Learn

IPv6 leaks — when modern addressing bypasses your VPN

See whether IPv6 traffic escapes a VPN tunnel built only for IPv4.

What it detects

Many VPNs were built for IPv4 and either ignore or poorly handle IPv6. If your network offers IPv6 and the VPN does not tunnel it, requests can travel over IPv6 straight to their destination — outside the tunnel, carrying your real IPv6 address.

This check has your browser attempt an IPv6 connection and observes whether it succeeds outside the expected path, indicating IPv6 is reaching the internet independently of the VPN.

Why it matters

An IPv6 leak reveals a real, routable address tied to your connection even while your IPv4 traffic is safely tunnelled — a partial but real de-anonymisation that is easy to miss because everything otherwise “looks” fine.

As IPv6 deployment grows, this leak becomes more common, not less.

How to read your result

A “leak” means IPv6 connectivity exists outside the tunnel; the safe fixes are a VPN that tunnels or blocks IPv6, or disabling IPv6 for the connection.

“No leak” means either your VPN handles IPv6 or your network has no IPv6 path to leak.

Frequently asked questions

Should I just disable IPv6?
Disabling IPv6 removes the leak but also its benefits. A better fix is a VPN that fully tunnels IPv6; disable it only if your VPN cannot.
Why does a VPN leak IPv6 but not IPv4?
Because the tunnel was configured for IPv4 routes only. IPv6 uses a separate routing table the VPN may not capture, so IPv6 packets take the normal path.
Is an IPv6 leak as serious as WebRTC?
Both can expose a real address. IPv6 leaks depend on your network offering IPv6, while WebRTC leaks work almost anywhere — treat any exposed address as significant.

Run the one-click checkup