A DNS leak occurs when your DNS queries are sent outside the VPN tunnel, typically to your ISP’s resolver. Your ISP can then see which domains you visit, defeating a core purpose of the VPN.
Causes include VPN software that does not route DNS, operating systems that prefer their own resolvers, and misconfigured IPv6. Many VPNs offer a “DNS leak protection” setting.
To test, connect your VPN and use a “what is my IP” service plus a dedicated leak test; your resolver should belong to the VPN provider, not your ISP.