Menu

VPN / WebRTC Leak Test

Purpose: Verify your public IP and check whether WebRTC is exposing local/private IP addresses - a common leak even when using a VPN.

Public IP & location

WebRTC local IP detection
Checking…
Tip: if a VPN is on and your public IP still shows your home country, or local IPs leak below, your setup may be exposing data.

VPN Leak Test: How It Works

A VPN is only doing its job if none of your traffic escapes outside the tunnel. Leaks happen quietly — the connection looks fine while DNS queries, WebRTC requests or IPv6 traffic bypass it entirely. This test checks the three places that leak.

The three leaks

LeakWhat escapesWhy it happens
DNSEvery domain you visitThe system uses the ISP's resolver instead of the VPN's
WebRTCYour real IP addressThe browser API queries local network interfaces directly
IPv6All IPv6 trafficThe VPN tunnels IPv4 only; IPv6 routes normally

DNS leaks

Even with traffic encrypted, if DNS queries go to your ISP's resolver, your ISP has a complete list of every domain you visit. The content is hidden; the destinations are not, and for most surveillance purposes the destinations are the point.

Check by comparing the resolver shown in a test against your VPN provider's. If it belongs to your ISP, the VPN is not handling DNS. Most clients have a setting to force DNS through the tunnel; enable it.

WebRTC leaks

WebRTC powers browser video calling, and to establish peer connections it asks the operating system for local network addresses — including your real public IP, bypassing the VPN entirely. It is a browser feature working as designed, not a VPN fault, which is why it catches people out.

Mitigations: disable WebRTC where the browser allows it, use an extension that restricts the API, or rely on a VPN client that blocks it at the system level. Test after any browser update, since settings sometimes reset.

IPv6 leaks

Many VPNs tunnel IPv4 only. On a dual-stack connection, IPv6 traffic then routes through your ISP unprotected — and modern sites increasingly prefer IPv6 when it is available, so this can be a large share of your traffic. A good client either tunnels IPv6 or blocks it entirely; a client that ignores it is leaking.

The kill switch

Every VPN connection drops occasionally. Without a kill switch, traffic silently reverts to your normal connection at that moment and you may not notice for hours. A kill switch blocks all traffic until the tunnel is re-established. If your provider offers one, it should be on — this is the setting that matters most in practice.

What a VPN does not do

That last point is the one worth sitting with. A free VPN in particular has to fund itself somehow, and the product being sold is frequently the traffic data of its users. 'Trust this company more than your ISP' is a defensible position for some providers and a bad trade for others.

Testing properly

  1. Note your real IP with the VPN off.
  2. Connect, then re-check — the address should have changed.
  3. Check the DNS resolver belongs to the VPN, not your ISP.
  4. Check WebRTC exposes no local or real address.
  5. Check whether an IPv6 address is visible.
  6. Disconnect the network briefly to confirm the kill switch blocks traffic.

Frequently Asked Questions

What is a DNS leak?
Your traffic goes through the VPN but your DNS queries go to your ISP's resolver, giving your ISP a full list of the domains you visit. The connection looks normal, which is what makes it easy to miss.
Why does WebRTC reveal my real IP?
WebRTC asks the operating system for local network addresses to establish peer connections, bypassing the VPN's routing. It is a browser feature behaving as designed rather than a VPN fault, which is why a VPN alone does not prevent it.
What is a kill switch and do I need one?
It blocks all internet traffic if the VPN connection drops, preventing silent fallback to your normal connection. Connections do drop, and without it you may not notice for hours. Enable it if your provider offers one.
Does a VPN make me anonymous?
No. It hides your address from sites and your destinations from your ISP, but logins, cookies and browser fingerprinting still identify you, and the VPN provider now sees everything your ISP previously could.
Are free VPNs safe?
Treat them with caution. Running a VPN costs money, and where the service is free the revenue often comes from the traffic data of its users — which inverts the reason for using one. Paid providers with independently audited no-log policies are a better proposition.
Should I disable IPv6?
If your VPN does not handle it, yes — otherwise IPv6 traffic bypasses the tunnel entirely, and modern sites often prefer IPv6 when available. A good client either tunnels or blocks it; disabling it system-wide is a workable fallback.

Related Security Tools

Browse all Security tools →