Skip to main content
Aivorize Tools

Methodology and Limitations

We want the tools to be useful and honest. That means explaining how each result is produced, what is measured locally, and where uncertainty remains.

How IP detection works

Your public IP is read from the request that reaches the server. Depending on the hosting layer, the app reads trusted headers such as x-forwarded-for, x-real-ip, or cf-connecting-ip. That IP is then sent server-side to ipapi.is to retrieve your approximate city, region, country, ISP name, ASN, and VPN/proxy/Tor signals. The enrichment happens on our server - the API key is never exposed to your browser.

How browser data is read

Browser information such as your browser name, operating system, language, screen resolution, color depth, timezone, hardware thread count, and cookie support is read locally in the browser using standard Web APIs (navigator, screen, Intl). This data is used only to display the result on your screen and is never transmitted to our servers.

How WebRTC testing works

WebRTC can expose local and public network addresses through ICE (Interactive Connectivity Establishment) candidates - a standard part of how peer-to-peer connections are negotiated. Our WebRTC Leak Test and VPN Check tools initiate a dummy RTCPeerConnection with Google's STUN servers (stun.l.google.com:19302) to collect ICE candidates. Any public IP addresses exposed in those candidates - beyond the IP already reported by the server - are classified as a potential leak. Your browser connects directly to Google's STUN servers; our server does not mediate this step.

How the DNS Leak Test works

The DNS Leak Test uses the bash.ws public API to determine which DNS resolvers are handling your requests. The test runs in three stages:

  1. Session ID: Your browser fetches a unique random ID from bash.ws/id. This ties all subsequent probe requests to your test session.
  2. DNS probes: Your browser makes 10 fetch requests to unique subdomains of that session ID under bash.ws (e.g. 1.{id}.bash.ws through 10.{id}.bash.ws). Each request triggers a DNS lookup. The DNS resolvers that handle these lookups are logged by bash.ws's authoritative DNS server.
  3. Results: After a short delay to allow all DNS lookups to register, your browser fetches the results from bash.ws's API. The response includes your public IP and a list of the DNS server IPs that resolved your requests, along with their country and ASN.

If the DNS servers shown belong to your ISP rather than your VPN provider, it indicates your DNS queries are bypassing the VPN tunnel - a DNS leak. If the DNS servers match your VPN provider's infrastructure, your DNS is properly tunneled.

Accuracy limits

  • IP geolocation is approximate and may point to the ISP's infrastructure rather than your actual location.
  • VPN, proxy, and Tor detection are based on signals from ipapi.is and provider data, not perfect certainty. A result of “not detected” does not guarantee your connection is anonymous.
  • WebRTC behavior varies by browser, platform, and extension configuration. Some browsers block ICE candidates by default.
  • DNS leak results depend on which DNS resolvers bash.ws observes. Split-horizon DNS or certain VPN configurations may produce inconclusive results.
  • Local browser details are accurate for the current device and session, but they do not identify who you are as a person.

What we store

This site does not store any diagnostic results, IP addresses, or browser fingerprint data after your request completes. The IP enrichment provider (ipapi.is) and the DNS test provider (bash.ws) receive the minimum data needed to return a result; what they retain is governed by their own policies. See the Privacy Policy for the full breakdown.

Where to go next

Try the What Is My IP tool, then review the privacy policy if you want the data handling details in plain language.