Before you disconnect anything
If the VPN protects work, travel, or a sensitive connection, do not disconnect it merely to run a test. Follow your organization’s policy. For a personal connection where a baseline is safe, record the normal public IPv4 or IPv6 address, approximate ISP, and location before enabling the VPN.
Step-by-step public IP test
- Record the baseline: open the ShowMyIP checker without the VPN and save the Cloudflare-observed address. The regional test is optional for the baseline.
- Connect to the intended exit: wait until the VPN application reports that the tunnel is established.
- Reload the page: confirm that the Cloudflare address differs from the disconnected baseline.
- Run the multi-region check: compare Cloudflare with the twelve AWS regions and five rounds.
- Review protocols: note whether the result is IPv4 or IPv6 and whether the VPN claims to support both.
How to interpret the patterns
| Observed pattern | Possible explanation | Next check |
|---|---|---|
| All sources show one new address | The tested web traffic consistently uses one VPN exit | Compare the ASN and expected exit country |
| Several new addresses owned by one provider | Load balancing or destination-based VPN exits | Repeat and check provider documentation |
| One result matches the disconnected baseline | Split tunneling, protocol escape, extension proxying, or a failed tunnel | Identify which source and protocol differ |
| Location differs but IP is unchanged | Geolocation database disagreement or stale data | Trust the address comparison before the city label |
Split tunneling is not always a leak
Split tunneling deliberately routes selected applications or destinations outside the VPN. This can improve local-device access or performance, but it changes what websites observe. If split tunneling is enabled, verify that the browser is included in the tunnel and that no domain-based exception covers the test endpoints.
Browser VPN extensions may proxy only browser requests, while a system VPN affects broader device traffic. Conversely, some security products intercept only selected web destinations. The product’s intended scope matters when deciding whether a difference is a defect.
IPv6 and DNS require separate tests
A public-IP check shows the source address used for its own web requests. It does not enumerate DNS resolvers and does not inspect every WebRTC path. A VPN can handle browser web traffic correctly while DNS follows a different resolver policy. Use the VPN provider’s supported diagnostic process for DNS and WebRTC, and avoid sites that claim to reveal private information without explaining their method.
If a provider supports only IPv4, it may safely disable IPv6 while connected. If it claims full IPv6 tunneling, an ISP-assigned IPv6 address appearing during the test deserves investigation.
Location is supporting evidence, not the verdict
VPN exits are frequently registered in one place and hosted in another. A city label can be wrong even when the tunnel works. Compare the exact address, ASN, and repeated source observations first. Treat the geolocation as an estimate.
No tool can prove complete anonymity. Logging policy, browser accounts, cookies, fingerprinting, malware, and application behavior are outside the scope of a public-IP comparison.