A DNS leak is one of the most common technical gaps in VPN clients: the tunnel itself works fine, and some requests still travel around it. Here's where that comes from.
What a DNS request actually is
Before reaching almost any resource online, a device first translates a domain name — say, meervpn.com — into an IP address via a DNS request. This happens for every new domain, usually invisibly, a fraction of a second before the connection itself.
Why a request can end up bypassing the tunnel
Operating systems default to whatever DNS server the current network hands them — a hotel router, a mobile carrier. If a VPN client doesn't explicitly point the system's DNS at a resolver inside the tunnel, some or all DNS requests keep going out directly through the network interface, skipping encryption entirely.
From the outside, everything looks fine: the app shows "connected," traffic to sites genuinely flows through the tunnel — while DNS requests are still "leaking" out to the network in parallel.
Why it matters
A session's list of DNS requests is a fairly precise fingerprint of which services you're using, even when each site's content is separately encrypted. A DNS leak undercuts exactly the part of "the VPN is on" that's supposed to matter for local-network visibility.
The trickier part is that it's rarely visible to the user: the connection indicator in the app doesn't show where DNS requests are actually going.
How this gets closed architecturally
The fix is routing DNS requests through the same encrypted tunnel as everything else, instead of relying on the local network's DNS server.
A tunnel that counts as "complete" has to cover DNS requests, not just requests to the sites themselves — that's an architectural principle baked into a client at design time, not a toggle bolted on after the fact.
Related questions
How would I even notice a DNS leak?
There are public online tools built specifically to check for DNS leaks: with a VPN connected, they show whose DNS server domains are actually being resolved through — the local network's or a resolver inside the tunnel.
Is a DNS leak a bug in one specific app, or a general problem?
It's a known category of issue across VPN clients generally, not a one-off bug in a single app — it shows up especially often with manually configured protocols like OpenVPN when DNS isn't explicitly set.
Can a DNS leak happen even if the VPN genuinely encrypts everything else?
Yes — they're independent mechanisms. Encrypting traffic to sites and routing DNS requests are configured separately. Correct client architecture means both go through the same tunnel by default.