Skip to main content
Free tool · DNS leak test

DNS leak test

Run a DNS leak test against your active connection. We probe multiple resolvers and report which servers your queries actually reached.

Live · DNS leak probe
Exit-IP verdict
Possible mismatch

We compare the IP your HTTPS traffic exits from (as seen by our edge) against the IP a public anycast probe sees on the same family. A same-family mismatch usually means traffic is being routed outside the tunnel. This is a heuristic, not a forensic test.

Cloudflare’s trace endpoint didn’t respond — it’s sometimes blocked by ad-blockers or restrictive networks. The origin probe still ran.

HTTPS exit IP (our edge)
Cloudflare sees
Cloudflare colo
Cloudflare WARP
Off

For a forensic test we’d run our own resolvers — that ships in a future release.

How it works

What this test actually does.

The probes, the servers, the assumptions — exposed up front so you know what the result means.

We compare the exit IP our edge sees against the exit IP Cloudflare's anycast edge sees on the same family. A same-family mismatch usually means traffic is being routed outside the tunnel. This is a consistency check, not a forensic DNS probe — that requires our own authoritative resolver, which ships in a future release.