Sovatun Guide

iPhone VPN DNS Leaks on Public Wi-Fi: A Simple Check

What an iPhone VPN DNS leak is, why it matters on public Wi-Fi, and a two-minute check you can run to confirm your VPN isn't leaking the sites you visit.

Answer First

Definition: A DNS leak is a small but important privacy gap in how your iPhone connects to the internet. DNS stands for Domain Name System, and it’s the internet’s phone book: when you type a site name like example.com, your iPhone first asks a “resolver” to translate that name into the numeric address your device can actually reach. A DNS leak means that request went outside your VPN’s encrypted tunnel — to a resolver controlled by someone else, usually your internet provider or the public Wi-Fi network you’re sitting on.

Why: Your VPN’s whole job is to carry your traffic through a private, encrypted tunnel so the network between you and the internet can’t watch. But the tunnel only helps if your traffic actually goes through it. When DNS lookups leak out, the person who runs the network — a coffee shop, airport, or hotel — can still see the names of the sites you visit, even though your VPN icon shows “connected.” You think you’re private, and for most of your traffic you are, but your browsing destinations are quietly visible.

Example: You’re at an airport, VPN on, checking a news site while you wait. The VPN hides the pages you read. But if your iPhone sent a leaked DNS query for that news site to the airport’s Wi-Fi resolver, the network operator just learned which site you visited — the one thing you connected the VPN to keep private.

The good news: verifying your iPhone VPN isn’t leaking DNS takes about two minutes, needs no technical skill, and is a habit worth building into your public Wi-Fi routine.

Key Facts

  • DNS is the lookup step that happens before you load any site; it reveals the name of every site you visit.
  • A VPN should carry your DNS lookups inside its encrypted tunnel, right alongside the rest of your traffic.
  • A DNS leak happens when those lookups are answered outside the tunnel — by your ISP or the local network — while the VPN is still “on.”
  • On public Wi-Fi, the risk is the network operator (or anyone who has compromised it): the hotspot owner, the venue, or an attacker running a fake access point.
  • Leak checks are free, run in your browser, and report which resolver your device actually used.
  • A clean check today doesn’t mean a clean check on every network — that’s why it’s a habit, not a one-time test.
What the network operator can seeNo VPNVPN, no DNS leakVPN with DNS leak
Which sites you visit (domain names)YesNoYes
That your device is using a VPNNoYesYes
How much data you’re movingYesYesYes

Expert Explanation

How the check works. A DNS leak test page shows you the IP address, provider, and country of the DNS resolver your iPhone actually used for its most recent lookups. That’s the whole trick: you don’t have to trust the VPN’s own claims, because the test asks your device’s resolver directly and reports who answered. If the answer comes back as your VPN provider’s server, your DNS is inside the tunnel. If it comes back as your home ISP, or the local coffee shop’s provider, it leaked.

The two-minute check. Do this on the network you care about — that’s the point:

  1. Connect your iPhone to the public Wi-Fi you’d actually use, and leave Settings → Wi-Fi open long enough to confirm you’re on it.
  2. Turn on your VPN and verify it shows as connected.
  3. Open Safari and visit any well-known DNS leak test page (search “DNS leak test”).
  4. Read the reported resolver: its provider and location should match your VPN server — not your home ISP or the local network.
  5. Repeat the check when you connect to a new network you use regularly, like a new office, hotel, or gym.

What the result means. If the resolver matches your VPN, DNS is tunneled — good. If it doesn’t, treat that network as see-through: don’t sign into email or banking on it, and check your VPN app’s settings or support page for DNS handling (most consumer VPN apps route DNS automatically, but some let a setting, a profile, or an older configuration leave it to the network). You may also want to check once with Wi-Fi off and cellular on, since your carrier’s resolver can also see your lookups.

