🩸 Cloudflare WARP Leak Test

Is Cloudflare WARP Leaking Your Real IP?

First, the quick question: does your traffic leave through Cloudflare WARP’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.

Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.

🛡️
Ready to test
Connect to Cloudflare WARP, then start the test
-
Leak Score
🌐
IPv4 Address Test
Checks if your visible IP matches your VPN - not your real ISP
Pending ▼
Run the test to see your IPv4 status.
🔢
IPv6 Leak Test
A VPN that carries only IPv4 can leave IPv6 going around the tunnel
Pending ▼
Run the test to check for IPv6 leaks.
📡
DNS Leak Test
Checks which resolvers answer your lookups - outside your VPN exit's network = leak
Pending ▼
Run the test to check your DNS servers.
🎥
WebRTC Leak Test
Browser WebRTC can bypass VPNs and reveal your local/real IP
Pending ▼
Run the test to check for WebRTC leaks.
📍
Geolocation Consistency
Checks if your browser timezone fits the continent of your exit IP
Pending ▼
Run the test to check geolocation consistency.

What This Test Tells You About Cloudflare WARP

Cloudflare WARP is the tunnel in Cloudflare’s 1.1.1.1 app, and the app’s mode decides what this test sees: in DNS only mode, formerly called “1.1.1.1”, it encrypts your lookups to Cloudflare’s resolver and does not tunnel your traffic, so sites still see your own address. Cloudflare says WARP does not provide anonymity, does not let you appear to be in another country, and does not proxy WebRTC. Cloudflare, Inc. is based in San Francisco.

The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on Cloudflare WARP as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.

Supported protocols: MASQUE (default), WireGuard

Cloudflare WARP Settings That Affect Leak Results

Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.

SettingWhere to find itWhat it does
WARP mode Cog icon (desktop), menu (mobile) “Traffic and DNS”, formerly 1.1.1.1 with WARP, tunnels everything and is the default. “DNS only” encrypts lookups and leaves your address unchanged. “Traffic only” tunnels traffic but leaves DNS to your operating system, whose resolver this test then reports.
DNS Protocol Cog icon → Preferences → Connection In WARP mode, “WARP” sends DNS through the tunnel; “HTTPS” and “TLS” send it outside the tunnel, encrypted, to Cloudflare’s 1.1.1.1 resolver.
1.1.1.1 for Families Preferences → Connection (desktop), Advanced → Connection options (mobile) Blocks malware, or malware and adult content, at the resolver. It is still Cloudflare’s resolver, on the 1.1.1.2 and 1.1.1.3 addresses.
Local proxy Preferences → Advanced → Configure Proxy (desktop) Sends only the applications you point at the proxy through WARP; everything else uses your regular connection. A browser that is not set to use it shows your own address in this test.
Disable for Wi-Fi / wired networks Preferences → Connection WARP does not run on the Wi-Fi or wired networks ticked here, so a test run on one of them shows your own connection.

Settings as described in Cloudflare WARP’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.

Common Cloudflare WARP Leak Scenarios

The IPv4 row shows your own ISP

Check the mode first: in DNS only mode WARP does not tunnel traffic, so your own address is the correct result. Then check whether the current network is ticked under Disable for Wi-Fi / wired networks. Cloudflare’s documentation checks a connection at cloudflare.com/cdn-cgi/trace, which should read warp=on.

A video call or game sees your real address

Cloudflare lists this as a known issue: WARP does not proxy WebRTC traffic, and apps or sites with access to your camera or microphone bypass WARP and can see your IP. This test does not ask for either permission, so a clean WebRTC row here does not cover a video call.

The DNS row shows a resolver outside Cloudflare

Check for Traffic only mode, which leaves DNS to your operating system, and for a secure DNS setting in your browser that uses another provider. In the other modes, Cloudflare documents DNS as going to its own 1.1.1.1 resolver.

How to Read Your Results

Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with Cloudflare WARP disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.

  • IPv4: the ISP and organisation fields should name Cloudflare WARP or its hosting partners, not your home ISP.
  • DNS: resolvers should sit in the same network as your Cloudflare WARP exit. Your ISP’s name, or a public resolver such as 1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak.
  • WebRTC: a 192.168.x.x or 10.x.x.x address is your local network and harmless. A public address differing from your exit IP is a real leak.
  • IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through Cloudflare WARP escaped the tunnel.
  • Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.

Why a Connected VPN Can Still Leak

The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.

This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.

Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.

🧰 Test Cloudflare WARP Further

The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.

📡
DNS Leak Test
See which DNS resolvers actually answer your queries
🔢
IPv6 Leak Test
Detect IPv6 traffic escaping your VPN tunnel
🎥
WebRTC Leak Test
Check if WebRTC exposes your real IP to any website
🔌
Kill Switch Test
Verify your VPN blocks traffic the moment it drops

Cloudflare WARP Leak Test - FAQ

Provider-specific questions about Cloudflare WARP, its settings, and what a failed check actually means.

Does Cloudflare WARP hide my IP address?

From the sites you visit, in WARP mode: Cloudflare says WARP replaces your IP address with a Cloudflare one. Cloudflare also says WARP does not provide anonymity, is not designed to stop the servers you talk to from identifying you, and does not let you appear to browse from another country - the replacement address is chosen to represent your approximate location. A Cloudflare address in or near your own region is WARP working as designed, not a fault.

What is the difference between WARP and 1.1.1.1 (DNS only) mode?

WARP mode, now labelled Traffic and DNS, tunnels all your traffic, DNS included, to Cloudflare. DNS only, formerly called 1.1.1.1, only encrypts your DNS lookups to Cloudflare’s resolver and does not tunnel anything else, so websites still see your own IP address. On this page that shows as your ISP in the IPv4 row, and the DNS row reports Cloudflare’s resolver as a leak, because it counts any resolver outside your exit’s network - here, your own ISP’s - as one. Both readings are correct for a mode that does not hide your address.

Does WARP have a kill switch?

Cloudflare’s documentation for the consumer 1.1.1.1 app does not describe one. On Windows and macOS it describes the tunnel as the job of a background service, separate from the app you interact with, so force-quitting the app, as our kill switch test asks, is not the same as stopping the tunnel. If your address stays the same through the force-quit, the test saw no drop to judge, rather than a kill switch holding.

Does WARP protect against WebRTC leaks?

Cloudflare says it does not: WARP does not proxy WebRTC traffic, and apps or sites with access to your camera or microphone, such as video calls and online games, bypass WARP and can see your IP address. The WebRTC row of this test does not ask for camera or microphone access, so it does not reproduce that case; a site you have given those permissions is the one to be careful with.

How do I test Cloudflare WARP for leaks?

Connect to Cloudflare WARP as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.

Do you store my Cloudflare WARP test results?

Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.

Is this page affiliated with Cloudflare WARP?

No. VPNMeter is independent and this page is not endorsed by or connected to Cloudflare WARP. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.