How to Check If Your VPN Is Working: 5 Quick Leak Tests

How to Check If Your VPN Is Working: 5 Quick Leak Tests
Key takeaways
  • A "Connected" icon doesn't prove your VPN is protecting you.
  • Five free tests check your IP, DNS, IPv6, WebRTC and what happens when the connection drops.
  • DNS and IPv6 leaks are the most common and the easiest to miss.
  • The whole check takes about five minutes per device.

A "Connected" icon only tells you the app thinks it's connected. It doesn't tell you whether your traffic, your DNS lookups, or your IPv6 connection are actually going through the VPN. When one of them slips out, that's called a VPN leak, and it can expose your real IP address or the sites you visit without any warning.

The good news: checking takes about five minutes, costs nothing, and works on any VPN. Here are the five tests worth running, what a good result looks like, and how to fix anything that fails.

Before you start: write down your real IP

Turn your VPN off and visit ipinfo.io or whatismyipaddress.com. Note the IP address and the internet provider shown. That's what you're trying to hide, so you'll compare every test against it.

Now turn your VPN on and run the tests below.

Test 1: Check your IP address

Visit the same IP lookup site again with the VPN connected.

Good result: a different IP address, with the provider and location of your VPN server instead of your home internet provider.

Problem: your real IP or your own internet provider still shows up. The VPN isn't routing your traffic.

How to fix it: disconnect and reconnect, make sure only one VPN app is active, and check that your config routes all traffic. In a WireGuard config that's the line AllowedIPs = 0.0.0.0/0, ::/0.

Why is the city slightly off? IP location databases are estimates. A server in one city can show up as a nearby city, or the city where the hosting company registered its addresses. The country and provider matter more than the exact city.

Test 2: Run a DNS leak test

Every time you open a website, your device first looks up its address through a DNS server. If those lookups skip the VPN and go to your internet provider, your provider can still see every site you visit, even while your browsing traffic is encrypted.

Go to dnsleaktest.com and run the Extended test, or use browserleaks.com/dns.

Good result: every DNS server listed belongs to your VPN, not to your internet provider.

Problem: you see your home internet provider's name in the list.

How to fix it:

  • Make sure your VPN config sets a DNS server (in WireGuard, the DNS = line).
  • If you set a custom DNS on your router, it can override the VPN on some devices.
  • Check your browser. If you've set a custom "Secure DNS" or "DNS over HTTPS" provider in Chrome, Edge or Firefox, the browser sends lookups to that provider instead of your VPN's DNS. It isn't a leak to your internet provider, but it bypasses any ad and tracker blocking your VPN does.
  • On Android, check Settings > Network > Private DNS. If it's set to a specific provider hostname, switch it to Off or Automatic while using a VPN.

How NorexVPN handles DNS: your dedicated server runs its own private DNS resolver. Your lookups never go to your internet provider or to a third-party DNS company, and the resolver doesn't record your queries. In a DNS leak test, the result should show your own server's address.

Test 3: Check for an IPv6 leak

This is the leak most people have never heard of, and one of the most common. Many networks now give your device both an IPv4 and an IPv6 address. Some VPNs only protect IPv4, so any site that supports IPv6 (Google, YouTube, Facebook and many others) can be reached outside the tunnel, straight from your real connection.

Visit test-ipv6.com with the VPN connected.

Good result: either the IPv6 address shown belongs to your VPN, or no IPv6 address is detected at all.

Problem: an IPv6 address from your home internet provider appears.

How to fix it: your VPN needs to route IPv6 through the tunnel too. In WireGuard, that's the ::/0 part of AllowedIPs. If your VPN doesn't support IPv6 at all, switching IPv6 off on your device is a workable stopgap.

How NorexVPN handles IPv6: every NorexVPN config routes both IPv4 and IPv6 through your server, so IPv6 traffic goes through the tunnel instead of leaking.

Test 4: Check for a WebRTC leak

WebRTC powers video calls and voice chat in your browser. To set up those connections, the browser can reveal your IP addresses to websites through JavaScript, and on some setups that has exposed a user's real IP even with a VPN on.

Visit browserleaks.com/webrtc.

