Why choose nekoip?

Built-in DNS leak test

Each lookup spawns unique hostnames and records the resolver IP plus provider label. Users immediately see why several Google LLC nodes appear even when pointing clients at 8.8.8.8, and they can spot leaks from unknown networks.

Which DNS resolver am I using?See which DNS service your device is actually using.

Reading privacy diagnostics

The checks describe observable network behavior. Compare the results with the DNS and browser configuration you intended to use.

DNS resolver results

Known resolver networks are often represented by several service addresses. Investigate unexpected providers rather than assuming every additional address is a leak.

WebRTC results

Additional addresses can appear when the browser enables peer connections. Review browser permissions and enterprise policies if the result differs from expectations.

Safer configuration

Keep the browser and operating system updated, use encrypted DNS where appropriate, and test again after changing network settings.

DNS leak test questions

Why do I see multiple Google IPs if my resolver is set to 8.8.8.8?

Google Public DNS is anycast: the query arrives at 8.8.8.8 but is processed by the closest resolver cluster (172.217.x.x, 172.253.x.x, etc.). The DNS leak widget lists those internal nodes, so several Google LLC IPs mean the traffic still flows through Google. Only unfamiliar networks indicate a potential leak.

How does the DNS leak test actually work?

Your browser fetches ten random hostnames under our probe domain. Each hostname encodes a unique ID, and our lightweight DNS server logs the resolver IP that requested it. When the widget polls the API we return the list of resolver IPs plus provider metadata sourced from DB-IP, giving you transparency without sending full queries to third parties.