Practical limits — be honest about them. A leak test only reflects that moment, that network, and that app configuration. Some public networks force their own DNS no matter what your VPN tries to do — the test will show that, and it’s worth knowing. Some VPNs tunnel IPv4 but not IPv6, which can leak on dual-stack networks; if your VPN offers an IPv6 setting, it’s worth one extra check. And keep perspective: a clean DNS test does not make you invisible or invincible. A VPN does not prevent phishing, malware, account compromise, or all tracking. It narrows what the network can see; it doesn’t replace HTTPS, updates, strong passwords, or skepticism about login pages. Note too that a VPN and your phone’s local-network permissions are separate things — the apps that can see your phone on the local network are a different exposure, which we cover in our guide to VPN local network access on iPhone.

Decision Framework

When to check. Make it a reflex, not a project. Check when you join a new public network you’ll use more than once, and before you do anything sensitive on one — checking email, banking, work logins. A quick re-check after an iOS update or a VPN app update is cheap insurance, since updates occasionally change network configuration. That’s the whole habit: a two-minute check whenever “new network + real browsing” is about to happen.

If the check shows a leak. Don’t panic, and don’t use that network for sensitive stuff until it’s resolved. Confirm the VPN is actually connected (look for the VPN indicator in the status bar), then check the app’s DNS-related settings and update it. If a leak persists with your current VPN, that’s a legitimate reason to consider a different one.

What this says about choosing a VPN. A DNS leak is one of the few things about a VPN you can verify yourself in two minutes — use that. The harder question is trust, and it deserves the same skepticism. Not every app labeled “VPN” is primarily protecting you: some are built to collect data, and the App Store has a history of quietly removing privacy-broken VPN apps — the Onavo case is the clearest example of a “VPN” that was really a data collector, and Apple’s pushback on that category says a lot about what to look for in a provider. SovaTun is built for exactly this everyday scenario — iPhone-first, for connection privacy on public Wi-Fi. And the test in this article is fair for any VPN, SovaTun included: run it, and judge what you see.

Key Takeaways

  • A DNS leak means the network operator can see which sites you visit even while your VPN is connected — it’s the one privacy promise that can silently fail.
  • On public Wi-Fi, the stakes are highest, because the network is run by someone else, and unsecured wireless traffic is a known risk area.
  • You can verify your iPhone VPN in two minutes with a browser-based DNS leak test: the resolver it reports must match your VPN, not your local network.
  • Treat the check as a habit tied to new networks, not a one-time audit.
  • A clean test is not a security guarantee: a VPN doesn’t stop phishing, malware, account compromise, or all tracking — and iCloud Private Relay is not a substitute for a VPN.

FAQ

Q: What is a DNS leak on my iPhone?

A: DNS is the phone book of the internet: it turns a name like example.com into the numeric address your device needs. A DNS leak happens when your iPhone sends those lookups to a resolver outside your VPN tunnel — usually your internet provider’s or the public Wi-Fi network’s. When that happens, the person running the network can see the names of the sites you visit, even though your VPN shows “connected.” The rest of your traffic may be tunneled and encrypted; the leak is specifically about those lookup requests slipping out.

Q: If my VPN is connected, can the public Wi-Fi operator still see which sites I visit?

A: Only if your VPN leaks DNS. When the VPN works as intended, your DNS lookups travel inside the encrypted tunnel, so the network operator sees a connection to your VPN server but not the site names. If DNS leaks, the operator sees the domain names you look up — though not the content of the pages, which HTTPS still protects. The operator can also see that you’re using a VPN and roughly how much data you’re moving, no matter what.

Q: How do I run a DNS leak check on my iPhone?

A: Connect to the public Wi-Fi network you actually use, turn on your VPN, and confirm it’s connected. Then open Safari and visit any reputable DNS leak test page. The page reports which DNS resolver your device used, including its location and provider. It should match your VPN server (same provider, same country), not your home ISP or the local network. Run it once on each new network you use regularly.

Q: Does iCloud Private Relay protect me from DNS leaks?

A: Not in the way a VPN does. Private Relay is an iCloud+ feature that hides your IP address and encrypts DNS — but it only applies to Safari (and some Apple services), not to other apps, and it isn’t a VPN. If you’re relying on it while using other apps on public Wi-Fi, those apps’ traffic isn’t covered. A VPN tunnels all your device’s traffic; Private Relay covers a slice of it.

Sources