dnsleaktest is a free, open source networking & connectivity project written in Batchfile and released under MIT. It has 587 GitHub stars, 70 forks and 2 open issues, and was last pushed 22 days ago. On this registry it ranks #59 of 59 tracked projects in Networking & Connectivity, with 5 head-to-head comparisons available.

What is dnsleaktest?

dnsleaktest is an open-source command-line tool for anyone who wants to check whether their DNS queries are leaking outside their VPN, available for Linux, macOS, and Windows.

What it is

dnsleaktest is a small script, published under the MIT licence and written in Batchfile with Python, shell, and Go variants, that reports your external IP address alongside the DNS servers your connection is actually using. If the network providers behind those two differ unexpectedly, the tool concludes that your DNS traffic may be escaping the intended connection or VPN. The project lives in the networking and connectivity space, with topics covering dns, dns-server, leak-detection, security, and vpn.

The concrete problem it addresses is DNS leakage: a VPN may tunnel your general traffic while your name-resolution requests still reach servers operated by a different network provider, quietly revealing browsing activity to your ISP or another party. By cross-referencing the observed DNS servers against your reported external IP, the tool makes that mismatch visible from the command line rather than requiring you to interpret raw resolver output yourself.

Key capabilities

  • Reports your external IP address together with the DNS servers in use and compares their network providers to flag possible leakage.
  • Ships as dnsleaktest.sh for Linux and macOS, requiring only curl and ping to be installed beforehand.
  • Provides a Python version, dnsleaktest.py, and a Windows batch file, dnsleaktest.bat, retrieved with Invoke-WebRequest.
  • Offers prebuilt Go executables for v1.4 across Linux (amd64, arm64, ARMv7), macOS (Intel and Apple Silicon), and Windows (amd64, arm64, 32-bit), built by GitHub Actions.
  • Supports building from source with GOOS, GOARCH, and CGO_ENABLED=0 go build for any target operating system and architecture.
  • Can run under Docker using --network host on Linux so the test sees the host's network stack and DNS configuration, including local resolvers such as systemd-resolved or NextDNS.
  • Publishes releases on the v1.4 release page and points to a companion site at bash.ws/dnsleak.

Who uses it and how

  • VPN users on Linux who want to confirm their resolver configuration, including setups with systemd-resolved or NextDNS, before trusting the tunnel.
  • macOS and Windows users who run the batch or Python version directly to spot a provider mismatch between their external IP and DNS servers.
  • Operators who prefer prebuilt binaries for their architecture, downloading the appropriate Go executable from the release page instead of compiling anything.
  • Developers who compile the tool themselves with GOOS, GOARCH, and CGO_ENABLED=0 go build to target a specific platform.
  • Anyone testing from Docker, where on macOS and Windows Docker Desktop runs containers in a virtual machine, so the command tests the DNS configuration visible inside the container rather than the host's.

Getting started

Download dnsleaktest.sh, dnsleaktest.py, or dnsleaktest.bat from the v1.4 release, mark it executable with chmod +x, and run it; alternatively run the Python version through Docker with python:alpine.

How it compares

The registry's facts name no comparable or competing tools in this category, so dnsleaktest stands alone here.

When to use it — and when not

Choose it when you need a quick, self-contained check of a single machine's DNS behaviour; there is no database, storage layer, or SMTP component to operate, since it is a script you download and run. It does not configure or repair your VPN or resolver — it only reports a possible mismatch — so anyone seeking automatic remediation, a graphical interface, or continuous monitoring should look elsewhere, and note that macOS executables are unsigned and the project shows only two open issues.

project readme (upstream, from github) — read inline

DNS Leak Test

This tool reports your external IP address and the DNS servers used by your connection. If their network providers differ unexpectedly, your DNS traffic may be leaking outside the intended connection or VPN.

Linux and macOS

How to install and use the shell version

Please, before use make sure you have curl and ping installed.

  1. Download dnsleaktest.sh from v1.4:
curl -fLO https://raw.githubusercontent.com/macvk/dnsleaktest/v1.4/dnsleaktest.sh
chmod +x dnsleaktest.sh
  1. Run it:
./dnsleaktest.sh

How to install and use the Python version

  1. Download dnsleaktest.py from v1.4:
curl -fLO https://raw.githubusercontent.com/macvk/dnsleaktest/v1.4/dnsleaktest.py
chmod +x dnsleaktest.py
  1. Run it:
./dnsleaktest.py

Windows

How to install and use the batch file

  1. Download dnsleaktest.bat
Invoke-WebRequest -UseBasicParsing https://raw.githubusercontent.com/macvk/dnsleaktest/v1.4/dnsleaktest.bat -OutFile dnsleaktest.bat
  1. Run dnsleaktest.bat:
dnsleaktest.bat

Prebuilt Go executables

Version 1.4 executables are built by GitHub Actions and published on the v1.4 release page.

Linux

After downloading the correct executable for your system:

chmod +x dnsleaktest-linux-amd64
./dnsleaktest-linux-amd64

macOS

The macOS executables are unsigned. macOS may ask you to confirm that you want to run a downloaded executable.

Windows

Open Command Prompt, navigate to the download directory, and run the downloaded executable.

Build from source

Install Go, then select the target operating system and architecture. Examples:

GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -o dnsleaktest-linux-amd64 dnsleaktest.go
GOOS=darwin GOARCH=arm64 CGO_ENABLED=0 go build -o dnsleaktest-darwin-arm64 dnsleaktest.go
GOOS=windows GOARCH=amd64 CGO_ENABLED=0 go build -o dnsleaktest-windows-amd64.exe dnsleaktest.go

How to run from Docker

Linux

Use host networking so the test sees the host's network stack and DNS configuration. This is important when the host uses a local DNS resolver such as systemd-resolved or NextDNS.

docker run --rm --network host python:alpine sh -c 'wget -q -O- https://raw.githubusercontent.com/macvk/dnsleaktest/v1.4/dnsleaktest.py | python'

macOS and Windows

Docker Desktop runs containers in a virtual machine, so host networking does not provide the same view of the host's DNS configuration as it does on Linux. The following command tests the DNS configuration visible inside the container:

docker run --rm python:alpine sh -c 'wget -q -O- https://raw.githubusercontent.com/macvk/dnsleaktest/v1.4/dnsleaktest.py | python'

Frequently asked questions

Is dnsleaktest free to use?

dnsleaktest is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does dnsleaktest do?

An open source script tests VPN connection for DNS Leak.

What is dnsleaktest written in?

dnsleaktest is primarily written in Batchfile. Its source is publicly available at https://github.com/macvk/dnsleaktest, and it has 587 GitHub stars.