How to fix a DNS leak
DNS translates names such as example.com into network addresses. When you use a VPN, you may expect DNS requests to follow the VPN's intended path. Unexpected resolvers can be worth investigating, but a provider mismatch alone is not proof of a leak.
First, confirm what you are seeing
Run a DNS leak test more than once and note the resolver operators and locations. Results can legitimately involve multiple resolver IPs, content-delivery infrastructure, encrypted DNS, or services selected by your browser or operating system.
Check your VPN settings
Look for DNS protection, leak protection, or a setting that uses the VPN provider's DNS. If your VPN application offers those controls, follow the provider's current documentation for your operating system.
Check browser secure DNS
Some browsers can use DNS over HTTPS independently of the operating system. That can make the resolver appear different from the VPN provider without necessarily exposing requests to your normal ISP. Review the browser's secure-DNS setting if the results are unexpected.
Reconnect and retest
Disconnect the VPN, reconnect to a different VPN server, then repeat the test. Comparing VPN-off and VPN-on results can help distinguish a persistent local setting from a route associated with one VPN server.
When results remain unclear
DNS routing can be complicated. Treat an unexplained resolver as a signal to investigate, not an automatic verdict. NetPrivacyScan intentionally reports inconclusive or mixed results when the evidence does not justify a stronger claim.