A VPN can look like it’s working, padlock icon, connected status, server list showing a foreign country, and still be leaking your real IP address, your ISP’s DNS servers, or both, through gaps most people never check for. Leak protection scores in our comparison table range from a perfect 5 out of 5 for providers like NordVPN, ProtonVPN, Surfshark and Mullvad down to 0 for several budget options, and the only way to know where your own VPN actually lands is to test it yourself. This takes about five minutes and needs nothing beyond a browser.

What a VPN leak actually is

A VPN is supposed to route all of your traffic, and the DNS lookups that translate website names into addresses, through its encrypted tunnel. A leak happens when some piece of that traffic slips outside the tunnel and reaches the open internet directly, exposing information the VPN was supposed to hide. There are three kinds worth checking for, and they fail independently of each other, so passing one test tells you nothing about the other two.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

IP leaks: is your real address showing?

An IP leak means your actual public IP address, the one assigned by your internet provider, is visible to a website despite your VPN being connected. This is the most basic failure a VPN can have, and it’s also the easiest to check.

  1. Before connecting to your VPN, search “what is my IP” and note the address shown, this is your real, unprotected IP.
  2. Connect to your VPN, choosing any server location different from your own country.
  3. Search “what is my IP” again. The address should now be different from your real one, and it should show the country of the server you connected to, not your own.

If the second check still shows your real IP or your real country, your VPN is not routing your traffic correctly, and you should stop using it for anything sensitive until you’ve confirmed the fix worked.

DNS leaks: are your lookups still going to your ISP?

Even when your traffic itself is routed correctly, DNS requests, the lookups that turn “example.com” into an IP address, can sometimes bypass the tunnel and go straight to your ISP’s own DNS servers instead of your VPN’s. That means your ISP can still see every domain you visit, even though your actual browsing traffic is encrypted.

  1. Connect to your VPN and pick a server in a different country.
  2. Visit a dedicated DNS leak testing site, dnsleaktest.com is a commonly used, free option, and run the extended test rather than the standard one.
  3. Check the results against your VPN’s server location and your ISP’s actual name. The DNS servers listed should belong to your VPN provider or a third-party privacy-focused resolver, not your home ISP.

If your ISP’s name shows up in the results, most VPN apps have a DNS leak protection toggle in their settings, usually enabled by default but worth confirming manually, especially after a recent app update.

WebRTC leaks: the browser-specific gap

WebRTC is a browser technology used for video calls and other real-time communication, and it can reveal your real IP address directly to a website through your browser, completely separate from your VPN’s network-level protection. This is a browser issue more than a VPN issue, which is why it needs its own test.

  1. With your VPN connected, visit a WebRTC leak test page, browserleaks.com’s WebRTC test is a widely used free option.
  2. Look for any “local” or “public” IP address listed that matches your real address rather than your VPN’s.
  3. If your real IP shows up, either disable WebRTC in your browser’s settings (Firefox has a built-in toggle; Chrome requires an extension), or use your VPN provider’s browser extension if it includes WebRTC leak blocking, which most major providers do by default now.

Running all three tests together

Once you’ve confirmed your VPN passes individually, it’s worth doing one combined check periodically, especially after any VPN app update, server switch, or operating system update, since any of those can silently reset a setting. Reconnect to your VPN, then run the IP check, the DNS leak test, and the WebRTC test back to back in the same browser session. If all three come back clean, showing your VPN’s server location consistently and no trace of your ISP or real IP, your connection is genuinely protected, not just appearing to be.

What to do if you find a leak

First, check whether your VPN app has a kill switch and make sure it’s enabled; this cuts your internet entirely if the VPN connection drops, which prevents exactly the kind of silent fallback to your unprotected connection that causes leaks. Second, try switching protocols within the app, WireGuard tends to have fewer leak issues than older OpenVPN configurations on some platforms. Third, disable IPv6 on your device if your VPN doesn’t fully support it, since IPv6 traffic can bypass an IPv4-only tunnel entirely without any error message. If none of that resolves it, the leak protection score in our comparison table is a good signal of which providers handle this consistently well versus which ones don’t, and it may simply be time to switch.

Testing on mobile, not just desktop

Most leak test guides assume you’re sitting at a laptop, but phones leak in the same three ways and get tested far less often. On iOS and Android, connect your VPN app first, then open your mobile browser and repeat the same IP and DNS checks you’d run on desktop; the same test sites work fine on a phone’s browser. WebRTC leak testing is less consistent on mobile since browser support for the underlying technology varies more, but the IP and DNS checks alone will catch the majority of real-world leak issues on a phone. Pay particular attention to what happens when your phone switches between Wi-Fi and mobile data mid-session, since some VPN apps briefly drop protection during that handoff before reconnecting, a gap that’s easy to miss unless you’re specifically testing for it.

Split tunneling and why it complicates testing

If you use split tunneling, routing some apps through the VPN and others outside it, standard leak tests can be misleading, since a “leak” in the traditional sense might actually just be an app you deliberately excluded working exactly as configured. Before running any of the tests above, check your VPN app’s split tunneling settings and confirm the browser you’re testing in isn’t on an exclusion list. If it is, either test in a different browser that’s fully routed through the tunnel, or temporarily disable split tunneling for the duration of the test, then re-enable it once you’ve confirmed the tunnel itself is leak-free.

Why this matters more on public Wi-Fi

A leak on your home network is a privacy problem. The same leak on public Wi-Fi, at a coffee shop, airport or hotel, is a bigger one, since anyone else on that network with basic tools can potentially see the exact traffic your VPN was supposed to hide. If you regularly connect to public networks, testing for leaks isn’t a one-time setup step, it’s worth a quick recheck any time you’re somewhere you don’t fully trust the network you’re on.

Keep reading: What Is a VPN Kill Switch and Why You Need One and Is It Safe to Use a VPN on Public Wi-Fi? The Real Risks in 2026.