Windows DNS Leak Protection
How Strict Route stops DNS leaks in TUN mode on Windows, and what to do when you cannot use it.
In TUN mode, Windows can still send DNS queries through your normal network adapter instead of the tunnel. Your internet provider can then see which sites you look up. This is a DNS leak. This page explains how Throne prevents it, how to check that the protection is on, and what to do when you cannot use it.
The page is about TUN mode only. Strict Route has no effect in System Proxy mode, where apps that ignore the proxy connect and look up names on their own.
Strict Route
Windows can send the same DNS query to the DNS servers of all network adapters at the same time. Even if Windows then uses the answer from the tunnel, the query has already left through your normal adapter, outside the tunnel.
Strict Route stops this. While TUN mode runs, Throne adds Windows firewall filters that:
- block DNS queries (port 53) on every network adapter except the tunnel, so Windows gets its answers from Throne;
- block IPv6 connections of other apps when
Tun Enable IPv6is off, so nothing leaks over IPv6.
ThroneCore itself is not blocked. The filters disappear when TUN mode stops or Throne exits. They can also block programs that must reach a DNS server or use IPv6 outside the tunnel.
Strict Route is on by default on Windows 10 and 11 since Throne 1.2.1. When it is on, you do not need the registry fallback below.
Check that it is on
- Open
Settings→Tun Settings. - Make sure
Strict Routeis ticked. - Press
OK. - If
Tun Modeis on, turn it off and on again. Throne reminds you with "Restart Tun to take effect".
When it is off
Strict Route can be off in these cases:
- Windows 7, 8 or 8.1.
Strict Routedoes not work on Windows older than Windows 10, so Throne leaves it off. - You turned it off after an error. If Windows cannot set up the filters, the profile does not start and Throne shows "Strict routing unavailable". The message suggests turning
Strict Routeoff, which also removes the protection. If you can fix the cause, turn it back on. - You started with Throne 1.2.0. That version had
Strict Routeoff by default, and updates keep your saved settings. Tick it now.
If you cannot use Strict Route, use the registry fallback below.
Registry fallback
Without Strict Route, you can turn off the Windows feature that sends DNS queries to all adapters at the same time. Its Group Policy name is Turn off smart multi-homed name resolution. This is weaker than Strict Route: it changes how Windows chooses DNS servers, but it blocks nothing. The policy exists on Windows 8 and later, so Windows 7 has neither protection.
With Group Policy (Pro, Enterprise, Education)
- In the Start menu, search for
Edit group policyand open it. - Go to
Computer Configuration→Administrative Templates→Network→DNS Client. - Double-click
Turn off smart multi-homed name resolution. - Select
Enabledand pressOK. - Restart Windows.
With the registry (Windows Home)
Windows Home has no Group Policy editor. This command sets the same policy in the registry:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" /v DisableSmartNameResolution /t REG_DWORD /d 1 /f
- Copy the command above.
- In the Start menu, search for
cmd. - Right-click
Command Promptand chooseRun as administrator. - Paste the command and press
Enter. - Restart Windows.
To undo it, run this command the same way, then restart Windows:
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" /v DisableSmartNameResolution /f
If you used Group Policy, set the policy back to Not Configured instead.
Browsers
Encrypted DNS
Browsers can use their own encrypted DNS (DNS over HTTPS), and Windows 11 can use it for a network adapter. These lookups do not use port 53, so Strict Route does not block them, and they do not use Throne's DNS settings. A leak test then shows the servers of that DNS provider.
If you want every lookup to go through Throne's DNS, turn off the secure DNS option in the privacy or security settings of your browser. Also turn off DNS over HTTPS for your network adapter in Windows Settings.
QUIC
Turning off QUIC does not fix DNS leaks. It helps with a different problem. Many sites, such as Google and YouTube, use QUIC (HTTP/3 over UDP), and some proxy servers carry UDP badly or not at all. If these sites load slowly or fail through the tunnel while other sites work, turn off QUIC in the browser so that it uses TCP.
In Chrome:
- Open
chrome://flags/. - Search for
QUIC. - Set
Experimental QUIC protocoltoDisabled. - Press
Relaunch.
Still leaking?
- Check your routing. Some results are expected. For example, domains that your rules send direct are looked up with
Direct DNSon purpose, and that is usually the DNS server of your internet provider. DNS leak tests lists the expected results. - Check security software. Some antivirus and firewall products filter or redirect DNS themselves. Test with them paused, or add an exception for Throne.
- Check other VPN apps. Disconnect other VPN clients while you use TUN mode. They can change DNS settings and firewall rules too.