---
title: "DNS leak"
description: "Which resolvers actually look up a name for you, measured with a one-time label so nothing can be cached."
canonical: "https://scalebrowser.net/check/dns-leak"
last_modified: "2026-10-04T12:05:52.000Z"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://scalebrowser.net/llms.txt
> Use this file to discover all available pages before exploring further.

one check

# Who looks up names for you

This asks for a name that has never existed anywhere. No cache can answer it, so whoever asks us for it is genuinely your resolver, and it asks several times, because large resolvers work in clusters.

## What this one page cannot tell you

What your resolver does with the lookups. We see which addresses asked us; we cannot see logging, filtering or anything else on their side. Encrypted DNS shows up here as your provider's resolver, which is the protection working.

The interesting part is usually not a single value but the disagreement between two. [The full check](https://scalebrowser.net/check) reads all five layers and shows you where they contradict each other.
