VPN Leak Check
Compare your connection before and after connecting to a VPN to verify if it is genuinely masking your IP, IPv6, and WebRTC traffic.
Step 1: Record Baseline
First, we need to record what your unprotected connection looks like. Make sure your VPN is currently disconnected.
Embed this VPN tool on your website
Want to let your readers verify their VPN status directly from your blog? Our embeddable VPN Check widget is 100% free and lightning fast.
How does this test work?
When you connect to a VPN, all of your internet traffic is supposed to be routed through an encrypted tunnel to a remote server. To the rest of the internet, your traffic should appear to originate from that server's IP address, masking your true identity and location.
However, VPN software isn't perfect, and modern web browsers have complex networking features. Sometimes, a VPN fails to route all traffic properly, leading to leaks.
This test works by comparing your connection state across two stages:
- Stage 1 (Baseline): We record your unprotected public IPv4 address, your IPv6 address (if your network supports it), and query your browser's WebRTC API to gather all accessible local and public ICE candidates.
- Stage 2 (Active): After you connect to the VPN, we run the exact same checks again.
We then compare the results. If your main IPv4 address hasn't changed, the VPN tunnel isn't active. If your IPv4 changed but your IPv6 address remained the same, your VPN is leaking IPv6 traffic. And if WebRTC exposes your original baseline IP while connected to the VPN, your browser is leaking your true identity via peer-to-peer protocols.
How Does a VPN Leak Test Work?
A VPN (Virtual Private Network) creates an encrypted tunnel between your device and a remote server. When it is working correctly, any website you visit should see the VPN server's IP address, not your real home IP. This test works by recording your connection fingerprint before and after the VPN is active, then comparing the results across three dimensions: your public IP, your IPv6 address, and your DNS resolver.
The key insight is that a VPN can fail in three independent ways simultaneously. A VPN could successfully mask your public IPv4 address but completely fail to mask your IPv6 address. It could hide your IP address but still route DNS requests through your ISP, revealing every domain name you visit. Or it could mask IP and DNS but still expose your real IP through the browser's WebRTC API. A true VPN check must test all three independently.
What Is an IPv6 Leak?
IPv6 is the next-generation internet addressing system. Many modern internet connections have both an IPv4 address (like 203.0.113.1) and an IPv6 address (like 2001:db8::1). A large number of VPNs are configured to only tunnel IPv4 traffic. When this happens, all IPv6 traffic bypasses the VPN entirely and is sent directly through your ISP, exposing your real IPv6 address to every website you visit. This is called an IPv6 leak.
IPv6 leaks are surprisingly common even with well-known VPN providers, because many VPNs default to IPv4-only protection. The fix is to ensure your VPN either has full IPv6 support or explicitly blocks all IPv6 traffic to prevent leaks.
Are Free VPNs Safe to Use?
While a free VPN might successfully change your IP address, it often comes with significant privacy trade-offs. Running a global network of encrypted servers is expensive. If you aren't paying for the product, you are often the product. Many free VPNs have been caught logging user activity, injecting ads into webpages, or selling bandwidth to third parties.
Furthermore, free VPNs are notorious for failing basic leak tests. Because they lack the advanced kill-switches and DNS routing features of premium providers, they frequently leak DNS queries and WebRTC IPs, rendering the core purpose of the VPN useless. It is highly recommended to use a verified, paid VPN provider with a strict no-logs policy and built-in leak protection.
The Importance of a VPN Kill Switch
A VPN kill switch is a critical security feature that monitors your connection to the VPN server. If that connection drops even for a fraction of a second, the kill switch instantly blocks all internet traffic on your device.
Without a kill switch, your operating system will silently fall back to your default ISP connection if the VPN disconnects. Your browser or torrent client will continue downloading and communicating using your real public IP address without you ever noticing. Our VPN check tool records the before-and-after states, but it cannot protect you from mid-session dropouts—only a reliable kill switch can do that.
Frequently Asked Questions
How do I know if my VPN is working?
Record your IP address without the VPN using this tool, then connect your VPN and run the check again. If the public IP and ASN are different, your VPN is routing your traffic. If they are the same, your VPN is not masking your connection.
What is a WebRTC leak in a VPN?
WebRTC is a browser technology for real-time communication like video calls. It can expose your real IP address to websites even when a VPN is active by bypassing the VPN tunnel through a separate channel. Our check detects this automatically. Use the dedicated WebRTC Leak Test for a more detailed report.
What does ASN mean in a VPN check?
An ASN (Autonomous System Number) identifies the network organisation your IP address belongs to. When connected to a VPN, the ASN should change from your ISP's organisation to your VPN provider's organisation. If the ASN has not changed, your traffic is still routing through your ISP regardless of what your VPN app says.
What if I have no IPv6 address?
If this tool shows "no IPv6 detected," it means your ISP has not yet assigned you an IPv6 address, which is still common. This is actually safe from a VPN leak perspective, since there is no IPv6 address that could leak in the first place.