IP and DNS Leak Test: How to Check Your VPN Connection
Learn how to run a quick IP and DNS leak test to catch traffic slipping outside your VPN tunnel, plus the fixes that stop it from happening again.
An IP or DNS leak happens when, even though your VPN is turned on, part of your traffic still goes straight through your regular internet provider. As a result, your real IP address or the domains you visit become visible outside the encrypted tunnel, even though you think everything is protected.
Why leaks happen
The causes are usually technical quirks, not a "broken" app:
- DNS requests take the old route. Your operating system defaults to the DNS servers set by your router or provider, and it doesn't always switch to the VPN's DNS servers automatically.
- IPv6 runs alongside IPv4. Many apps only protect IPv4 traffic, so IPv6 requests go out unprotected if the protocol isn't disabled on the device.
- WebRTC in the browser. The technology behind browser video calls can expose your real IP address even with an active VPN connection — that's a browser quirk, not an app failure.
- Brief connection drops. When your network switches (say, from Wi-Fi to mobile data), the VPN tunnel can drop for a second, letting some requests slip through unprotected.
How to check your IP and DNS in 5 minutes
The process is simple and works on any device:
- Turn off your VPN and note your regular IP address — most IP-checking sites display it as a single number on the page.
- Turn on your VPN and connect to a server.
- Refresh the IP-checking page — the address should change completely to the server's address you connected to, with no trace of your original one.
- Open a separate DNS leak test tool — it lists the DNS servers actually handling your requests. Only your VPN provider's servers should appear, not your home internet provider's.
- If you use a browser, also test for WebRTC leaks — there are free pages built just for this that instantly show whether your real address is exposed through the browser's API.
What your test results mean
| Test result | What it means | What to do |
|---|---|---|
| IP fully changed, DNS shows only VPN servers | Everything is working correctly | Nothing — your connection is properly protected |
| IP changed, but your provider's server shows up in the DNS list | DNS leak | Turn on DNS protection in the app's settings or switch protocols |
| WebRTC shows your real address in the browser | Browser leak | Disable WebRTC in browser settings or use a blocking extension |
| IP doesn't change at all | VPN isn't actually active | Check whether the app is really connected to a server |
How to stop leaks from happening again
A one-time check only shows you the current state — it's far more useful to set up your protection so leaks don't come back:
- Turn on the kill switch. This feature cuts internet access if the VPN connection drops unexpectedly, instead of letting traffic slip through unprotected.
- Disable IPv6 on your device if the app only protects IPv4 traffic — that way all your traffic travels over a single protocol.
- Use a protocol with built-in DNS protection. Modern VPN protocols usually route DNS requests through the same tunnel as everything else, with no extra setup needed.
- Recheck your connection after switching networks. A quick IP check after moving from Wi-Fi to mobile data saves you time troubleshooting later.
When it's worth raising a flag
If tests keep showing a leak across different servers, even after reinstalling the app, that's a sign to contact support with concrete test results (screenshots) rather than endlessly tweaking settings on your own. A good support team should be able to explain the cause or point you to a specific leak-free protocol.
This topic is especially relevant on open networks — read more in our article on public Wi-Fi security, and if you want to verify a provider's data-handling claims, check out our piece on no-logs policies. For plans and subscription details, visit our pricing page.