LeoTun

Internet Freedom Alliance

2026-10 sing-box upgraded: old configs no longer work. Sign in and re-scan the code on the sing-box page, once per device.
2026-09 New router firmware is out — please update. OpenVPN is back: download a profile, import it, and connect in one tap.
2026-09 New Personal plan: 4 USD/month for 2 devices, routers included — everyone should have a VPN router.
HomeRouterOpenVPNCiscoHiddifyProxyPrivateContact

Related guides

DNS Leak vs DNS Poisoning: How to Check and Fix

Updated 2026-10-08

The short answer: DNS poisoning (often called DNS pollution) means you asked where a site lives and got a fake address, so the site does not open or something else opens in its place. A DNS leak means your VPN is on but the asking is still done through your local internet provider. The first stops you from arriving; the second lets someone else know where you are going. They are different problems. Checking is simple: see which exit IP websites see, then see whose servers resolve names for you. This guide explains both terms, how to detect and fix each, and three questions that come up with IP lookups: why two sites show different locations, what an IP “cleanliness” score is, and why secure DNS on a device can throw off a router’s split routing.

What DNS is

DNS is the internet’s way of asking for directions. You type a domain name, the device needs an IP address, and the step in between — which address belongs to this name — is a question put to a DNS server. By default that is a server chosen by your provider or your router, and classic DNS queries are unencrypted: equipment along the way can read the question and has a chance to answer before the real server does.

What DNS poisoning looks like

DNS poisoning means that answer has been replaced with a fake one: the name points to an unrelated address or to one that cannot be reached. From the user’s side it shows up like this.

  • Certain sites spin forever, time out or report a connection reset, while other sites work normally at the same moment.
  • Switching to a public DNS server does not help: the fake answer is inserted along the way, so whoever you ask, the reply still gets beaten to you.
  • The same name resolves to a different address each time, and those addresses belong to organisations that have nothing to do with the site.
  • The browser shows a certificate error: the name was pointed at someone else’s server, which cannot present the site’s certificate. Stop there and do not click through.
  • On another network (mobile data, for example) or with a VPN connected, the same site opens at once.

How to detect DNS poisoning

If the pattern is already “opens with the VPN, fails without it”, that is conclusion enough. To confirm whether one name resolves correctly, follow these four steps.

  1. With the VPN off, look the name up on a computer’s command line, replacing example.com with the domain in question, and note the address returned: nslookup example.com
  2. Connect the VPN (a whole-device method, global mode) and look the same name up again. Different results are common, since large sites have servers in many places; the next step is the one that counts.
  3. Take the first address to an IP-lookup site such as ipinfo.io and check who owns it. If it belongs to the site itself or its cloud provider, resolution is fine. If it belongs to an unrelated organisation, or cannot be reached at all, the answer was poisoned.
  4. Repeat a couple of times. Genuine results stay within a small fixed set of addresses; poisoned results often change on every query.

How to fix DNS poisoning

There are four approaches, from partial to complete. The first two only change who you ask; the third solves asking and travelling together.

  • Change DNS server: works when the provider’s own DNS is wrong or has cached an old address. It does nothing against answers inserted along the way.
  • Encrypted DNS (DoH, DoT): the query cannot be altered in transit, so you get the real address. The real address may still be unreachable, so this is half a fix.
  • Send both resolution and traffic through the route: the complete fix. The name is resolved at the far end, the answer is genuine, and the visit leaves from the far end too.
  • Edit the hosts file to pin an address by hand: it breaks as soon as the address changes and does not scale past a few sites. Suitable as a stopgap.
  • LeoTun takes the third approach: DNS is assigned by the route and resolved inside the tunnel, so the device’s original DNS is not used. With the web proxy, the proxy server resolves names for the browser. The router does this for every device at home, and resolves Chinese sites the domestic way so they open directly. On our routes you normally do not need to change any DNS setting.

DNS leak versus DNS poisoning

  • DNS poisoning: the answer is fake. The site fails to open or you are sent somewhere else. It happens when you are not on a route, or when resolution is not.
  • DNS leak: the answer is genuine, but your local provider was the one asked. The provider learns which domains you are heading to, and a video site may work out your real location from it. It happens when the VPN is connected but lookups travel outside the tunnel.
  • Common causes of a leak: secure DNS switched on in the browser or the system; another VPN or mesh-networking tool running at the same time; the device’s IPv6 not going through the tunnel.
  • When you are abroad watching Chinese video, the typical sign of a leak is “connected, the IP is right, and the region message still appears”. The steps are in Tencent Video or iQIYI blocked abroad.

