Five days free, no card
DNS leak check: how to run one and read it
A tunnel can hide your traffic and still let your lookups go to your provider. A leak test shows it in under a minute.
No card and no account. The key is issued in Telegram in about a minute.
- Key
- 1
- Devices at once
- 5
- Logs kept
- 0
- Free before any payment
- 5 days
- Locations · online
- 6
- Monthly, after the free days
- $4.9/mo
Scan the QR or paste the vless:// link into your client. Nothing is charged for the first five days.
- Ashburn12 ms
- Los Angeles58 ms
- Toronto24 ms
- London79 ms
- Frankfurt88 ms
- Tokyo146 ms
All locations run VLESS over Reality; on a filtered network it reads as ordinary HTTPS.
- Fits v2rayNG, Hiddify, V2Box, Streisand
- No app of ours to install
- Five devices on one key
- Five days free, then a flat price per term
- No logs, no account
How to check DNS leak status properly
The usual causes of a leak
- ▸The operating system sends lookups to every network adapter at once and accepts the quickest reply. Windows is known for this.
- ▸IPv6 is active on the network but the tunnel carries only IPv4, so IPv6 lookups go around it.
- ▸The browser uses its own secure DNS setting, which can bypass the system path.
- ▸A client running in proxy mode covers the browser only, and other apps resolve names directly.
- ▸The router or the provider intercepts standard DNS traffic regardless of your settings.
Fixing it
In most clients the fix is a single switch. Turn on TUN mode, sometimes called VPN mode, so the whole device goes through the tunnel and not only apps that respect a proxy. Enable the client's own DNS handling, which Hiddify, v2rayN, v2rayNG and NekoRay all provide. If the test still shows an IPv6 resolver from your provider, either enable IPv6 routing in the client or disable IPv6 on that adapter.
Browser level secure DNS is fine to leave on as long as it points to a public resolver and not to your provider. After every change, run the test again. It is the only proof that counts.
Why it matters less than the ads say, and still matters
Most of your traffic is HTTPS, so a provider that sees your lookups learns which sites you visit and not what you do there. That is still more than many people want to share, and on a filtered network leaked lookups are often what triggers the block. Closing the leak is part of finishing the setup, not an advanced extra.
With a BSR key the client resolves names through the tunnel by default when it runs in TUN mode. Run the test once anyway. It is quick and it confirms the result on your own devices.
Five days, no card
DNS leak check: how to run one and read it - 5 days free
Open the Telegram bot and get your personal VLESS key in about 30 seconds.
- Key in Telegram in under a minute
- No card, no email, no KYC
- Works in the client you already have
- Five devices on one key
Nothing is charged and nothing renews on its own. · Bot online · VLESS over Reality
Account statement
Every balance on this statement is zero
There is no account here, so there is nothing to attach a log to. You never give us an email, a phone number or a name. The bot knows a Telegram chat, a key and an expiry date, and that is the whole record. We say that plainly instead of pretending to be beyond every jurisdiction.
| What we hold about you | Balance |
|---|---|
| Registration, email, phone number | 0 |
| Browsing history and connection logs | 0 |
| Connection times and IP addresses | 0 |
| Card details stored | 0 |
| Silent renewals and hidden charges | 0 |
Notes to the statement
Questions people ask before the first key
What is a DNS leak in one sentence?
Your site name lookups go to your internet provider while the rest of your traffic goes through the VPN.
Is a DNS leak test safe to run?
Yes. It only makes lookups for test names and lists who answered. Nothing is installed.
How often should I check DNS leak status?
After the first setup, after changing client or settings, and once on each new network.
I see a public resolver in the results. Is that a leak?
Not if the request reached it through the tunnel. A leak is when your own provider's servers appear.
Does a DNS leak expose my passwords?
No. It exposes the names of the sites you visit. The content stays encrypted by HTTPS.
Can a leak happen on iPhone or Android?
It is less common there, because the system sends all traffic through the VPN interface. It can still happen with per app routing or an IPv6 only path.
Still unsure?
Support and your key live in the same Telegram bot. The setup page shows which client to install.