VPN leak test checklist

Check the public exit IP, DNS resolver observations and WebRTC addresses separately. A VPN connection icon or a low IP risk score alone cannot establish that every application uses the tunnel.

What can the checks tell you?

Resolver location can differ because of anycast or upstream infrastructure. Browser tests cover this browser session, not every application or all future traffic. Missing observations remain unknown.

Steps

  1. Confirm that the public IP matches the intended VPN exit.
  2. Compare DNS observations with the provider’s documented routing; investigate unexpected resolvers.
  3. Compare WebRTC public addresses with the intended exit, then repeat after one configuration change.

FAQ

Does a passed checklist guarantee anonymity?

No. It is a snapshot of limited observations. Accounts, cookies and other applications can behave differently.

Related diagnostics

Modern home, IP risk, privacy and latency pages start a shared session automatically, including external DNS and STUN connections. Direct entry to tools, method or policy pages does not start a session; an existing session may continue. Old language homepages show an IP profile and use separate buttons for extra browser checks. Guides are explanations, not test results.

LanguageEnglish简体中文繁體中文Español — inicioFrançais — accueil日本語 — ホーム한국어 — 홈