How to check which DNS and exit IP you are really using

  1. Exit IP: once connected, open an IP-lookup site such as ipinfo.io or ip.sb. The address and location should be the exit you chose, not your home broadband.
  2. DNS: open a DNS leak test (dnsleaktest.com, or the DNS page on browserleaks.com). It lists the servers resolving names for you. In global mode, your local provider should not appear in the list.
  3. IPv6: open test-ipv6.com. If IPv6 shows as unavailable, or shows an address that is not your local one, all is well.
  4. Read the result differently in split-routing mode: Chinese sites are meant to be resolved domestically, so a domestic server on the test page is not necessarily a leak. To be sure, switch to global and test again.
  5. Disconnect and run everything once more, then compare. If the two runs are identical, traffic is not going through the route; check that the client is really connected.

Why two IP-lookup sites show different locations

With split routing on, this is normal and is in fact split routing doing its job. Inside China with an overseas region selected, a Chinese IP-lookup site is sent direct and sees your home broadband address, while an overseas lookup site goes through the route and sees the exit address. Both are right: one answers “where do Chinese sites see me”, the other “where do overseas sites see me”.

The same holds for the China entry: Chinese sites leave from China and overseas sites land through an overseas line, so an overseas lookup site shows the overseas end.

A third kind of disagreement comes from databases. Which country or city an IP belongs to depends on the geolocation database each lookup site uses, and they update at different times. One IP showing different cities, even different countries, on two sites is not unusual. What a website or app actually goes by is its own database.

To see the exit when everything takes the route, switch the client to global and look again. The directions of router split routing and how to verify them are in How split routing works on a VPN router.

What an IP “cleanliness” score means

An IP cleanliness score, also called IP reputation or a fraud score, is a risk rating that some checking sites assign to an address. There is no common standard; each site has its own formula, and one address can score very differently from site to site. It measures how much a website treats the address as an ordinary home user. It says nothing about whether your data is protected. Four things mostly drive it.

  • Address type: home broadband, mobile network or data centre.
  • Whether it is flagged as a proxy or VPN: some databases collect exactly these addresses.
  • History: whether the address has sent spam, hammered an API or been reported.
  • How many people use it at once: when many share one exit, everyone’s behaviour is recorded against the same address.

Why shared exits score lower, and whether it matters

Shared exits score lower by their nature. Many users share one exit address, and if any of them ever tripped a risk control, the record sits on that address. The address also falls in a data-centre range, which costs points on type alone. This is true of VPN and proxy exits in general.

In practice a low score means more CAPTCHAs, extra verification on some sites, and a few services that decline data-centre addresses. Treat the result as a reference. When a particular site turns you away, reconnect through another region: each region has different exit addresses, and each region has several machines behind it.

Secure DNS on a device can bypass router split routing

A router has to see which name a device is asking about before it can decide whether that visit takes the route or goes direct. A device with encrypted DNS turned on (DoH or DoT) asks a third-party server over its own encrypted channel, the router never sees the query, and split routing for that device stops matching: something that should take the route does not, or Chinese sites take a detour. When only one device in the house misbehaves, check this first.

  • Android: Settings → Network & internet → Private DNS, choose “Off”. Menu names vary by brand; searching settings for “Private DNS” finds it.
  • Chrome: Settings → Privacy and security → Security → Use secure DNS, turn it off. Edge and Firefox have an equivalent in their privacy settings; Firefox calls it “DNS over HTTPS”.
  • iPhone and Mac: there is no single system switch. If you installed a DNS app or a DNS profile, disable it under Settings → General → VPN & Device Management, and turn off iCloud Private Relay if it is on.
  • Afterwards, reconnect that device to the Wi‑Fi and verify with the method in the last section of the router split-routing guide.

FAQ

What does DNS poisoning mean?

When your device looks up the address for a domain, the answer is replaced with a fake one that points to an unrelated or unreachable address, so the site does not open. It has nothing to do with your device or browser; the problem is on the path the query takes.

Will changing DNS to 8.8.8.8 or 1.1.1.1 fix DNS poisoning?

Usually not. Ordinary DNS queries are unencrypted and the fake answer is inserted along the way, whoever you ask. Changing server only helps when the provider’s own DNS is at fault. The complete fix is to send both resolution and traffic through the route.

