Skip to content

Full access for 3 days at 1 ₽ — no auto-renewal.

Try for 1 ₽

Tools · DNS check

Who answers your DNS queries

Before every site opens, someone translates its name into an address. This page shows which servers do it for you and whether they take a different route than your traffic.

The check isn't set up on this site yet. Below — how it all works and what to look at.

What a resolver is

Sites are addressed by numbers, people remember names. The translation is done by a DNS server — the resolver: before opening a page, your device quietly asks it “what address does this name have” and only then connects to the site.

Hence an awkward consequence: the resolver sees the list of every name you open — even when the content itself is encrypted. Not a leak by itself, but worth knowing whose hands that list ends up in.

Why the check is ours, not someone else's

You can't learn your resolver from inside the browser — the browser doesn't know who answered its query. It can only be seen from the opposite side: by running an authoritative server for a domain zone and recording who comes asking.

We run such a server ourselves. Sending visitors of a privacy service to a third-party test that would collect their resolvers would contradict the very product.

About “different routes”

With a VPN on, not only site connections but also name lookups should pass through the tunnel. If traffic goes into the tunnel while names are still asked of the home provider's resolver, you get a paradox: content hidden, browsing list visible to the same network as before.

The page compares the country and network of your resolvers with the country and network of the address you exit through. Match — one route. Divergence — some queries live their own life. Without a VPN there's usually no divergence: the provider's resolver on the provider's connection is the norm.

Why there are several servers

At a large operator the resolver is a pool of machines with queries spread across them. That's why the check requests several unique names: a single name would light up just one machine from the pool.

Uniqueness is mandatory: a repeated name would return from cache and never reach us, while a fresh one forces the resolver to come to us in person each time. For the same reason the address set varies slightly between runs.

Questions and answers

No. They live a few minutes in the server's RAM and are erased: no disk, no logs, no third parties.
Neither good nor bad — it's a missing measurement. The usual cause: strictly configured encrypted DNS or an extension that cut the query. Taking emptiness for “all fine” is wrong.
Not by itself: the system or browser is set to a public resolver. What matters is whether its route matches the route of the rest of your traffic.
The leak test looks for your address being disclosed around the connection — IPv6, WebRTC. This page is about something else: who receives the names of the sites you open.
Resolvers work as a pool; one machine answers, then another. That's normal. Look not at the specific address but at the country and network owner.

Names — the same route as the traffic

In MeerGuard White name lookups travel inside the same protected channel — no separate setting required.

Open the Telegram botif Telegram opens for you
Sign up on the siteif Telegram is blocked