Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

VPN Leak Test

Find out whether anything slips past your VPN — IPv6, WebRTC or your clock.

Network Uses live data Free, no sign-up

Run the VPN leak test

Untick it for a baseline run without the VPN. The test contacts MySmartCoPilot’s server, icanhazip.com or ipify.org, Google’s public STUN server and the Tor Project’s relay list — only when you press the button.

Next steps

About the VPN Leak Test

A VPN should carry all of your browser’s traffic. A leak is anything that still goes out through your own internet provider: IPv6 traffic the VPN does not tunnel, WebRTC (the technology behind video calls) asking a public server for your address over UDP, or a browser extension or split-tunnelling rule that sends some sites another way. Any of them shows websites your real network — and it takes them only a few lines of script.

This test looks at your connection the way websites do. It finds your IPv4 and IPv6 exit addresses, the public address WebRTC reveals, and the address MySmartCoPilot’s server sees, puts each one in its network (the AS that routes it), and compares them: if they leave through different networks, something leaks. It also checks whether the exit is a data centre or an internet provider, whether it is a Tor exit, and whether your browser’s time zone and languages fit the exit’s location — the clues sites use to spot VPN users. Each row says OK, Check, Leak or Info, with what was found and how to fix it.

How to use it

  1. Connect your VPN or proxy the way you normally use it, then open (or reload) this page.
  2. Leave My VPN or proxy is on right now ticked — untick it for a baseline run without the VPN — and press Run the leak test. It usually takes a few seconds.
  3. Read the verdict at the top, then each row: Leak means traffic leaves through another network; Check means something deserves a look; heuristic rows are marked as such.
  4. For a comparison, disconnect the VPN, untick the box and run the test again: your own provider should appear only in that baseline.
  5. Use Copy report or Download .txt to send the result to your VPN provider’s support.

Examples

A VPN that does not tunnel IPv6
Result
IPv4 exit: 198.51.100.24 — AS9009 M247 (data centre)
IPv6 exit: 2001:db8:abcd::5 — AS7922 COMCAST-7922
→ Leak found: IPv6 leak

IPv4 goes through the VPN, IPv6 straight to the home provider. Sites that support IPv6 see the home network. Documentation addresses (RFC 5737, RFC 3849) stand in for real ones.

WebRTC around a split tunnel
Result
Exit (browsing): 198.51.100.24 — AS9009 M247
WebRTC: 203.0.113.9 — AS7922 COMCAST-7922
→ Leak found: WebRTC leak

The browser’s web traffic uses the VPN, but its UDP traffic to the STUN server does not. The fix row names the WebRTC setting for each browser.

Everything tunnelled — except the clock
Result
All addresses: AS9009 M247 (Amsterdam)
Browser time zone: Asia/Kolkata (UTC+05:30)
→ No leaks found, but your time zone gives the VPN away

Nothing leaks, but any site can see that the browser’s clock is set for another place than the exit address.

Common uses

  • Checking a new VPN, a new VPN server or a VPN app update before you rely on it.
  • Finding out why a streaming or banking site still sees your home country with the VPN on.
  • Confirming that a corporate or school VPN carries IPv6 and WebRTC traffic too.
  • Collecting a clear report for your VPN provider’s support team.

What each check looks at

  • IPv6 leak: your IPv4 and IPv6 exits must leave through the same network. Many VPNs tunnel only IPv4; then IPv6 goes straight out through your provider.
  • Different routes for different sites: MySmartCoPilot’s server and the address check should see the same network. If not, split tunnelling, a proxy setting or an extension sends part of your traffic another way.
  • WebRTC leak: the page asks a public STUN server (Google’s) for its view of your address over UDP, as video-call sites do, and compares it with your exits.
  • Local address: whether WebRTC shows your device’s local address (such as 192.168.1.20) or hides it behind a random “.local” name.
  • Exit network (heuristic): a data centre, a content-delivery network or an internet provider, from the networks the site knows, cloud providers’ published IP ranges and the network’s registered name.
  • Time zone and languages (heuristic): your browser’s settings against the location of your exit address.
  • Tor: whether the exit is a Tor exit relay in the Tor Project’s relay list.

