WebRTC leak test

A VPN changes the address websites see. Your browser can still let another one slip out through WebRTC, the feature behind in-browser calls. This test puts the two side by side.

01 · What our server sees

216.73.217.0

Amazon.com, Inc. · AS16509

The address your traffic leaves from. With a VPN connected, it should be the VPN's.

02 · What WebRTC gives away

Collecting addresses…

The comparison uses public addresses only and runs in your browser. To learn its own public address, the browser queries two STUN servers, one operated by Google and one by Cloudflare, and they see your address the same way any website does. Public addresses that turn up are sent to our server for a single purpose: naming the network they belong to. Local addresses stay on your device and we store nothing.

Why a browser can know more than one address

Loading a web page is a simple exchange. Your browser asks, a server answers, and the server learns one thing about your network, which is the address the request came from. A video call works differently. Two browsers try to send audio and video straight to each other, and for that each one has to tell the other where it can be reached.

WebRTC is the browser feature that takes care of this. Before a call, it collects every address that might work, a step called ICE gathering. It lists the addresses of the network interfaces on your device, then asks a public helper called a STUN server one question: “what address do you see me coming from?” Each answer becomes a “candidate”.

Any web page can start this gathering with a few lines of JavaScript. It doesn’t need a call or a permission prompt, and nothing shows on screen. If the STUN question travels outside your VPN tunnel, or over an interface the VPN doesn’t cover, the candidate list contains the address your provider gave you. That’s what a WebRTC leak is.

What the test does

  1. When the page loads, our server notes the address your request came from and names the network that owns it. That’s box 01.
  2. Your browser opens a WebRTC connection that goes nowhere, pointed at two STUN servers, one run by Google and one by Cloudflare, and collects candidates for up to seven seconds.
  3. The candidates get sorted. Private ranges (10.x, 172.16 to 172.31, 192.168.x), carrier-shared addresses (100.64 to 100.127), link-local addresses and .local names are set aside as local. The rest are public.
  4. Up to six public addresses go to our server, which sends back the network each one belongs to.
  5. Each public address is compared with box 01 and gets a label.

Reading the labels

LabelRuleMeaning
SameIdentical to the address our server sawWebRTC adds nothing. With a VPN on, both are the VPN’s address.
DifferentSame family (both IPv4 or both IPv6) but another addressWith a VPN on, this is very likely your real address getting out.
Same providerOther family, same network operator as box 01Typically the IPv6 side of the same connection or the same VPN. No leak.
Other providerOther family, different network operatorUsually an IPv6 address from your internet provider while the VPN only tunnels IPv4.
To checkOther family, operator couldn’t be identifiedCompare it yourself with the address you have when the VPN is off.

Under the list, the page says whether local addresses are visible. Current browsers replace them with a random name ending in .local, which tells a website nothing. A plain 192.168.x.x address doesn’t lead back to you either, but it’s one more detail a tracker can use to tell devices apart.

“No public address” and “WebRTC is turned off” both mean this door is shut. Either the browser refused to gather candidates or no STUN answer came back.

The test has no way of knowing whether you use a VPN. Without one, two different public addresses can be perfectly normal, on a line with both IPv4 and IPv6 for example, and websites see your real address anyway. A red result is only a problem when a VPN or proxy is supposed to be hiding you. The test also covers WebRTC and nothing else. DNS leaks are a separate matter.

Closing the leak

In the VPN application
Look for “WebRTC leak protection”, “IPv6 leak protection” and “kill switch”, and turn on all three. If the provider doesn’t support IPv6, disable IPv6 on the network adapter while you’re connected. A VPN that only exists as a browser extension protects page traffic and may leave WebRTC alone, so go for the full application.
Firefox
Open about:config and set media.peerconnection.ice.default_address_only to true. WebRTC then sticks to the default route, which is the tunnel. Setting media.peerconnection.enabled to false removes WebRTC entirely.
Chrome and Edge
There’s no built-in switch. Google publishes an extension, WebRTC Network Limiter, with the option “Use my default public interface only”. The uBlock Origin extension has a similar setting, “Prevent WebRTC from leaking local IP addresses”.
Brave
Settings, Privacy and security, “WebRTC IP handling policy”: choose “Disable non-proxied UDP”.

After each change, reload this page with the VPN connected. You’re aiming for every public line marked “Same” or “Same provider”, or no public address at all.

Questions people ask

What is a WebRTC leak?

It’s when a web page gets hold of your real IP address through the browser’s WebRTC feature, even though a VPN or proxy hides it from normal page requests. A short script is all the page needs. No camera or microphone permission is involved.

I do not use a VPN. Does this test matter to me?

Hardly. Without a VPN, every site already gets your real address with each request, so WebRTC gives away nothing extra. The test is for people who count on a VPN or proxy to hide their location.

Will disabling WebRTC break anything?

Turning it off completely stops calls and screen sharing in the browser, which means Google Meet, Microsoft Teams on the web, Discord, Jitsi and the like. Restricting WebRTC to the default route, or using the VPN’s own protection, keeps calls working.

Why does the test show an IPv6 address when my VPN is on?

Many VPNs only tunnel IPv4. If your internet provider gives you IPv6 as well, traffic to IPv6 destinations can go around the tunnel. Turn on IPv6 leak protection in the VPN, or switch IPv6 off on the device.

Is a .local address or a 192.168 address a leak?

No. Those identify your device on your own network and can’t be reached or located from outside. The only thing that counts as a leak is a public address different from the one your VPN presents.