VPN Leak Test
Check whether your browser, DNS, or WebRTC traffic reveals additional public network paths.
- No install
- No account
- No camera or microphone
- First-party diagnostics
Ready to test
This test checks your connection path, forced IPv4/IPv6 paths, WebRTC candidates and DNS resolvers, then compares them for consistency.
- Connection path
- Not tested
- IPv4
- Not tested
- IPv6
- Not tested
- WebRTC
- Not tested
- DNS
- Not tested
Checking your network paths
- Checking connection path
- Checking network identity
- Inspecting WebRTC paths
- Checking DNS resolver path
- Preparing result
Try the test again.
Possible causes
A different public network path can occur normally for several reasons:
Observed public paths
Why this result
Supporting
Informational
Concerning
Understanding VPN leak tests
Understand what this test checks
A different address is not automatically a problem — here’s what each signal can and can’t tell you.
-
01
What does a VPN leak test check?
This test compares the public network path your browser normally uses with the paths exposed through forced IPv4/IPv6 requests, WebRTC and DNS — then reports whether those paths agree, rather than guessing at what software is running on your device.
-
02
Why can WebRTC reveal another path?
WebRTC gathers network addresses to find the best route between two devices. If that address differs from the one used for ordinary web requests, it’s a second observed path — not proof of anything by itself.
-
03
Why do DNS resolvers matter?
The resolver handling your DNS queries can belong to your ISP, a VPN, or a public service like Google or Cloudflare. Any of these can be entirely normal; it only becomes informative alongside the other signals.
-
04
Why might IPv4 and IPv6 differ?
Dual-stack networks routinely send IPv4 and IPv6 traffic through different infrastructure, addresses and even providers. A cross-family difference alone is expected, not a fault.
-
05
Why isn’t an extra IP automatically a leak?
CGNAT, multi-WAN setups, split tunneling and normal ISP routing can all produce an additional address. This test looks for corroborating evidence — a matching network identity across signals — before treating a difference as noteworthy.
-
06
What does the confidence level mean?
Confidence reflects how much usable HTTP, WebRTC, and DNS evidence was available and how consistently those signals aligned. A high-confidence result is stronger evidence, not a guarantee that every possible network path was tested.
How this test works
- 01 HTTP path observation Your normal public IP is read the same way any website sees it.
- 02 Forced IPv4/IPv6 checks Dedicated IPv4-only and IPv6-only requests confirm what each address family actually exposes.
- 03 Network identity enrichment Each observed IP is matched to its network, ASN and provider.
- 04 WebRTC observation IPRevealed’s own first-party STUN server gathers any public WebRTC candidates.
- 05 DNS resolver observation A quick DNS check identifies which resolver actually answered your query.
- 06 Conservative multi-signal verdict Every signal is combined conservatively; a single difference is never treated as a leak on its own.