DNS leak
A DNS leak is a name lookup that travels outside the path you intended, so a resolver you did not choose learns the hostname you were about to visit.
A DNS leak is a name lookup that travels outside the path you intended, so a resolver you did not choose learns the hostname you were about to visit. The request itself may go through the proxy perfectly well; the lookup that preceded it did not.
#Who resolves the name
This depends entirely on the proxy protocol and on how the client was told to use it. The difference is invisible in the response you get back, which is why the mistake survives so long.
| Setup | Name resolved by |
|---|---|
| HTTP CONNECT to a hostname | The proxy |
| HTTP forward proxy, absolute-form request | The proxy |
| SOCKS5 with an address type of IPv4 or IPv6 | The client, before connecting |
| SOCKS5 with the domain-name address type | The proxy |
RFC 1928 defines that domain-name address type, X'03', precisely so the proxy can do the lookup. Whether your client uses it is a client-side decision.
#The commonest instance
curl -x socks5://gateway.example:1080 https://example.com # client resolves
curl -x socks5h://gateway.example:1080 https://example.com # proxy resolves
The extra h is the whole difference. The first form asks your system resolver for the name, which reaches your ISP’s resolver from your own address, and the destination is disclosed there before any proxied byte moves. Nothing in the response tells you which of the two happened, and both succeed.
Browser automation has its own version of this. A browser launched with a proxy setting may still resolve names through the operating system for some code paths, and extensions can add more. Verify by capturing traffic on your own interface rather than by reading the configuration.
#Why it matters beyond privacy
A leaked lookup also breaks geo-targeting. Large sites answer DNS differently by resolver location, so resolving locally and connecting through a distant exit node can send you to the wrong edge server entirely, producing content that matches neither location.
#Commonly confused with
An address leak, where the destination sees your real address, is a different failure with a different test. A DNS leak discloses to a resolver operator, not to the destination, and the destination may see nothing wrong at all. Encrypted transports such as DNS over HTTPS change who can read the lookup, but not which machine performs it.