VPN Leak Test: How It Works
A VPN is only doing its job if none of your traffic escapes outside the tunnel. Leaks happen quietly — the connection looks fine while DNS queries, WebRTC requests or IPv6 traffic bypass it entirely. This test checks the three places that leak.
The three leaks
| Leak | What escapes | Why it happens |
|---|---|---|
| DNS | Every domain you visit | The system uses the ISP's resolver instead of the VPN's |
| WebRTC | Your real IP address | The browser API queries local network interfaces directly |
| IPv6 | All IPv6 traffic | The VPN tunnels IPv4 only; IPv6 routes normally |
DNS leaks
Even with traffic encrypted, if DNS queries go to your ISP's resolver, your ISP has a complete list of every domain you visit. The content is hidden; the destinations are not, and for most surveillance purposes the destinations are the point.
Check by comparing the resolver shown in a test against your VPN provider's. If it belongs to your ISP, the VPN is not handling DNS. Most clients have a setting to force DNS through the tunnel; enable it.
WebRTC leaks
WebRTC powers browser video calling, and to establish peer connections it asks the operating system for local network addresses — including your real public IP, bypassing the VPN entirely. It is a browser feature working as designed, not a VPN fault, which is why it catches people out.
Mitigations: disable WebRTC where the browser allows it, use an extension that restricts the API, or rely on a VPN client that blocks it at the system level. Test after any browser update, since settings sometimes reset.
IPv6 leaks
Many VPNs tunnel IPv4 only. On a dual-stack connection, IPv6 traffic then routes through your ISP unprotected — and modern sites increasingly prefer IPv6 when it is available, so this can be a large share of your traffic. A good client either tunnels IPv6 or blocks it entirely; a client that ignores it is leaking.
The kill switch
Every VPN connection drops occasionally. Without a kill switch, traffic silently reverts to your normal connection at that moment and you may not notice for hours. A kill switch blocks all traffic until the tunnel is re-established. If your provider offers one, it should be on — this is the setting that matters most in practice.
What a VPN does not do
- It does not make you anonymous. Logins, cookies and browser fingerprinting identify you regardless of address.
- It does not protect against malware or phishing.
- It does not hide activity from the sites you use. Signed into an account, you are identified.
- It does not eliminate trust. It moves visibility from your ISP to the VPN provider, who can see everything the ISP previously could.
That last point is the one worth sitting with. A free VPN in particular has to fund itself somehow, and the product being sold is frequently the traffic data of its users. 'Trust this company more than your ISP' is a defensible position for some providers and a bad trade for others.
Testing properly
- Note your real IP with the VPN off.
- Connect, then re-check — the address should have changed.
- Check the DNS resolver belongs to the VPN, not your ISP.
- Check WebRTC exposes no local or real address.
- Check whether an IPv6 address is visible.
- Disconnect the network briefly to confirm the kill switch blocks traffic.