Fuga de DNS (DNS leak)
Un fallo de privacidad en el que las consultas DNS evitan tu proxy, revelando a tu ISP o a un tercero qué sitios visitas.
Una fuga de DNS ocurre cuando tu dispositivo resuelve nombres de dominio a través del servidor DNS equivocado -normalmente el de tu ISP- en lugar de a través de tu proxy. Aunque tu tráfico web real se enrute por un proxy, la consulta DNS que convierte un nombre como example.com en una dirección IP puede escapar del túnel, revelando a tu ISP (o a quien opere ese DNS) exactamente qué sitios visitas.
Esto anula parte del propósito de usar un proxy para la privacidad. Puedes estar ocultando tu IP al destino, pero una fuga de DNS entrega tu historial de navegación a un tercero. Es un fallo común y fácil de pasar por alto, porque la página se carga correctamente igualmente - nada parece ir mal desde el lado del usuario.
La solución depende del protocolo del proxy. SOCKS5 admite resolución DNS remota: el proxy resuelve el nombre de host por ti, así que la consulta nunca sale por tu DNS local. Los proxies HTTP que manejan la solicitud completa también resuelven de forma remota. Las fugas suelen producirse cuando el software está mal configurado y resuelve el DNS localmente antes de entregar la conexión al proxy.
Para evitar fugas de DNS, usa SOCKS5 con DNS remoto (o asegúrate de que tu cliente envíe nombres de host al proxy en lugar de IPs ya resueltas), y verifícalo con una prueba de fuga de DNS. Para el scraping, el DNS remoto también importa para la precisión - quieres que la ubicación del proxy resuelva nombres de host geo-específicos, no la tuya.
The lookup that happens before the request
Before your client can reach example.com it has to turn that name into an address. If that lookup happens on your machine, your resolver, usually your own provider, sees every domain you visit. The request itself then travels through the proxy, but the list of destinations has already leaked to a party you were trying to keep out of it.
With an HTTP proxy the question rarely arises: you send the full URL to the proxy and it resolves the name at its end. SOCKS5 is where the leak lives, because the protocol allows both behaviours and the client decides. Sending an address means resolving locally. Sending a hostname means the proxy resolves.
Browsers add their own twist. Chrome and Firefox may use DNS over HTTPS to a resolver of their choosing, which bypasses both your system settings and, in some configurations, the proxy. A browser profile that looks correctly proxied can still be resolving names through a third party.
The practical damage is twofold. Your target list is exposed, and geography can break: a resolver near you may return a server near you, so a request that should have looked local to Brazil arrives at a European edge node.
Making the lookup happen on our side
One letter in the scheme decides it. Use socks5h rather than socks5 and the hostname travels to us:
Leaky and not leaky
# Leaks: your resolver sees the target
curl -x socks5://login:password@proxy.sotaproxy.com:10000 https://example.com
# Does not leak: we resolve the name
curl -x socks5h://login:password@proxy.sotaproxy.com:10000 https://example.com
# HTTP scheme resolves on our side by design
curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com- In Python, requests with socks5h:// behaves correctly once you install the socks extra. Plain socks5:// resolves locally and nobody warns you.
- In an antidetect browser, disable DNS over HTTPS in the profile settings. Otherwise the browser talks to its own resolver regardless of your proxy.
- WebRTC is a separate leak with the same consequence. Disable it in profiles used for account work, because it reports your real address to any script that asks.
- Test with a leak-check service through the proxy, not from your normal browser. What matters is what the profile does, not what your desktop does.
Misreadings of DNS leaks
A leak does not reveal your traffic
It reveals which domains you looked up. The content is still protected by TLS, but the destination list is often the sensitive part.
The proxy is not broken
A DNS leak means the name resolution took a different path from the connection. Both can be true at once, and the proxy is working exactly as instructed.
socks5 and socks5h look like a typo
They are two different behaviours. Most leaks in scraping stacks come down to this single character.
A VPN does not fix a browser doing DoH
The browser can still talk to its configured resolver over HTTPS. Turn it off in the profile rather than assuming the tunnel covers it.
Términos relacionados
Ver esto en práctica
¿Listo para usar fuga de dns (dns leak)?
SotaProxy te da acceso a proxies residenciales rotativos, móviles, de centro de datos e ISP. Sin compromiso mínimo.
Empezar