{"id":895,"date":"2026-07-29T23:22:01","date_gmt":"2026-07-29T23:22:01","guid":{"rendered":"https:\/\/blog.asambe.ai\/index.php\/2026\/07\/29\/troubleshoot-dns-leaks-with-doh-on-windows-and-mac\/"},"modified":"2026-07-29T23:22:03","modified_gmt":"2026-07-29T23:22:03","slug":"troubleshoot-dns-leaks-with-doh-on-windows-and-mac","status":"publish","type":"post","link":"https:\/\/blog.asambe.ai\/index.php\/2026\/07\/29\/troubleshoot-dns-leaks-with-doh-on-windows-and-mac\/","title":{"rendered":"Troubleshoot DNS Leaks with DoH on Windows and Mac"},"content":{"rendered":"<p>Worried that your computer is leaking DNS requests and exposing where you browse? This guide shows you how to test for DNS leaks and turn on DNS over HTTPS (DoH) on Windows and Mac. You will learn quick fixes, deeper checks, and safe ways to keep your browsing requests private.<\/p>\n<h2>Table of Contents<\/h2>\n<ul>\n<li><a href=\"#before-you-start\">Before You Start<\/a><\/li>\n<li><a href=\"#quick-fix-steps\">Quick Fix Steps<\/a><\/li>\n<li><a href=\"#deeper-diagnosis\">Deeper Diagnosis<\/a><\/li>\n<li><a href=\"#preventive-care\">Preventive Care<\/a><\/li>\n<li><a href=\"#when-to-seek-help\">When to Seek Help<\/a><\/li>\n<li><a href=\"#conclusion\">Conclusion<\/a><\/li>\n<li><a href=\"#frequently-asked-questions\">Frequently Asked Questions<\/a><\/li>\n<\/ul>\n<h2 id=\"before-you-start\">Before You Start<\/h2>\n<p>First, a quick definition: DNS (Domain Name System) turns website names into IP addresses. A DNS leak is when your device still uses an unencrypted or unexpected DNS server, even if you thought it was protected. DoH (DNS over HTTPS) hides DNS lookups inside encrypted HTTPS traffic.<\/p>\n<ul>\n<li>What you need: Your Windows or Mac computer, your usual web browser, and internet access.<\/li>\n<li>Estimated time: 20\u201340 minutes for testing and setup.<\/li>\n<li>Difficulty: Easy to Medium. You will follow on-screen menus and simple checks.<\/li>\n<li>What can go wrong: Choosing the wrong DNS settings can break internet access. Always write down your current settings before changing them.<\/li>\n<\/ul>\n<p>Router: the box that creates your home Wi\u2011Fi network. Modem: the box that connects your home to the internet from your provider (sometimes it\u2019s combined with the router).<\/p>\n<p><strong>Warning:<\/strong> Avoid downloading DNS \u201ctuning\u201d tools from random sites. Do not edit the Windows Registry or install macOS configuration profiles from untrusted sources.<\/p>\n<h2 id=\"quick-fix-steps\">Quick Fix Steps<\/h2>\n<ol>\n<li>\n<h3>Run a quick DNS leak test<\/h3>\n<p>In your browser, search for \u201cDNS leak test\u201d and open a well-known testing site. Click the Standard or Extended test. Note the DNS servers shown (for example, your ISP name or a public resolver).<\/p>\n<p><strong>Tip:<\/strong> Do not click pop-up ads or \u201coptimizer\u201d downloads on testing pages.<\/p>\n<p>    <img decoding=\"async\" src=\"IMAGE_URL\" alt=\"A DNS leak test page showing detected DNS servers\">\n  <\/li>\n<li>\n<h3>Enable Secure DNS in your browser (fastest change)<\/h3>\n<p>Most modern browsers have a \u201cSecure DNS\u201d or \u201cDNS over HTTPS\u201d setting. Open your browser\u2019s Settings, then look under Privacy\/Security. Turn on Secure DNS and choose a reputable provider, or keep \u201cUse current service with secure DNS\u201d if offered.<\/p>\n<p><strong>Note:<\/strong> This protects that browser\u2019s traffic. Other apps may still use regular DNS unless the system also uses DoH.<\/p>\n<\/li>\n<li>\n<h3>Windows 11: Turn on system-wide DoH<\/h3>\n<ol>\n<li>Open Settings &gt; Network &amp; Internet.<\/li>\n<li>Select Wi\u2011Fi (or Ethernet) &gt; click your connected network.<\/li>\n<li>Next to \u201cDNS server assignment,\u201d click Edit.<\/li>\n<li>Set to Manual. Turn on IPv4 (and IPv6 if your ISP supports it).<\/li>\n<li>Enter DNS server addresses from a reputable encrypted-DNS provider (for example: 1.1.1.1 \/ 8.8.8.8 \/ 9.9.9.9). Then set Encryption to \u201cEncrypted only (DNS over HTTPS)\u201d for each entry.<\/li>\n<li>Click Save.<\/li>\n<\/ol>\n<p><strong>Tip:<\/strong> Write down your old DNS settings before changing them, so you can revert if needed.