IPv4
public addressThe test takes up to 10 seconds. Cards fill in as soon as each check is ready.
In 10 seconds we show what websites can see about you: your IP address, DNS servers, WebRTC, IPv6 and time zone — and how to fix every leak.
The test runs in your browser for about 10 seconds. Addresses go to the public services ipify and ip-api, which see them by definition; we do not store the result.
The test takes up to 10 seconds. Cards fill in as soon as each check is ready.
The test takes up to 10 seconds. Cards fill in as soon as each check is ready.
—
—
—
—
We will send the test result with every address, provider and the fixes. Easy to forward to your admin.
LiMP VPN is built by YuSMP Group. It keeps all of your traffic inside the tunnel:
Only need your IP address, ISP and browser details? That is the What is my IP page.
A VPN or proxy replaces your IP address for websites. But the browser and the OS sometimes send part of the traffic around the tunnel, and a website learns your real network.
Before opening a site, your device asks a DNS server for its address. If those queries go to your home ISP's DNS while the VPN is on, the ISP sees which sites you open and a website can learn your real network.
WebRTC powers calls and video chat in the browser. To connect two people directly, the browser learns its public address from a STUN server. If that request bypasses the VPN, any website can read your real IP with one line of JavaScript.
Many VPNs tunnel only IPv4. If your ISP gives you IPv6, sites reachable over IPv6 get your requests directly, around the tunnel, and see an address from your home network.
Pick your system. The steps are general; exact menu names depend on your OS version and VPN client.
In your VPN client turn on «Use VPN DNS» and the kill switch. Stop Windows from sending DNS to every adapter: gpedit.msc → Computer Configuration → Administrative Templates → Network → DNS Client → «Turn off smart multi-homed name resolution» → Enabled. For WireGuard add a DNS = line to the [Interface] section.
A WebRTC leak is easiest to close in the browser (see the «Browser» tab). If your VPN client has WebRTC leak protection, turn it on.
Turn on IPv6 support or IPv6 leak protection in your VPN. For WireGuard use AllowedIPs = 0.0.0.0/0, ::/0. If the VPN cannot do IPv6, disable it on the adapter: ncpa.cpl → adapter properties → untick «Internet Protocol Version 6 (TCP/IPv6)».
If the zone should match the IP: Settings → Time & language → Date & time → turn off «Set time zone automatically» and pick the zone.
Turn on the VPN client's own DNS. Check System Settings → Network → your adapter → Details → DNS: with the VPN on, your home router's DNS should not remain there. For WireGuard set DNS = in the [Interface] section.
A WebRTC leak is easiest to close in the browser (see the «Browser» tab). Safari only gives WebRTC to sites after a camera or microphone request, so leaks are more common in Chrome and Firefox.
Turn on IPv6 in the VPN client. If it is not supported: System Settings → Network → your adapter → Details → TCP/IP → «Configure IPv6» → «Link-local only».
System Settings → General → Date & Time → turn off automatic time zone and pick a city.
In the VPN app turn on DNS through the tunnel and «route all traffic through VPN». Remove third-party DNS profiles: Settings → General → VPN & Device Management.
Turn on the full tunnel («route all traffic through VPN») in your VPN app. WebRTC then goes through the tunnel too.
Choose a protocol with IPv6 support in your VPN app (for example, WireGuard) and the full tunnel. iOS does not let you disable IPv6 manually.
Settings → General → Date & Time → turn off «Set Automatically» and pick a city.
Settings → Network & internet → VPN → gear next to your VPN → turn on «Always-on VPN» and «Block connections without VPN». «Private DNS» in network settings sets its own resolver: switch it off or point it to your VPN's DNS.
Turn on «Always-on VPN» and «Block connections without VPN». Chrome on Android cannot disable WebRTC. In Firefox open about:config and set media.peerconnection.enabled = false.
Turn on IPv6 in the VPN app or choose a protocol that supports it. On mobile data you can keep IPv4 only: Settings → Network → SIM → Access Point Names → «APN protocol» → IPv4.
Settings → System → Date & time → turn off «Use network-provided time zone» and pick the zone.
Chrome, Edge: Settings → Privacy and security → «Use secure DNS». Turn it off so queries go through the VPN, or pick a public DNS-over-HTTPS provider. Firefox: Settings → Privacy & Security → «DNS over HTTPS».
Firefox: about:config → media.peerconnection.enabled = false, or enable «Prevent WebRTC from leaking local IP addresses» in uBlock Origin. Chrome, Edge: the WebRTC Network Limiter extension → «Use my proxy server». Full uBlock Origin has been disabled in Chrome since 2025, and uBO Lite has no such option.
The browser cannot help here: IPv6 is set up in the VPN and the OS. Open your OS tab.
Firefox: about:config → privacy.resistFingerprinting = true, then sites see UTC and English. The language is set in browser settings: put the IP country's language first.
Five things: your public IPv4 address and its provider, your IPv6 address, the public address the browser learns through WebRTC, the DNS servers that resolve your queries, and whether the browser's time zone and language match the IP's country. The verdict is «No leaks found», «Indirect signs» or «Looks like a leak».
No. It means your network or VPN has no IPv6 or it is disabled, so nothing can leak over IPv6. The problem is the opposite case: IPv6 works but belongs to a different provider than IPv4.
They are public DNS and DNS-over-HTTPS services. They do not reveal your ISP: only the service itself sees the query. We call it a leak when the DNS server belongs to your home ISP while websites see an IP from another network, such as a VPN.
No. Without a VPN your ISP's DNS is normal and the test accounts for it. If the ISP runs DNS from another autonomous system or country, you get an orange «indirect sign», not a leak. Every address with its ASN and country is shown so you can check it yourself.
Websites read the browser's time zone and language with JavaScript. If the IP is Dutch but the time zone is Moscow, a site can guess you use a VPN or proxy. Your network is not exposed, so this is only an «indirect sign».
We do not know your real ISP, so the DNS verdict is a heuristic: we say «looks like a leak», not «leak proven». Every value is shown with its provider, ASN and country so you can verify it.
No. Your browser runs the test; our server only compares the addresses and answers right away. To detect the addresses the browser calls the public services ipify and ip-api, which see your IP. A report is e-mailed only if you leave your address.
Any VPN that sends DNS through the tunnel, covers or blocks IPv6 and has a kill switch. Our own LiMP VPN does all three. Run this test again after switching your VPN on to confirm.