Privacy troubleshooting

How to check a VPN for IP leaks

A useful VPN test compares a known disconnected baseline with several destinations after the tunnel connects. One unfamiliar address is not enough context.

Published and reviewed by ShowMyIP on September 19, 2026

Before you disconnect anything

If the VPN protects work, travel, or a sensitive connection, do not disconnect it merely to run a test. Follow your organization’s policy. For a personal connection where a baseline is safe, record the normal public IPv4 or IPv6 address, approximate ISP, and location before enabling the VPN.

Step-by-step public IP test

  1. Record the baseline: open the ShowMyIP checker without the VPN and save the Cloudflare-observed address. The regional test is optional for the baseline.
  2. Connect to the intended exit: wait until the VPN application reports that the tunnel is established.
  3. Reload the page: confirm that the Cloudflare address differs from the disconnected baseline.
  4. Run the multi-region check: compare Cloudflare with the twelve AWS regions and five rounds.
  5. Review protocols: note whether the result is IPv4 or IPv6 and whether the VPN claims to support both.

How to interpret the patterns

Observed patternPossible explanationNext check
All sources show one new addressThe tested web traffic consistently uses one VPN exitCompare the ASN and expected exit country
Several new addresses owned by one providerLoad balancing or destination-based VPN exitsRepeat and check provider documentation
One result matches the disconnected baselineSplit tunneling, protocol escape, extension proxying, or a failed tunnelIdentify which source and protocol differ
Location differs but IP is unchangedGeolocation database disagreement or stale dataTrust the address comparison before the city label

Split tunneling is not always a leak

Split tunneling deliberately routes selected applications or destinations outside the VPN. This can improve local-device access or performance, but it changes what websites observe. If split tunneling is enabled, verify that the browser is included in the tunnel and that no domain-based exception covers the test endpoints.

Browser VPN extensions may proxy only browser requests, while a system VPN affects broader device traffic. Conversely, some security products intercept only selected web destinations. The product’s intended scope matters when deciding whether a difference is a defect.

IPv6 and DNS require separate tests

A public-IP check shows the source address used for its own web requests. It does not enumerate DNS resolvers and does not inspect every WebRTC path. A VPN can handle browser web traffic correctly while DNS follows a different resolver policy. Use the VPN provider’s supported diagnostic process for DNS and WebRTC, and avoid sites that claim to reveal private information without explaining their method.

If a provider supports only IPv4, it may safely disable IPv6 while connected. If it claims full IPv6 tunneling, an ISP-assigned IPv6 address appearing during the test deserves investigation.

Location is supporting evidence, not the verdict

VPN exits are frequently registered in one place and hosted in another. A city label can be wrong even when the tunnel works. Compare the exact address, ASN, and repeated source observations first. Treat the geolocation as an estimate.

No tool can prove complete anonymity. Logging policy, browser accounts, cookies, fingerprinting, malware, and application behavior are outside the scope of a public-IP comparison.

Why VPN locations can look wrongUnderstand IPv6 tunnel behavior