

Under various circumstances, the system process svchost.exe will send out DNS queries without respecting the routing table and the default gateway of the VPN tunnel, causing the leak. Each network interface can have its own DNS.

In brief: Windows lacks the concept of global DNS. In this context, with "DNS leak" we mean an unencrypted DNS query sent by your system OUTSIDE the established VPN tunnel. At "WebRTC" mark select "Disable non-proxied UDP". Select "Show advanced settings" and click on "Privacy & security".

Mozilla Firefox: Type "about:config” in the address bar.WebRTC implement STUN (Session Traversal Utilities for Nat), a protocol that allows to discover the public IP address.