Good result: any public IP address shown is your VPN's. Private addresses such as 192.168.x.x or 10.x.x.x are normal. They're local network addresses and don't identify you on the internet.

Problem: your real public IP from the first step appears.

How to fix it: a full-tunnel VPN (one that routes all traffic, like the WireGuard setting above) usually solves this on its own. If it doesn't, turn off WebRTC IP sharing in your browser, or use a browser extension that limits WebRTC.

Test 5: Test what happens when the connection drops

A VPN that works perfectly while connected can still leak for a few seconds when your Wi-Fi drops, when you switch networks, or when your phone wakes up. The fix is making sure nothing gets out unless the VPN is up. This is often called a kill switch.

Here's where to find it in the official WireGuard apps:

DeviceSetting
AndroidSettings > Network > VPN > gear icon next to WireGuard > turn on Always-on VPN and Block connections without VPN
iPhone / iPadIn the WireGuard app, edit the tunnel and turn on On-Demand for Wi-Fi and cellular
WindowsIn the WireGuard app, edit the tunnel and tick Block untunneled traffic (kill-switch)
MacIn the WireGuard app, edit the tunnel and turn on On-Demand

To test it: with the VPN on, switch Wi-Fi off and back on, then immediately reload an IP lookup site. You should only ever see your VPN's address.

Bonus: check your ad and tracker blocking

If your VPN blocks ads and trackers, test it with a blocking test page such as d3ward's ad block test. With the VPN on, it should block a large share of the test domains. Browser extensions only protect one browser. DNS-level blocking protects every app on the device, including games, apps and smart TVs.

How NorexVPN handles this: ad, tracker, malware and phishing blocking runs on your server itself, so it covers every app on every connected device. If the test shows nothing blocked, check the browser and Private DNS settings from Test 2, since those can route lookups around it.

Quick reference

TestFree toolGood result
IP addressipinfo.ioVPN server's IP and provider
DNS leakdnsleaktest.com (Extended)Only your VPN's DNS servers
IPv6 leaktest-ipv6.comVPN's IPv6, or none
WebRTC leakbrowserleaks.com/webrtcNo real public IP shown
Connection dropToggle Wi-Fi, recheck IPNever your real IP

Run these after installing a new VPN, after a big system update, and any time something feels off. It takes five minutes and removes the guesswork.

Frequently asked questions

Can my internet provider tell I'm using a VPN?

Yes. Your provider can see that you're connected to a VPN server and how much data you use. What it can't see is the sites you visit or what you do on them, because that traffic is encrypted inside the tunnel.

Does a VPN make me completely untraceable?

No, and any VPN that promises that is overselling. A VPN hides your traffic from your local network and your internet provider, and gives websites a different IP address. Websites can still recognize you through the accounts you log into, cookies, and browser fingerprinting. A VPN is one strong layer of privacy, not an invisibility cloak.

Why does my VPN show a different city than the server I picked?

IP location databases are approximations and update on their own schedules. A server can appear in a nearby city, or in the city where the hosting provider registered its address block. The country and network are the parts that matter for privacy.

Do I need to run these tests on every device?

Ideally, yes. Each device has its own settings: Private DNS on Android, browser DNS options, kill switch settings. A leak on one device doesn't mean every device leaks, and a clean result on your laptop doesn't cover your phone.

What's the most common leak?

DNS and IPv6 leaks are the ones people most often miss, because browsing still works normally while they happen. That's why they're worth checking even when everything looks fine.

A VPN that passes by design

NorexVPN gives you your own dedicated WireGuard server instead of a shared one. That server runs your private DNS resolver, routes both IPv4 and IPv6 through the tunnel, and blocks ads, trackers and malware for every device you connect. It doesn't record the sites you visit, the addresses you connect to, or your DNS queries.

See it pass every test yourself

NorexVPN gives you your own dedicated WireGuard server with private DNS, IPv6 protection and built-in ad blocking. Try it free for 7 days. A card is required, and you won't be charged if you cancel before the trial ends.

Start your 7-day free trial

Keep reading

Ready for a VPN that's actually yours?
Clean IP, no activity logs, WireGuard-powered. Up and running in minutes.
Try free for 7 days