VPN leak test checklist
Check the public exit IP, DNS resolver observations and WebRTC addresses separately. A VPN connection icon or a low IP risk score alone cannot establish that every application uses the tunnel.
What can the checks tell you?
Resolver location can differ because of anycast or upstream infrastructure. Browser tests cover this browser session, not every application or all future traffic. Missing observations remain unknown.
Steps
- Confirm that the public IP matches the intended VPN exit.
- Compare DNS observations with the provider’s documented routing; investigate unexpected resolvers.
- Compare WebRTC public addresses with the intended exit, then repeat after one configuration change.
FAQ
Does a passed checklist guarantee anonymity?
No. It is a snapshot of limited observations. Accounts, cookies and other applications can behave differently.
Related diagnostics
Modern home, IP risk, privacy and latency pages start a shared session automatically, including external DNS and STUN connections. Direct entry to tools, method or policy pages does not start a session; an existing session may continue. Old language homepages show an IP profile and use separate buttons for extra browser checks. Guides are explanations, not test results.