<\/p>\n<p>    <img decoding=\"async\" src=\"IMAGE_URL\" alt=\"Windows 11 DNS settings with Encrypted (DNS over HTTPS) selected\">\n  <\/li>\n<li>\n<h3>macOS: Use browser DoH now; optional advanced system DoH later<\/h3>\n<p>macOS can use encrypted DNS system\u2011wide via a configuration profile, but that is advanced. For a quick win, keep DoH enabled in your browser as in Step 2.<\/p>\n<p><strong>Advanced (optional):<\/strong> Some DNS providers offer a signed macOS profile that enables DoH\/DoT system\u2011wide. Only download from the provider\u2019s official website. <strong>Warning:<\/strong> Installing profiles changes system networking. Back up and read the provider\u2019s instructions carefully. If unsure, skip this and use browser DoH.<\/p>\n<\/li>\n<li>\n<h3>Flush DNS and restart the connection<\/h3>\n<p>Turn Wi\u2011Fi off and back on, or unplug and replug Ethernet.<\/p>\n<p>Windows: open Command Prompt and run <code>ipconfig \/flushdns<\/code>.<\/p>\n<p>macOS: open Terminal and run <code>sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder<\/code> (you will be asked for your password).<\/p>\n<\/li>\n<li>\n<h3>Re-run the DNS leak test<\/h3>\n<p>Open the test site again. You should now see your chosen encrypted DNS service, or at least not your ISP if you switched providers. If the test still shows your ISP or mixed servers, go to Deeper Diagnosis.<\/p>\n<\/li>\n<li>\n<h3>Optional: Try another network for comparison<\/h3>\n<p>Connect your computer to a phone hotspot or a trusted guest network. Run the test again. If it works there, your home router may be forcing DNS\u2014see Deeper Diagnosis.<\/p>\n<\/li>\n<\/ol>\n<h2 id=\"deeper-diagnosis\">Deeper Diagnosis<\/h2>\n<h3>1) Check your modem\/router basics<\/h3>\n<ul>\n<li>Look at the lights: Power solid, Internet\/Online solid or blinking normally, Wi\u2011Fi solid\/blinking. Red or flashing lights can mean a line or account issue.<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"IMAGE_URL\" alt=\"Router front panel with normal green lights for power, internet, and Wi\u2011Fi\"><\/p>\n<p><strong>Tip:<\/strong> If the router and modem are separate, power-cycle both: unplug for 20 seconds, then plug in the modem, wait 2 minutes, then plug in the router.<\/p>\n<h3>2) See if the router forces DNS<\/h3>\n<ul>\n<li>Open your browser and go to your router\u2019s admin page (often <code>http:\/\/192.168.0.1<\/code> or <code>http:\/\/192.168.1.1<\/code>). Router: the box that creates your Wi\u2011Fi network.<\/li>\n<li>Sign in with the router admin password. Check Internet\/WAN settings for \u201cDNS\u201d or \u201cEncrypted DNS\/DoH\/DoT.\u201d If the router forces its own DNS, your computer\u2019s settings may be overridden.<\/li>\n<li><strong>Warning:<\/strong> Do not factory reset the router unless you know the consequences. You can lose Wi\u2011Fi names, passwords, and ISP settings.<\/li>\n<\/ul>\n<h3>3) Confirm OS network settings<\/h3>\n<h4>Windows 11<\/h4>\n<ul>\n<li>Settings &gt; Network &amp; Internet &gt; your connection &gt; DNS. Ensure each DNS entry shows \u201cEncrypted only (DNS over HTTPS).\u201d<\/li>\n<li>Open Command Prompt and run <code>ipconfig \/all<\/code>. Under your adapter, check \u201cDNS Servers.\u201d They should match the ones you set.<\/li>\n<\/ul>\n<h4>macOS (Ventura\/Sonoma and later)<\/h4>\n<ul>\n<li>System Settings &gt; Network &gt; Wi\u2011Fi &gt; Details &gt; DNS shows DNS servers in use (not necessarily encrypted). If you use a profile for DoH\/DoT, verify it\u2019s installed under System Settings &gt; Privacy &amp; Security &gt; Profiles.<\/li>\n<li><strong>Warning:<\/strong> Remove profiles only if you created them and know what they do.<\/li>\n<li>Optional command: open Terminal and run <code>scutil --dns | grep -i nameserver<\/code> to list active DNS servers.<\/li>\n<\/ul>\n<h3>4) Browser checks<\/h3>\n<ul>\n<li>Use a Private\/Incognito window to avoid extensions interfering. In your browser\u2019s Privacy\/Security settings, ensure \u201cSecure DNS\u201d or \u201cUse DNS over HTTPS\u201d is ON.<\/li>\n<li>If there\u2019s a choice between \u201cUse current service provider\u201d and \u201cChoose a provider,\u201d try the provider list to avoid ISP fallback.<\/li>\n<\/ul>\n<h3>5) Look for blockers<\/h3>\n<ul>\n<li>VPNs, firewalls, parental controls, or workplace filters can block or redirect DoH. Temporarily turn off VPNs to test (if safe to do so). Re-run the leak test.