T-03 · server

IPv6 Leak Test

Many VPNs only tunnel IPv4. If your device also has working IPv6, traffic can reach sites over that address — outside the tunnel. This test asks for your IPv4 and IPv6 addresses on separate paths and compares the networks behind them.

TEST T-03 · compares your IPv4 and IPv6 paths
Ready to test

What an IPv6 leak is

Your device can speak two internet protocols at once: the older IPv4 and the newer IPv6. A lot of VPN software was built for IPv4 and only routes that traffic through the tunnel. If your ISP also gives you IPv6, requests can quietly go out over the IPv6 address — outside the VPN — exposing an address the tunnel was meant to hide.

This test fetches your address over an IPv4 path and an IPv6 path separately, then compares the networks (ASN) behind them. A red result means IPv6 exits through a different network than IPv4 — the usual IPv4-only VPN leak. A green result means there was no extra IPv6 path, or both families leave through the same network. It does not prove every app on your device behaves the same way.

Who this matters for

  • VPN users on IPv6-enabled ISPs, where the VPN only tunnels IPv4.
  • Anyone whose VPN app lacks an IPv6 kill switch or IPv6 leak protection.

How to fix an IPv6 leak

  • Use a VPN that tunnels or blocks IPv6. The cleanest fix — the app handles both protocols so nothing slips out.
  • Disable IPv6 at the OS level if your VPN can't handle it. Effective but heavy-handed, and it can break IPv6-only networks.

Common questions

I got IPv4 — am I safe from all leaks?

This check only covers IPv6. Your DNS or WebRTC could still expose you separately. Run the other tests in the suite for the full picture.

Why was the test inconclusive?

The server-side check couldn't be reached or the deployment isn't configured for it. That's not a verdict either way — we only report what we could actually measure.

Related checks

IPv6 is one path out. These cover the others: