VPN providers. They push their product, or say you have a leak because you're not on their network. Others dump data that a non-technical user can't use.
So I built (or may have slightly over engineered) my own. It shows who resolves your DNS queries, in plain terms.
What does it do differently?
Intelligent, Context-Aware Verdicts
Users can declare whether they're on a VPN (Yes, No, or Not sure) to provide context. If a user visits the site from a recognized consumer ISP (for now, the top ~50 ASNs globally) but they haven't manually answered, the tool intelligently defaults to No, ensuring the audit won't misdiagnose standard home or mobile internet routing as a VPN leak.
Gets the nuance
- Same-Network DNS: Confirms traffic stays within the ISP or VPN tunnel.
- Custom DNS in Use: Recognizes when third-party resolvers (DoH, manual router DNS) are active, reassuring the user that this is safe if intentional.
- Split DNS in Use: Identifies when queries resolve partly through the ISP and partly through an external service (more common with Connectivity Assist on iOS or dual-stack misconfiguration).
- True DNS Leak Warning: Fires when there is definitive proof, such as a user declaring VPN = Yes while queries leak out through their ISP or a network outside the VPN.
Helps you verify
If you've manually chosen to use a public DNS resolver such as one from Google, Cloudflare, Quad9 or OpenDNS, it verifies whether all (or some) observed queries match that expectation.
Standard vs. Extended Checks
- Standard Check (6 queries): Fast, lightweight, and completes in ~2–3 seconds for routine checks.
- Extended Test (36 queries): Optional, to catch intermittent leaks or secondary DNS fallbacks that fewer queries might miss.
If you try it, I would love to hear what you think.