In short
- DNS turns site names into IP addresses; almost every request to a site or app begins with a DNS query.
- Whoever answers your DNS queries sees the list of domains you reach.
- With a VPN on, those queries should go through its DNS servers; a leak means some of them go elsewhere.
- The usual causes are a weak client, unhandled IPv6, and DNS servers set manually in the system.
- A leak test shows which DNS servers answered and whether your provider or country is visible.
What DNS does and why it matters for privacy
When you open a site, your device first asks: what IP address does this name have? A DNS server answers — usually your provider's, assigned by default.
That query goes out before every new connection: for sites, app updates and background services.
Whoever operates the DNS server sees the stream of queries: which domains, from which address, at what time and how often.
Even without page content, that is a detailed picture of activity. So where your DNS queries end up is a privacy question, not just a technical one.
How a leak happens
Once connected, a VPN should take DNS over: sending queries to its own DNS servers inside the encrypted channel.
A leak occurs when the system or an app carries on using the previous DNS server. A common case is unhandled IPv6: the client covers IPv4 while IPv6 queries go out directly.
Other causes are a weak or misconfigured client, DNS servers entered manually in the system, and operating system features along the lines of "pick the fastest DNS".
From the outside everything looks fine: the VPN is connected and sites open. But some queries are going around it, and without a test that is hard to notice.
What is actually visible during a leak
The operator of the DNS server — as a rule, your provider — sees a list of domains tied to your address and the time of day.
Page content stays closed: HTTPS protects it. What leaks is the roster of sites and services.
For many purposes that list of domains is exactly what someone wanted to keep to themselves, including the country they are connecting from.
If your provider sees your DNS queries, changing your IP through a VPN achieves less than it appears: the network address changed, but the source of the domain list did not.
How to check
Run a leak test with the VPN connected. The tool shows which DNS servers answered the queries and which network they belong to.
If your provider's DNS server is among them, or your real country is displayed, that is a sign of a leak.
If only the VPN service's DNS servers and its location show up, DNS is travelling through the protected channel.
It is worth repeating the test after changing network — moving from Wi-Fi to mobile data, for instance — because DNS settings can change with it.
What to do about it
Use a client that forces DNS through the tunnel. In good apps that is the default behaviour.
If your client does not handle IPv6, disable IPv6 for the connection or switch to a client that accounts for it.
Remove manually entered DNS servers from your system settings unless you need them for something specific.
Repeat the test after each change — that is how you confirm queries are no longer slipping past.
How MaskNet handles it
For traffic that goes through the protected MaskNet network, DNS queries are directed to the service's own servers. The list of domains does not reach your provider's DNS server.
Local Russian services that use a direct connection are recognised as usual — that is part of smart routing, not a separate mode.
So both the address of the connection and the source of the DNS queries belong to the MaskNet network rather than to your provider.
You can confirm this yourself: the leak test shows which DNS servers answer while MaskNet is connected.
What to remember
- A DNS leak means DNS queries going around the VPN, straight to your provider's DNS server.
- During a leak your provider sees the list of domains, even though page content is protected by HTTPS.
- Common causes are unhandled IPv6, a weak client and manual DNS settings.
- A leak test shows which DNS servers answer and whether your provider is visible.
- MaskNet sends DNS for tunnelled traffic to its own servers, and the tool lets you verify it.