<\/li>\n<li>Public Wi\u2011Fi with captive portals may not allow encrypted DNS until you sign in.<\/li>\n<\/ul>\n<h2 id=\"preventive-care\">Preventive Care<\/h2>\n<ul>\n<li>Keep Windows\/macOS and your browsers updated. Updates improve networking and security.<\/li>\n<li>Use one consistent encrypted DNS provider per device to avoid conflicts. Keep a note of the IPs or DoH URL.<\/li>\n<li>Avoid mixing many DNS entries. Start with two (primary and secondary) from the same provider.<\/li>\n<li>Secure your router: change the admin password, update firmware, and disable remote admin unless needed.<\/li>\n<li>Reboot your router\/modem monthly to clear glitches.<\/li>\n<li>Back up your computer regularly before making major network changes.<\/li>\n<li>Download profiles or tools only from the official provider\u2019s site. When in doubt, stick with browser-level DoH.<\/li>\n<\/ul>\n<h2 id=\"when-to-seek-help\">When to Seek Help<\/h2>\n<ul>\n<li>You still see ISP DNS in leak tests after enabling browser DoH and (on Windows) system DoH.<\/li>\n<li>Your router says \u201cDNS error,\u201d or you cannot change DNS without it breaking internet access.<\/li>\n<li>You are on a work\/school device or network with managed profiles or policies.<\/li>\n<li>You frequently get DNS errors like <code>DNS_PROBE_FINISHED_NXDOMAIN<\/code> across multiple sites.<\/li>\n<li>Call your ISP and ask if they support encrypted DNS (DoH\/DoT) or allow custom DNS. If your router is ISP-supplied, request their instructions.<\/li>\n<li>Consider a local tech professional if configuration profiles or router settings feel overwhelming.<\/li>\n<\/ul>\n<h2 id=\"conclusion\">Conclusion<\/h2>\n<p>You tested for leaks, enabled DoH in your browser, and\u2014on Windows\u2014turned on system-wide encrypted DNS. If needed, you checked your router and confirmed settings. Keep things stable with updates and simple, consistent DNS choices. Your browsing requests should now be harder to snoop or redirect.<\/p>\n<h2 id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n<h3>Is DoH the same as a VPN?<\/h3>\n<p>No. DoH encrypts only DNS lookups. A VPN encrypts most traffic and can hide your IP from websites. You can use both, but start with DoH for simple DNS privacy.<\/p>\n<h3>Which DNS addresses should I use?<\/h3>\n<p>Pick any reputable public resolver that offers DoH. Examples include providers that publish IPv4\/IPv6 addresses like 1.1.1.1, 8.8.8.8, or 9.9.9.9, plus a matching DoH service. These are examples, not endorsements\u2014use the provider you trust.<\/p>\n<h3>Will DoH slow down my internet?<\/h3>\n<p>Usually no. Many users see similar or better performance. If pages feel slower, try a different reputable provider or switch between IPv4 and IPv6 as supported.<\/p>\n<h3>Do I need to set this up on my phone too?<\/h3>\n<p>It helps. iOS and Android support encrypted DNS in system settings or via the browser. Search your phone\u2019s Settings for \u201cPrivate DNS,\u201d \u201cEncrypted DNS,\u201d or \u201cSecure DNS.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fix DNS leaks fast. Step-by-step guide to test and enable DNS over HTTPS (DoH) on Windows and macOS, verify privacy, and keep settings safe. Beginner-friendly tips.<\/p>\n","protected":false},"author":1,"featured_media":894,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[9],"tags":[],"class_list":["post-895","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-docs"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blog.asambe.ai\/wp-content\/uploads\/2026\/07\/2026-07-29-23-21-53-data.png?fit=1024%2C1024&ssl=1","_links":{"self":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/comments?post=895"}],"version-history":[{"count":1,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/895\/revisions"}],"predecessor-version":[{"id":896,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/posts\/895\/revisions\/896"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/media\/894"}],"wp:attachment":[{"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/media?parent=895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/categories?post=895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.asambe.ai\/index.php\/wp-json\/wp\/v2\/tags?post=895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}