Реферальна програма →
ГоловнаГлосарійВитік DNS (DNS leak)
Глосарій

Витік DNS (DNS leak)

Дефект приватності, за якого DNS-запити йдуть в обхід проксі, розкриваючи вашому провайдеру чи третій стороні, які сайти ви відвідуєте.

Витік DNS відбувається, коли ваш пристрій розв’язує доменні імена через не той DNS-сервер - зазвичай вашого провайдера - замість проксі. Навіть якщо реальний вебтрафік іде через проксі, DNS-запит, що перетворює ім’я на кшталт example.com на IP-адресу, може «втекти» з тунелю, розкриваючи вашому провайдеру (або тому, хто тримає цей DNS) саме ті сайти, які ви відвідуєте.

Це зводить нанівець частину сенсу використання проксі задля приватності. Ви можете приховувати свій IP від цілі, але витік DNS віддає історію серфінгу третій стороні. Це частий і легко упусканий дефект, бо сторінка все одно завантажується коректно - з боку користувача ніщо не має неправильного вигляду.

Виправлення залежить від протоколу проксі. SOCKS5 підтримує віддалене розв’язання DNS: проксі резолвить ім’я хоста за вас, тож запит ніколи не йде через ваш локальний DNS. HTTP-проксі, що обробляють повний запит, теж резолвлять віддалено. Витоки зазвичай трапляються, коли ПЗ неправильно налаштоване резолвити DNS локально, перш ніж передати з’єднання проксі.

Щоб уникнути витоків DNS, використовуйте SOCKS5 із віддаленим DNS (або переконайтеся, що клієнт надсилає проксі імена хостів, а не заздалегідь розв’язані IP), і перевірте DNS-leak-тестом. Для скрапінгу віддалений DNS також важливий для точності - ви хочете, щоб розташування проксі розв’язувало гео-специфічні імена хостів, а не ваше власне.

The lookup that happens before the request

Before your client can reach example.com it has to turn that name into an address. If that lookup happens on your machine, your resolver, usually your own provider, sees every domain you visit. The request itself then travels through the proxy, but the list of destinations has already leaked to a party you were trying to keep out of it.

With an HTTP proxy the question rarely arises: you send the full URL to the proxy and it resolves the name at its end. SOCKS5 is where the leak lives, because the protocol allows both behaviours and the client decides. Sending an address means resolving locally. Sending a hostname means the proxy resolves.

Browsers add their own twist. Chrome and Firefox may use DNS over HTTPS to a resolver of their choosing, which bypasses both your system settings and, in some configurations, the proxy. A browser profile that looks correctly proxied can still be resolving names through a third party.

The practical damage is twofold. Your target list is exposed, and geography can break: a resolver near you may return a server near you, so a request that should have looked local to Brazil arrives at a European edge node.

Making the lookup happen on our side

One letter in the scheme decides it. Use socks5h rather than socks5 and the hostname travels to us:

Leaky and not leaky

# Leaks: your resolver sees the target
curl -x socks5://login:password@proxy.sotaproxy.com:10000 https://example.com

# Does not leak: we resolve the name
curl -x socks5h://login:password@proxy.sotaproxy.com:10000 https://example.com

# HTTP scheme resolves on our side by design
curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com
  • In Python, requests with socks5h:// behaves correctly once you install the socks extra. Plain socks5:// resolves locally and nobody warns you.
  • In an antidetect browser, disable DNS over HTTPS in the profile settings. Otherwise the browser talks to its own resolver regardless of your proxy.
  • WebRTC is a separate leak with the same consequence. Disable it in profiles used for account work, because it reports your real address to any script that asks.
  • Test with a leak-check service through the proxy, not from your normal browser. What matters is what the profile does, not what your desktop does.

Misreadings of DNS leaks

A leak does not reveal your traffic

It reveals which domains you looked up. The content is still protected by TLS, but the destination list is often the sensitive part.

The proxy is not broken

A DNS leak means the name resolution took a different path from the connection. Both can be true at once, and the proxy is working exactly as instructed.

socks5 and socks5h look like a typo

They are two different behaviours. Most leaks in scraping stacks come down to this single character.

A VPN does not fix a browser doing DoH

The browser can still talk to its configured resolver over HTTPS. Turn it off in the profile rather than assuming the tunnel covers it.

Дивись на практиці

Готовий використовувати витік dns (dns leak)?

SotaProxy надає доступ до ротуючих резидентських, мобільних, дата-центр та ISP проксі. Без мінімальних платежів.

Почати