This check helps you understand which DNS resolvers are visible to a domain that is operated for the test. It does not inspect browser settings, guess a resolver from an IP range, or test a visitor until the visitor starts the check.
Purpose
A DNS resolver can reveal that a device asked about a name even when the website connection itself is protected. This tool shows the resolver addresses that reached the configured observer for one randomized test hostname.
How The Check Works
After you choose Start DNS Check, the browser requests one temporary child hostname below a domain delegated to the observer. The application then polls its own fixed observer API for that test. Visitors cannot choose the observer URL or DNS target.
Reading Results
An inconclusive result lists observed resolvers but has no trusted comparison list. A matched result means every observed resolver matches the administrator-approved addresses. A potential leak result means at least one observed resolver is outside that list; it is a signal to investigate, not proof of a browser defect.
Privacy And Limits
The observer sees the DNS request needed for the test. This page never receives your DNS configuration. Resolver observations can vary because of browser DNS privacy features, caches, VPNs, split DNS, network policy, and the selected comparison list. For operating steps and troubleshooting, open DNS Leak Check.