Browser connection privacy

WebRTC Leak Test

See which network addresses your browser shares with a WebRTC peer.

The test runs in this browser and uses a public STUN server.

This checks WebRTC address exposure only, not DNS leaks. Privacy details

What this browser test checks

WebRTC is a set of browser features used for audio, video, and direct data connections. To establish a peer-to-peer path, a browser gathers ICE candidates: possible network routes that can reach another participant. This test creates a local data channel and asks a public STUN server for connectivity information. It displays candidates the browser exposes and compares public server-reflexive (srflx) candidates with the public IP that this site sees for your HTTP request.

A host candidate may show a private local address, or a browser may replace it with an mDNS name ending in .local. That name is designed to avoid exposing the local address to a remote website; it is not a public IP leak. A server-reflexive candidate shows the public-facing address learned through STUN. Relay candidates represent a TURN relay, if available. Browser versions and privacy settings differ, and some browsers hide or limit candidate details.

When a VPN leak is reported

The page reports a VPN leak only when you tick the box saying a VPN is connected and the browser exposes a public srflx address different from the address seen by this site. If the VPN box is not checked, a public candidate is expected to match the ordinary internet route and is simply reported. A mismatch can indicate WebRTC used a different network path, but it may also come from multiple network interfaces, IPv4/IPv6 routing, proxy setup, or a changing address. Repeat the check while the VPN is connected and compare both addresses with the VPN provider's own guidance.

This is a browser-side WebRTC check, not a DNS leak test, anonymity score, or guarantee that every site sees the same network identity. The STUN server receives standard connection information to answer the ICE request. The public IP comparison uses this site's existing same-origin address endpoint. No candidate list is uploaded or stored by the page.

What to do if you see an unexpected address

First confirm the VPN is connected and that the visible public address changes when the VPN is turned on. Update the browser, then review its WebRTC or IP handling settings. Chromium-based browsers and Firefox may offer privacy controls or reputable extensions that limit non-proxied UDP/WebRTC traffic, though this can affect calls and conferencing. Prefer your VPN provider's documented browser or system-level leak protection over installing several overlapping extensions. Re-run the test after each change, and test the services you actually use. Our VPN check guide explains other useful checks, and VPN and proxy differences explains why routes may differ.

Frequently asked questions

Are mDNS .local candidates leaks?

No. They are local names used instead of exposing the device's private address to a remote peer.

Why does the result say no public candidates?

The browser, network, or privacy controls may hide candidates, STUN may be blocked, or the check may have timed out. It does not prove that every WebRTC path is protected.

Does this check DNS leaks?

No. It checks WebRTC ICE candidates only. DNS queries are outside this test.

Does this page send candidates to the site?

No. Candidate gathering and comparison run in your browser. The site supplies only the HTTP public-IP value; the selected STUN server sees its own ICE request.