WebRTC
We open a real peer connection through STUN and watch which addresses the browser is willing to hand over.
running
Eight checks straight in the browser: WebRTC, DNS, IPv6, time zone, fingerprint. A score from 1 to 10 in five seconds.
Your address
Critical
You are visible almost entirely
Every check runs in your browser and on our server, with no plugin and no stored result. A browser cannot see the traffic of other apps, so this measures the web stack, not the whole system.
Checking
A leak rarely hits at once. The data is filed into databases, cross-matched, and sold onward.
Your address, city, provider and browser fingerprint get glued to already leaked records and sold as a package.
Passwords from old breaches are replayed in bulk. A matching device and city helps get past the login check.
Browsing history becomes leverage. The pressure usually lands on people who have something to lose.
Knowing your provider, city and device, someone calls posing as your bank or support. The details are what make it convincing.
An account with real history is worth more than an empty one. It gets used to deceive the people who trust you.
Most of these databases settle in closed sections of shadow forums that an ordinary person cannot reach. Data cannot be taken back from there, which makes not leaking it the cheaper option.
Eight checks
Nothing here needs an install. Everything below runs in five seconds on this very tab.
We open a real peer connection through STUN and watch which addresses the browser is willing to hand over.
running
We request an address over IPv6 separately and compare its autonomous system with the IPv4 one.
running
We draw canvas twice and compare the hashes. If they match, you are recognisable without an IP.
running
We hit ten random subdomains and collect the resolvers that went out to the network for you.
running
We compare the browser time zone with the offset for your IP. A mismatch gives away the real country.
running
We resolve the autonomous system and check whether the address reads as a datacenter or a home line.
running
A leak does not look like an error. The site simply receives a second address, and that one is real.
Every DNS query goes to the provider. Your browsing history assembles itself, without a single leak.
The site gets an address in Amsterdam, a time zone in Moscow and DNS from your home ISP. That combination is useless.
Address, DNS, IPv6 and clock all say the same thing. That is when a tunnel actually works.
Open it on any device, the test only uses what the browser already ships with.
If your score is under eight
Leaks are not fixed by browser settings. They are fixed by a tunnel that owns DNS, IPv6 and WebRTC itself. We built one.
No. The address is used to compute the score inside that one request. We do not write it to a database or pass it on. Geo enrichment goes through an external lookup, and only the address is sent.
Some checks depend on the network: the DNS probe may not arrive, IPv6 may come up late. Those items are marked as no data and drop out of the calculation, which shifts the weight of the rest slightly.
No. A ten means we found no leaks in the browser web stack. Payment details, accounts, behaviour and the traffic of other apps are all outside what a browser can measure.
Not for anonymity, yes for access. Datacenter ranges are easy to identify, so banks and streaming services tend to add verification or block the login.
The test always measures the device and browser it is open in. To check another device, open vpnsafety.io on that device.