Network Tools DNS leak DoH public IP

DNS Privacy Check

Best-effort DNS privacy smoke: public IP plus DNS-over-HTTPS. Not a full ISP DNS leak lab.

Interactive tool

Run the test

Runs in your browser

Best-effort only: resolves your public IP and optionally proves DNS-over-HTTPS works via Cloudflare DoH. Full ISP DNS query logging is not available from a browser page — this tool does not claim definitive leak / no-leak results.

For candidate IPs that may differ from your HTTP path, also run the WebRTC Leak test.

Press Run to gather public IP and DoH status.

Ready.

Permission status

Checked in your browser. DeviceHub does not store permission grants.

  • Special permission Not required

Live results

Metrics update as you run the test. Nothing is uploaded.

Loading

Waiting for interactive tool output…

Device information

Labels and capability details reported by your browser.

No device details yet.

Description

About DNS Privacy Check

Introduction

DNS Privacy Check is a best-effort privacy smoke: it resolves your public IP and optionally probes DNS-over-HTTPS, then explains what a browser page cannot prove. It is not a full ISP DNS leak laboratory and does not log which recursive resolver answers your everyday queries.

What this tool does

On Run, it resolves public IP via DeviceHub /api/client-ip when available (with possible ipify fallback) and probes Cloudflare DoH for a sample record. Results include IP source labels, DoH status, and honesty rows. It does not claim leak or no-leak.

When to use it

Use it after enabling a VPN, when teaching the gap between DoH success and ISP resolver visibility, or before escalating to dedicated leak labs. Prefer WebRTC Leak Test for ICE candidate IPs, IP Address for a calm HTTP egress snapshot.

How it works

Public IP uses the same DeviceHub and ipify helpers as other network tools. DoH is a fetch to Cloudflare’s public dns-json endpoint. Browser fetch cannot attach to OS resolver sockets. Permissions stay none. Third-party fallbacks observe your egress when they run.

Step-by-step instructions

  1. Open DNS Privacy Check on the VPN or network path you want to inspect.
  2. Click Run and wait for public IP and DoH results.
  3. Read honesty rows; inconclusive by design is valid when proof is impossible.
  4. Cross-check with WebRTC Leak Test and IP Address before drawing conclusions.

Common problems

Expecting a red or green leak verdict misunderstands scope. DoH success does not prove every app uses encrypted DNS. Split-tunnel VPNs often leave DNS on the ISP while HTTP exits elsewhere.

Privacy explanation

IP resolution may hit DeviceHub or ipify; DoH sends a query to Cloudflare’s public resolver. DeviceHub does not upload results for ad profiling. Permissions stay none.

Runtime principles

Built for the browser

What happens when you run this test — without downloads or accounts.

  1. 01

    Runs in your browser

    DNS Privacy Check uses standard web APIs — no install, extension, or desktop app required.

  2. 02

    Reads what the browser allows

    Results come from events and capability signals the web platform exposes for this session.

  3. 03

    Private by default

    Input and diagnostic values stay in your browser session for display — nothing is sold as media.

Compatibility

Supported browsers

Expected support for modern engines. Individual APIs may still vary by device.

  • Chrome

    supported

    Latest stable

  • Firefox

    supported

    Latest stable

  • Safari

    supported

    Latest stable

  • Edge

    supported

    Latest stable

Devices

Supported devices

Hardware and form factors this browser test is designed to exercise.

  • Wi‑Fi connections

    Browser network hints when the Network Information API exists.

  • Ethernet

    Desktop sessions with stable connectivity signals.

  • Cellular

    Mobile browsers that expose connection type hints.

Privacy

Your data stays with you

DNS Privacy Check is built privacy-first. Diagnostics run in your browser session whenever web APIs allow.

Read our privacy policy

Troubleshooting

Common problems

Quick fixes before you dig into FAQs.

DoH works but I still worry about ISP DNS
This page cannot log which recursive resolver your OS uses for normal browsing. A working Cloudflare DoH probe only proves HTTPS DNS to that endpoint succeeded, not that every app uses DoH.
Public IP resolve failed
Check VPN, extensions blocking fetch, and captive portals. DeviceHub /api/client-ip may be missing locally; ipify fallback needs third-party reachability.
Results say inconclusive by design
That is correct. Compare with WebRTC Leak Test for ICE candidate IPs and IP Address for HTTP-path baseline rather than expecting a definitive leak verdict here.

FAQ

Frequently asked questions

Structured answers for users and FAQ rich results.

Browse FAQs
Is this a full ISP DNS leak laboratory?
No. DNS Privacy Check is best-effort. DeviceHub does not operate an authoritative DNS logger that records which recursive resolver answered your everyday queries.
What does this page check?
It combines public IP signals (DeviceHub /api/client-ip and/or ipify), optional DNS-over-HTTPS hints, and guidance to compare with WebRTC Leak Test, not a complete resolver inventory.
What does inconclusive mean?
Honest inconclusive output means the page cannot prove leak or no-leak from browser-visible signals alone. That protects you from false confidence.
Should I use WebRTC Leak Test too?
Yes. ICE candidates can reveal IPs that bypass the HTTP VPN path. DNS Privacy Check and WebRTC Leak Test answer different privacy questions.
Do third parties see my probes?
IP fallbacks and public DoH endpoints observe those requests when they run. Each tool page documents that tradeoff.
Do I need a permission?
No. Permissions remain none, no microphone or camera prompts.

Newsletter

Updates coming soon

A lightweight email digest for new tools and release notes is planned. No signup form is live yet — check Release Notes for product updates.

Release notes

Need another diagnostic after DNS Privacy Check?

Explore related DeviceHub tools that pair well with this test.