DNS leaks
DNS translates domain names into network addresses. If a VPN configuration intends DNS requests to use a protected resolver but the device continues sending them to the local network or internet provider, that is commonly described as a DNS leak.
Multiple resolvers are not automatically a leak; the expected policy determines what is correct.
IPv4, IPv6 and browser behavior
A configuration may correctly route IPv4 while leaving IPv6 outside the tunnel, or the reverse. Browsers can also expose local or network addresses through real-time communication features depending on platform behavior and permissions.
Modern browsers have changed these behaviors over time, so old testing instructions may no longer describe current results.
How to interpret leak tests
Run tests before and after connecting, compare expected DNS resolvers and addresses, and repeat on more than one network. A test website can observe only the traffic that reaches that site; it cannot prove that every application and route is correct.
Use operating-system routing and DNS diagnostics when a precise answer is required.
Continue learning
Browse the VPN learning center, review secure configuration delivery, or check client compatibility.