FAQs

Does changing my DNS server hide my browsing from my ISP?

No. Switching to 8.8.8.8 or 1.1.1.1 changes which service provider answers your queries, but it doesn’t encrypt them. Standard DNS is sent in cleartext, so your ISP can still see every domain you look up, and so can anyone else on the network.

To actually hide it, you need encrypted DNS (DoH or DoT), or a VPN, which encrypts your DNS queries along with the rest of your traffic.

Is it safe to use a free public DNS server?

From a well-known provider, generally yes. But as always with free, there’s a trade-off.

These services see every domain you look up, so their logging policy matters more than their speed. Quad9 is run by a Swiss non-profit and blocks known-malicious domains by default. Cloudflare publishes independent audits of its data retention. Google retains more, for longer.

What you want to avoid is a DNS server you didn’t choose and don’t recognise, which is exactly what this tool is designed to help you catch.

What is a DNS leak, and how do I check for one?

A DNS leak is when your DNS queries escape your VPN tunnel and go through your ISP’s servers instead of your VPN’s. Your connection looks encrypted, but your ISP can still see every site you visit.

The quick check: connect your VPN, and then run the tool at the top of this page. The ISP column should show your VPN provider, or whatever you’ve manually set. If it shows your ISP instead, you have a leak. For a full check, use the Top10VPN.com leak test tool.