DNS Leak Test
Check whether your network is leaking information through DNS or Cloudflare's edge. Runs entirely in your browser.
Limitations of this test
This v1 detects mismatches in your edge-visible IP, country, and connection metadata — useful for catching VPN failures, WARP anomalies, and corporate gateway routing. Full multi-resolver DNS leak detection (where we fingerprint every recursive resolver handling your queries) requires a dedicated authoritative DNS server we don't run yet. We'll roll that out at a wildcard subdomain after launch.
For a thorough leak check today, pair these results with a manual comparison: the IP shown above should match your public IP and your VPN provider's expected IP. Mismatches indicate something's leaking.
What we test
- Edge-visible IP — what Cloudflare's network sees when your browser connects. This catches the case where your home IP appears despite a VPN being on.
- Edge-visible country — verify your VPN's claimed location matches what's actually showing up.
- WARP / Gateway flags — detect if Cloudflare's WARP service or a corporate Gateway is intercepting your traffic.
- Protocol versions — see whether you're getting modern TLS 1.3 and HTTP/3 or falling back to older protocols.