Chrome DNS Leak: Secure DNS, DoH, and VPN Conflicts
Chrome Secure DNS can send lookups to Google or Cloudflare outside your VPN path. Here is how to control it.
Key takeaway: follow the security steps carefully and prefer AES-256 encryption where available.
Chrome Secure DNS can send lookups to Google or Cloudflare outside your VPN path. Here is how to control it. What Chrome Secure DNS does Chrome can use DNS over HTTPS to a chosen provider. That protects DNS from local network spies, but it may bypass the VPN resolver and reveal queries to the DoH operator — or break kill-switch assumptions. When it becomes a leak If your threat model is “ISP must not see my queries,” DoH to a third party may be acceptable. If your threat model is “only VPN resolver,” Chrome DoH is a leak relative to that policy. Recommended settings with AstraGuard For strict VPN DNS: set Secure DNS to Off while connected, or ensure it uses a resolver consistent with your privacy policy. Retest on tools . Enterprise Chrome Managed browsers may force Secure DNS. Check chrome://policy and consult admins for privacy-critical work. Related Firefox DNS leak guide for cross-browser consistency. Chrome settings path Settings → Privacy and security → Security → Use secure DNS. For strict VPN DNS testing, choose Off, relaunch, and retest. Enterprise-managed Chrome may gray this out — check chrome://policy . Protect yourself with AstraGuard VPN AstraGuard VPN helps keep DNS inside the tunnel with strong encryption, kill switch options, and simple setup on desktop and mobile. Create an account , pick a plan on packages , then verify on privacy tools .