---
title: "DNS leak"
url: https://proxy.wiki/glossary/dns-leak/
type: Glossary Term
author: "proxy.wiki editorial"
published: 2026-09-06
updated: 2026-09-06
site: proxy.wiki
topics: ["Proxy fundamentals"]
license: CC BY 4.0 — quote freely with attribution to https://proxy.wiki/
---

# DNS leak

> A DNS leak is a name lookup that travels outside the path you intended, so a resolver you did not choose learns the hostname you were about to visit.

**A DNS leak is a name lookup that travels outside the path you intended, so a resolver you did not choose learns the hostname you were about to visit.** The request itself may go through the proxy perfectly well; the lookup that preceded it did not.

## Who resolves the name

This depends entirely on the proxy protocol and on how the client was told to use it. The difference is invisible in the response you get back, which is why the mistake survives so long.

| Setup | Name resolved by |
| --- | --- |
| [HTTP CONNECT](/glossary/http-connect/) to a hostname | The proxy |
| HTTP forward proxy, absolute-form request | The proxy |
| [SOCKS5](/glossary/socks5/) with an address type of IPv4 or IPv6 | The client, before connecting |
| SOCKS5 with the domain-name address type | The proxy |

RFC 1928 defines that domain-name address type, `X'03'`, precisely so the proxy can do the lookup. Whether your client uses it is a client-side decision.

## The commonest instance

```
curl -x socks5://gateway.example:1080  https://example.com   # client resolves
curl -x socks5h://gateway.example:1080 https://example.com   # proxy resolves
```

The extra `h` is the whole difference. The first form asks your system resolver for the name, which reaches your ISP’s resolver from your own address, and the destination is disclosed there before any proxied byte moves. Nothing in the response tells you which of the two happened, and both succeed.

Browser automation has its own version of this. A browser launched with a proxy setting may still resolve names through the operating system for some code paths, and extensions can add more. Verify by capturing traffic on your own interface rather than by reading the configuration.

## Why it matters beyond privacy

A leaked lookup also breaks [geo-targeting](/glossary/geo-targeting/). Large sites answer DNS differently by resolver location, so resolving locally and connecting through a distant [exit node](/glossary/exit-node/) can send you to the wrong edge server entirely, producing content that matches neither location.

## Commonly confused with

An address leak, where the destination sees your real address, is a different failure with a different test. A DNS leak discloses to a resolver operator, not to the destination, and the destination may see nothing wrong at all. Encrypted transports such as DNS over HTTPS change who can read the lookup, but not which machine performs it.

## Frequently asked questions

### Does using a SOCKS5 proxy prevent DNS leaks?

Not by itself. RFC 1928 allows the client to send either a literal address or a domain name. If the client resolves the name first and sends an address, the lookup has already left your machine. In curl, socks5h:// asks the proxy to resolve; socks5:// does not.

### Can a DNS leak break geo-targeting as well as privacy?

Yes. Content delivery networks answer name lookups differently depending on where the resolver sits. Resolving through your own ISP and then connecting through a distant exit node can route you to an edge server chosen for your real location, giving results that match neither the proxy nor you.

### How do I check which resolver was used?

Capture traffic on your own interface while making a proxied request and look for outbound port 53 or encrypted resolver traffic. If a lookup for the target hostname leaves your machine directly, the resolution is local. This is more reliable than any web-based leak-test page.

## Sources

1. [RFC 1928: SOCKS 5, including the domain-name address type X'03'](https://www.rfc-editor.org/rfc/rfc1928.html)
2. [RFC 8484: DNS Queries over HTTPS, which changes who can read a lookup](https://www.rfc-editor.org/rfc/rfc8484.html)
