What is DNS?
DNS translates domain names (like skypath.cloud) into IP addresses. Every website visit starts with a DNS query.
Whoever resolves that query can see which domains you looked up — even if the page content is encrypted with HTTPS.
Privacy
Free DNS leak check for VPN users — see which DNS resolvers queried a unique SkyPath hostname (classic resolver-trace).
Resolver-trace — which DNS IPs queried SkyPath
A DNS leak is when normal domain lookups go through your ISP (or another unexpected resolver) instead of your VPN’s DNS — revealing which sites you visit.
This test creates a unique hostname and records which recursive resolvers queried SkyPath’s authoritative DNS for it — the classic resolver-trace method.
Compare resolver IPs to your VPN provider’s DNS. If you see your ISP’s resolvers while connected to a VPN, fix OS DNS, split tunneling, or IPv6.
DNS translates domain names (like skypath.cloud) into IP addresses. Every website visit starts with a DNS query.
Whoever resolves that query can see which domains you looked up — even if the page content is encrypted with HTTPS.
Leaks often occur when the OS keeps using ISP DNS, when split tunneling sends DNS outside the VPN, or when IPv6 DNS bypasses IPv4-only VPN tunnels.
Fixes usually involve enabling the VPN's DNS setting, disabling split tunneling, or blocking non-VPN DNS in your firewall.
We generate a one-time hostname under a SkyPath-controlled zone. Your browser triggers a normal OS DNS lookup for that name.
SkyPath’s Probe authoritative DNS logs which resolver IPs asked for it. Those IPs are the evidence behind the verdict — not a DoH reachability probe.
A DNS leak is when DNS requests travel outside your VPN tunnel, exposing your browsing activity to your ISP or another third party.
It shows which resolvers queried our unique hostname from your network path. That is strong evidence for VPN DNS behavior, but OS settings, IPv6, and split tunneling can still change on the next connection — re-test after changes.
Use your VPN app's DNS setting, disable manual DNS overrides, turn off split tunneling for DNS, and consider blocking DNS to addresses other than your VPN. Then re-run this test.
The Probe must receive DNS queries for your unique hostname. If authoritative DNS is not delegated yet in an environment, or your network blocks the lookup, results stay pending. Try again or check network filters.