How it works
DNS resolver detection relies on a clever trick — there is no browser API that exposes which DNS server you use. Here is how the measurement actually works.
Unique hostnames are generated
When you hit "Check my DNS", a random session token creates 24 hostnames that have never existed before — like 7f3a2b.bash.ws. No DNS cache anywhere in the world holds them, so every lookup must travel all the way to the authoritative nameserver for that domain. Firing a batch rather than one matters because resolver pools rotate: a single lookup often reveals only one member of a much larger pool.
Your browser resolves them
Your browser asks whichever recursive resolver your OS or router is configured to use. That resolver — your actual DNS server — doesn't know the answer, so it queries the authoritative nameserver to find out. The lookup reaches the nameserver regardless of whether the HTTP request itself succeeds.
The nameserver logs who asked
The source IP of that query is your real recursive resolver — the actual DNS server handling your lookups. This page retrieves that log and reports what it contains: the resolver IP, the network that owns it, its AS number and its location, exactly as the registries publish them.
Frequently asked questions
Why can't you just ask my browser which DNS server it uses?
Browsers intentionally hide this. DNS configuration is an OS-level detail that the browser sandbox cannot read. The only reliable way to observe it is to make the browser perform a lookup and watch who comes asking at the authoritative nameserver.
What is a recursive resolver?
When you type a domain into your browser, your OS sends the query to a recursive resolver — a server that does the legwork of finding the answer. Most people use the one their ISP assigns automatically via DHCP. Others configure a different resolver, such as 1.1.1.1, 9.9.9.9, or one provided by software running on their network.
Do you guess what kind of DNS service I am using?
No. An IP address does not reveal whether a resolver belongs to a VPN, a filtering service or a private server — plenty of DNS services run on shared hosting networks, so any such label would frequently be wrong. This page reports only what is published about each resolver: its IP, network owner, AS number and location.
What does the "Your ISP" marker mean?
It appears only when a resolver's AS number is identical to your connection's AS number, or when the network owner name matches your internet provider's in the same country. Both are direct comparisons of published data, not inferences. Without that match, the resolver is simply reported as being on a different network.
Why does the operator name differ from the network owner?
Registry strings are often written in shorthand — CLOUDFLARENET rather than Cloudflare. Where an operator is well known, the normal spelling is shown instead, and the raw registry string is always available under Details. Nothing else is changed.
What if nothing is detected?
An ad-blocker or privacy extension may have blocked the probe requests before they triggered a DNS lookup. Browser-level DNS-over-HTTPS can also route queries through a resolver that is not visible at the network level. Try temporarily disabling extensions and scanning again.
Who observes the DNS queries?
This app delegates the authoritative nameserver step to bash.ws, which runs an authoritative nameserver for *.bash.ws and exposes the resulting query log as JSON. A Next.js serverless route cannot bind UDP port 53 and run a nameserver itself. You can point the app at your own nameserver by setting DNS_LEAK_PROVIDER=selfhosted, DNS_TEST_DOMAIN, and DNS_TEST_RESULTS_ENDPOINT.
How does the expected vs actual check work?
You tell us what you believe you configured, and we compare that against what was actually observed. This is the only place the tool can honestly discuss VPNs, routers or browser DoH — because you supplied the expectation, we are checking a claim rather than guessing at your setup. When it fails, the possible causes listed are exactly that: possibilities, not a diagnosis.
Why are the behaviour tests marked "indicative"?
JavaScript never sees DNS responses. All a browser learns is whether a request succeeded, so a failure could be NXDOMAIN, a refused connection, a timeout or an extension blocking it. Each test is built so the informative answer is the success case, and every result lists its method and how it could be wrong. Ad-blocking is deliberately not tested, because an extension blocking a request is indistinguishable from the resolver blocking it.
What does the multi-network flag mean?
It counts how many distinct AS numbers the observed resolvers span. More than one means your lookups are being handled on several different networks, which is worth checking against what you intended — split-tunnel VPNs, per-browser DoH and separate Wi-Fi and Ethernet settings all produce it.
What is stored when I share a result?
Your public IP is truncated before it is saved — 203.0.113.47 becomes 203.0.113.x. Resolver addresses are kept in full, since those identify DNS infrastructure rather than a person. Links expire after 30 days. Nothing at all is stored unless you press the share button.