WebRTC and your addresses

Browsers follow RFC 8828: without your consent, WebRTC may only use the route your web traffic takes (the “default route”) and may show the local address of that interface. Current browsers also hide that local address — usually behind a random .local name (mDNS) — unless a page has camera or microphone permission. A WebRTC leak therefore usually means the VPN does not catch UDP traffic, or it lets some interfaces bypass the tunnel. A trusted VPN app’s WebRTC or leak protection fixes it for every browser; the fix row also names the browser setting.

Heuristics, not certainty

Addresses are compared by network — the AS (autonomous system) that announces them on the internet — using the IPtoASN routing snapshot (public domain, PDDL v1.0) that ships with the site; two addresses of one AS count as the same network. Whether a network is a data centre or an internet provider is a heuristic: known cloud, hosting and CDN networks, the published IP ranges of large cloud providers, and words in the network’s registered name. Some VPNs rent home-broadband addresses (“residential” exits), which look like an internet provider, and a network’s name can be misleading — so these rows are labelled heuristic and never decide on their own that something leaks.

The same judgement separates a leak from a VPN with two providers: when IPv4 and IPv6 (or WebRTC) leave through two different networks, that is a Leak — unless both look like data-centre networks. Then the row says Check instead, because a leak shows your home or mobile provider, while two hosted networks usually belong to the VPN. A baseline run without the VPN reports such differences as information only.

Limitations

  • It tests this browser only. Other apps can bypass the VPN differently, for example with per-app split tunnelling.
  • DNS leaks are not tested: a web page cannot see which DNS resolver your device asks, and testing it needs a DNS server that records the resolvers looking up one-time names, which this site does not run. Use your VPN provider’s DNS leak test.
  • Network names come from a routing snapshot, so a block of addresses that recently moved to another network can show its earlier owner.
  • If a content blocker stops icanhazip.com, ipify.org or the STUN server, those checks find fewer addresses; the rows then say what is missing.
  • MySmartCoPilot’s server allows a limited number of these tests per hour for each visitor.

Privacy

The test runs only when you press the button, and its results stay in your browser. Your browser asks MySmartCoPilot’s server how it sees your connection (address, approximate location, time zone and network — nothing is stored or logged); asks icanhazip.com, or ipify.org if that fails, for your IPv4 and IPv6 addresses; sends a STUN request to Google’s public STUN server (stun.l.google.com), as any video-call site does; and asks the Tor Project’s Onionoo service whether your exit address is a Tor relay. Each of them sees your IP address, like any site you visit. Network names are looked up in data files downloaded from MySmartCoPilot, so your addresses are not sent anywhere for that.

Frequently asked questions

What is a VPN leak?

Traffic that leaves your device outside the VPN tunnel, so websites see your real internet provider. The usual causes are IPv6 that the VPN does not carry, WebRTC traffic over UDP, split-tunnelling rules, proxy settings and browser extensions.

The test found an IPv6 leak. What should I do?

Turn on the VPN app’s IPv6 leak protection (often called “block IPv6” or part of a kill switch), or choose a VPN that tunnels IPv6. As a stopgap, switch IPv6 off for the network adapter or on your router while you use the VPN, then run the test again.

Does a WebRTC leak mean my VPN is broken?

It means the VPN does not catch all UDP traffic from this browser. Turn on the VPN’s WebRTC or leak protection, or limit WebRTC in the browser as the fix row describes. Video calls in the browser can stop working if you switch WebRTC off completely.

Why does the test say my time zone gives the VPN away?

Your browser tells every site its time zone, and sites can compare it with the location of your IP address. A clock set for India behind an Amsterdam address is a common sign of a VPN. It is not a leak — your address stays hidden — but if it matters, set the device’s time zone to match or pick a VPN server in your own time zone.

Is it normal that my exit network is a data centre?

Yes, with a VPN: VPN servers run in data centres, so the exit network should be one. Without a VPN, a data-centre exit usually means a work network, a cloud desktop or a proxy.

Why is there no DNS leak test?

A web page cannot read which DNS resolver your device uses. A DNS leak test needs its own DNS server that logs which resolvers look up one-time names, and this site does not run one. Your VPN provider’s own DNS leak test can check it.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.