Skip to main

VPN leak test: DNS, WebRTC and IPv6

In 10 seconds we show what websites can see about you: your IP address, DNS servers, WebRTC, IPv6 and time zone — and how to fix every leak.

FreeNo sign-upResults are not stored
Your IPdetecting…

The test runs in your browser for about 10 seconds. Addresses go to the public services ipify and ip-api, which see them by definition; we do not store the result.

Press «Run the test»

The test takes up to 10 seconds. Cards fill in as soon as each check is ready.

IPv4

public address
Waiting

The test takes up to 10 seconds. Cards fill in as soon as each check is ready.

IPv6

next-generation address
Waiting

—

WebRTC

what the browser exposes
Waiting

—

DNS

who resolves your queries
Waiting

—

Time zone and language

do they match the IP's country
Waiting

—

Only need your IP address, ISP and browser details? That is the What is my IP page.

What DNS, WebRTC and IPv6 leaks are

A VPN or proxy replaces your IP address for websites. But the browser and the OS sometimes send part of the traffic around the tunnel, and a website learns your real network.

DNS leak

Before opening a site, your device asks a DNS server for its address. If those queries go to your home ISP's DNS while the VPN is on, the ISP sees which sites you open and a website can learn your real network.

How it should beBrowserVPNVPN DNS
LeakBrowserISP DNS

WebRTC leak

WebRTC powers calls and video chat in the browser. To connect two people directly, the browser learns its public address from a STUN server. If that request bypasses the VPN, any website can read your real IP with one line of JavaScript.

How it should beBrowserVPNSTUN
LeakBrowserSTUN, real IP

IPv6 leak

Many VPNs tunnel only IPv4. If your ISP gives you IPv6, sites reachable over IPv6 get your requests directly, around the tunnel, and see an address from your home network.

How it should beBrowserVPN (IPv4)Website
LeakBrowserIPv6 around the VPN

How to fix leaks on Windows, macOS, iOS, Android and in the browser

Pick your system. The steps are general; exact menu names depend on your OS version and VPN client.

DNS leak

In your VPN client turn on «Use VPN DNS» and the kill switch. Stop Windows from sending DNS to every adapter: gpedit.msc → Computer Configuration → Administrative Templates → Network → DNS Client → «Turn off smart multi-homed name resolution» → Enabled. For WireGuard add a DNS = line to the [Interface] section.

WebRTC leak

A WebRTC leak is easiest to close in the browser (see the «Browser» tab). If your VPN client has WebRTC leak protection, turn it on.

IPv6 leak

Turn on IPv6 support or IPv6 leak protection in your VPN. For WireGuard use AllowedIPs = 0.0.0.0/0, ::/0. If the VPN cannot do IPv6, disable it on the adapter: ncpa.cpl → adapter properties → untick «Internet Protocol Version 6 (TCP/IPv6)».

Time zone and language

If the zone should match the IP: Settings → Time & language → Date & time → turn off «Set time zone automatically» and pick the zone.

FAQ

What does the VPN leak test check?

Five things: your public IPv4 address and its provider, your IPv6 address, the public address the browser learns through WebRTC, the DNS servers that resolve your queries, and whether the browser's time zone and language match the IP's country. The verdict is «No leaks found», «Indirect signs» or «Looks like a leak».

Is «IPv6 unavailable» bad?

No. It means your network or VPN has no IPv6 or it is disabled, so nothing can leak over IPv6. The problem is the opposite case: IPv6 works but belongs to a different provider than IPv4.

Why are Cloudflare, Google or Quad9 DNS not a leak?

They are public DNS and DNS-over-HTTPS services. They do not reveal your ISP: only the service itself sees the query. We call it a leak when the DNS server belongs to your home ISP while websites see an IP from another network, such as a VPN.

The test shows my ISP's DNS without a VPN. Is that wrong?

No. Without a VPN your ISP's DNS is normal and the test accounts for it. If the ISP runs DNS from another autonomous system or country, you get an orange «indirect sign», not a leak. Every address with its ASN and country is shown so you can check it yourself.

Why is the time zone a sign rather than a leak?

Websites read the browser's time zone and language with JavaScript. If the IP is Dutch but the time zone is Moscow, a site can guess you use a VPN or proxy. Your network is not exposed, so this is only an «indirect sign».

How accurate is the verdict?

We do not know your real ISP, so the DNS verdict is a heuristic: we say «looks like a leak», not «leak proven». Every value is shown with its provider, ASN and country so you can verify it.

Do you store my IP?

No. Your browser runs the test; our server only compares the addresses and answers right away. To detect the addresses the browser calls the public services ipify and ip-api, which see your IP. A report is e-mailed only if you leave your address.

Which VPN does not leak?

Any VPN that sends DNS through the tunnel, covers or blocks IPv6 and has a kill switch. Our own LiMP VPN does all three. Run this test again after switching your VPN on to confirm.