A DNS leak test shows my local provider’s servers. What now?

Switch to global mode and test again to rule out split routing. If they still appear, turn off secure DNS in the browser and Private DNS on Android, quit other VPN and mesh-networking tools, and use an IPv6 test to see whether a local IPv6 address is showing.

A Chinese IP-lookup site shows my home address. Is the route not working?

Most likely split routing is working: Chinese sites go direct, so they see your home broadband. Open an overseas IP-lookup site as well; if it shows the exit address, everything is as it should be.

Does a low IP cleanliness score affect my security?

No. The score reflects how websites regard the address and has no bearing on encryption or privacy. It affects how many CAPTCHAs you see and whether a few sites accept you; switch region when that happens.

Isn’t secure DNS safer? Why turn it off behind the router?

Secure DNS stops the local network from reading or altering your queries. At home behind the router, the router already takes care of that, and a device that encrypts its own queries leaves the router unable to route it by domain. Turn it back on when you are away from home and not behind the router.

Related pages

  • How split routing works on a VPN router →
  • Tencent Video or iQIYI blocked abroad? Fix it in 5 steps →
  • Is a VPN safe to use? Who can see what →
  • Which region is fastest from inside China →
  • Cannot connect, slow, or dropping: what to check →
  • How to Choose a China VPN →
  • Does Cisco AnyConnect Work in China? →
  • Choosing a VPN Router →
  • How to Import a Hiddify Subscription →
  • China VPN for Students Abroad →
  • What a Web Proxy Is and When to Use One →
  • Free or Paid China VPN? →
  • What the Private Network (Tailscale) Is →
  • How to Use OpenVPN and When to Choose It →
  • Flashing the Router Firmware: From Stock to Ours, Step by Step →
  • What the Router Firmware Does →
  • How to Reach Us and Never Lose Contact →
  • Where We Beat Other VPNs →
  • How to Recognise a Risky VPN App →
  • Which connection method fits which scenario →
  • For the TV and the Grandparents at Home →
  • Watching Home Cameras and a NAS in China from Abroad →
  • What to Do When iOS Cannot Install an App →
  • Setting Up for Business Trips and Travel →
  • On a Company Laptop: No Admin Rights, Corporate VPN Already On →
  • Many Devices, One Setup, No Redo on a New Phone →
  • Routing a Synology or QNAP NAS →
  • Routing a Linux Server and Command-Line Tools →
  • “Damaged” on a Mac, and how to verify the installer →
  • Using RustDesk for remote help →
  • What macOS's Network Extension Approval Is →
  • Not enough device slots? Temporary vs long-term fixes →
  • Dropbox and other apps want an HTTP / SOCKS proxy — what to do →
  • How to Get Good Answers from the AI Support →
  • How to manually uninstall the Cisco client on a Mac →
  • Cisco error “remote user is disabled” →
  • Refund Policy and Feedback →
  • What a VPN is, what it is used for, and how to connect →
  • VPN vs “airport” proxy subscriptions vs accelerators →
  • VPN protocols compared: WireGuard, OpenVPN, AnyConnect, Hysteria2 →
  • VPN Slow? How to Run a Speed Test and Find the Cause →
  • VPN on iPhone: which method to use and how to set it up →
  • VPN on Android: which client to use and how to set it up →
  • VPN on a computer: which method for Windows and Mac →
  • Using ChatGPT in China: Why It Fails and What Matters →
  • No Verification Code for an Overseas App? Telegram, Instagram and TikTok in China →
  • What Is OpenWrt? Soft Routers, Bypass Gateways and VPN Routers for China →
  • How to Use a VPN in China: Set Up Before You Land →
  • VPN Not Working in China? Why, and What to Try →
  • Best VPN for China: How to Judge One Yourself →
  • Do VPNs Work in China? What NordVPN, ExpressVPN and Others Say Themselves →
  • eSIM vs VPN in China: Which One Do You Need? →
  • Travel VPN Router for China: Setup and Who Needs One →
  • WhatsApp in China: Does It Work and How to Set It Up →
  • Google in China: Gmail, Maps and Google Play Explained →
  • YouTube in China: How to Watch, and Why Netflix Refuses →

Flags by Twemoji (CC-BY 4.0)·IP Geolocation by DB-IP

AboutGuidesContact

© 2007–2026LeoTun