Connection privacy check

See whether your connection is taking the private route.

This browser-based check looks at the public IP, DNS resolvers, and WebRTC candidates visible from this device. It does not save your results or send them to an advertising or analytics service.

Ready when you are.

Overall result

Ready to check

Run the check to review your connection path.

Public connection

VPN exit IP

Not checked

The address a website sees for this connection.

IP address
LibreGuard match
Not checked

Provider and geographic enrichment are not queried in this version.

Name resolution

DNS leaks

Not checked

Resolvers that answered the privacy probe from your connection.

  • Run the check to inspect DNS resolvers.

A DNS leak can reveal the domains your device looks up outside the VPN route.

Browser path

WebRTC leaks

Not checked

Public browser candidates that may bypass the expected VPN route.

  • Run the check to inspect WebRTC candidates.

Private local addresses are ignored. Modern browsers may hide some candidates by design.

A quick explanation

What does a leak mean?

DNS leaks

DNS turns names such as example.com into addresses. A DNS leak happens when those lookups use a resolver outside the protected VPN path, even though other traffic appears to use the VPN.

WebRTC leaks

WebRTC helps browsers make real-time connections. Depending on the browser and network, its connection candidates can reveal an additional public address that does not match the VPN route.

How to read “inconclusive”

Inconclusive means the browser or an optional privacy-check service did not provide enough evidence. It is not a green result, but it is also not proof that a leak exists.