Referral Program →
HomeGlossaryDNS Leak
Glossary

DNS Leak

A privacy flaw where DNS lookups bypass your proxy, revealing which sites you visit to your ISP or a third party.

A DNS leak happens when your device resolves domain names through the wrong DNS server - typically your ISP's - instead of through your proxy. Even if your actual web traffic is routed through a proxy, the DNS lookup that turns a hostname like example.com into an IP address can escape the tunnel, revealing to your ISP (or whoever runs that DNS) exactly which sites you are visiting.

This defeats part of the point of using a proxy for privacy. You may be hiding your IP from the destination, but a DNS leak hands your browsing history to a third party. It is a common and easily overlooked flaw, because the web page still loads correctly - nothing looks wrong from the user's side.

The fix depends on the proxy protocol. SOCKS5 supports remote DNS resolution: the proxy resolves the hostname on your behalf, so the lookup never leaves through your local DNS. HTTP proxies handling the full request also resolve remotely. Leaks tend to occur when software is misconfigured to resolve DNS locally before handing the connection to the proxy.

To avoid DNS leaks, use SOCKS5 with remote DNS (or ensure your client sends hostnames to the proxy rather than pre-resolved IPs), and verify with a DNS-leak test. For scraping, remote DNS also matters for accuracy - you want the proxy's location to resolve geo-specific hostnames, not your own.

The lookup that happens before the request

Before your client can reach example.com it has to turn that name into an address. If that lookup happens on your machine, your resolver, usually your own provider, sees every domain you visit. The request itself then travels through the proxy, but the list of destinations has already leaked to a party you were trying to keep out of it.

With an HTTP proxy the question rarely arises: you send the full URL to the proxy and it resolves the name at its end. SOCKS5 is where the leak lives, because the protocol allows both behaviours and the client decides. Sending an address means resolving locally. Sending a hostname means the proxy resolves.

Browsers add their own twist. Chrome and Firefox may use DNS over HTTPS to a resolver of their choosing, which bypasses both your system settings and, in some configurations, the proxy. A browser profile that looks correctly proxied can still be resolving names through a third party.

The practical damage is twofold. Your target list is exposed, and geography can break: a resolver near you may return a server near you, so a request that should have looked local to Brazil arrives at a European edge node.

Making the lookup happen on our side

One letter in the scheme decides it. Use socks5h rather than socks5 and the hostname travels to us:

Leaky and not leaky

# Leaks: your resolver sees the target
curl -x socks5://login:password@proxy.sotaproxy.com:10000 https://example.com

# Does not leak: we resolve the name
curl -x socks5h://login:password@proxy.sotaproxy.com:10000 https://example.com

# HTTP scheme resolves on our side by design
curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com
  • In Python, requests with socks5h:// behaves correctly once you install the socks extra. Plain socks5:// resolves locally and nobody warns you.
  • In an antidetect browser, disable DNS over HTTPS in the profile settings. Otherwise the browser talks to its own resolver regardless of your proxy.
  • WebRTC is a separate leak with the same consequence. Disable it in profiles used for account work, because it reports your real address to any script that asks.
  • Test with a leak-check service through the proxy, not from your normal browser. What matters is what the profile does, not what your desktop does.

Misreadings of DNS leaks

A leak does not reveal your traffic

It reveals which domains you looked up. The content is still protected by TLS, but the destination list is often the sensitive part.

The proxy is not broken

A DNS leak means the name resolution took a different path from the connection. Both can be true at once, and the proxy is working exactly as instructed.

socks5 and socks5h look like a typo

They are two different behaviours. Most leaks in scraping stacks come down to this single character.

A VPN does not fix a browser doing DoH

The browser can still talk to its configured resolver over HTTPS. Turn it off in the profile rather than assuming the tunnel covers it.

See this in practice

Ready to use dns leak?

SotaProxy gives you access to rotating residential, mobile, datacenter, and ISP proxies. No minimum commitment.

Get started