Back
Whoer.net Explained: What "Disguise %" and a Foreign DNS Really Mean

Last updated: July 25, 2026
Quick answer: Whoer.net is the most popular "how anonymous am I" checker — and the most misread one. The scary "disguise 63%" score and a DNS flag from the wrong country are, in most cases, not a leak and not a broken proxy. Here's what each Whoer check actually measures, which ones matter, and how to test a proxy properly.
What Whoer checks
When you open whoer.net, it looks at your IP address, DNS servers, browser headers, time zone, language, WebRTC, and JavaScript environment, then boils everything down to one percentage. That single number is what confuses everyone — so let's take the checks one by one.
"My IP is USA but DNS shows South Africa" — the classic panic
This is the single most common complaint we see from proxy users, and it's almost never a problem. Here's what actually happens:
Your proxy node needs to turn domain names into addresses, so it asks a public DNS resolver — usually Google's
8.8.8.8.Google doesn't have one DNS server; it has hundreds around the world. Your request exits from whichever data center is closest to the proxy node — often South Africa or Singapore.
Whoer sees a DNS request coming from a Google server in South Africa and paints a red flag next to it.
Check the DNS address itself: if it starts with 172.253.x.x or similar Google ranges, that's Google's infrastructure — not your home provider. Your real ISP appears nowhere in this chain, which means there is no leak. A leak would be your home ISP's DNS showing up while you're on a proxy — a completely different picture.
Does the DNS country actually matter?
For 95% of tasks — no. Social networks, marketplaces, dating platforms and ad accounts don't compare your DNS country against your IP country. A handful of streaming services do. If your specific task is one of those rare cases:
Use SOCKS5 and enable "resolve DNS through proxy" in your browser or antidetect profile — SOCKS5 supports this natively.
Verify on browserleaks.com, which shows raw data without a marketing score on top.
What "disguise 63%" actually is
The disguise percentage is Whoer's own formula, and it's built to alarm you: the site sells its own VPN, and a scary score converts visitors. Things that lower your percentage include running an "unpopular" browser language, a time zone mismatch, or simply having JavaScript enabled — none of which real antifraud systems weigh the way Whoer implies. Treat the number as a checklist hint, not a verdict.
The checks that DO matter
Check | Why it matters | What "good" looks like |
|---|---|---|
IP type and reputation | Sites treat datacenter IPs and residential IPs completely differently | Residential or mobile IP, not flagged in blacklists |
WebRTC | Can reveal your real IP even behind a proxy | Disabled or showing only the proxy IP |
Time zone vs IP country | Easy signal for antifraud | System time zone matches the IP's region |
Language vs GEO | Same | Browser language plausible for the IP country |
DNS country | Only for a few streaming services | Usually ignorable (see above) |
The first row is the one you can't fix in settings — it depends on the proxy itself. A clean residential or mobile IP passes as a normal user; a cheap datacenter IP fails IP-type checks no matter how perfect the rest of your setup is.
How to test a proxy properly
Open browserleaks.com — check IP, WebRTC, and DNS separately, without a combined score.
Match your time zone and language to the IP's country (antidetect browsers do this per profile).
For DNS-sensitive tasks, use SOCKS5 with remote DNS resolution.
Ignore any single "anonymity percentage" — no real antifraud system works that way.
FAQ
Is Whoer.net accurate?
The raw data (IP, DNS, WebRTC, headers) is accurate. The disguise percentage is a marketing formula — read the data, ignore the score.
Whoer shows DNS in another country — is my proxy leaking?
Almost certainly not. The proxy node resolves domains through Google DNS, and Google answers from its nearest data center. A real leak is your home ISP's DNS appearing — not Google's.
Why does Whoer show 63% disguise with a paid proxy?
Usually time zone or language mismatch with the IP country, or WebRTC — browser-side settings, not the proxy's fault. Fix them in an antidetect profile and the score jumps.
What's better than Whoer for checking?
browserleaks.com for detail, plus a quick IP-reputation lookup. For the underlying IP quality itself, that's determined by what you buy — residential and mobile IPs from the catalog are what antifraud systems classify as normal users.

