🩸 ExpressVPN Leak Test

Is ExpressVPN Leaking Your Real IP?

Connect to ExpressVPN, then run the test below. We check IPv4, IPv6, DNS, WebRTC and geolocation consistency - the five channels that can expose you while the app still reports a healthy connection.

πŸ›‘οΈ
Ready to test
Connect to ExpressVPN, then start the test
-
Leak Score
🌐
IPv4 Address Test
Checks if your visible IP matches your VPN - not your real ISP
Pending β–Ό
Run the test to see your IPv4 status.
πŸ”’
IPv6 Leak Test
Many VPNs fail to tunnel IPv6 - exposing your real address
Pending β–Ό
Run the test to check for IPv6 leaks.
πŸ“‘
DNS Leak Test
Checks which DNS servers resolve your queries - ISP servers = exposed
Pending β–Ό
Run the test to check your DNS servers.
πŸŽ₯
WebRTC Leak Test
Browser WebRTC can bypass VPNs and reveal your local/real IP
Pending β–Ό
Run the test to check for WebRTC leaks.
πŸ“
Geolocation Consistency
Checks if IP location, timezone, and browser language are consistent
Pending β–Ό
Run the test to check geolocation consistency.

What This Test Tells You About ExpressVPN

ExpressVPN uses Lightway, its own protocol built on wolfSSL, and runs a DNS resolver on every server it operates. Its kill switch is called Network Lock, which is worth knowing because searching the settings for “kill switch” will not find it.

The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on ExpressVPN as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.

Supported protocols: Lightway, OpenVPN, IKEv2

ExpressVPN Settings That Affect Leak Results

Before concluding anything from a failed row, check these. Most reported leaks turn out to be a setting rather than a defect.

SettingWhere to find itWhat it does
Network Lock Options β†’ General This is the kill switch. It blocks all internet traffic if the VPN drops unexpectedly, and is enabled by default on desktop.
IPv6 leak protection Options β†’ Advanced Prevents IPv6 address detection. Leave it on unless you have a specific reason not to.
Protocol Options β†’ Protocol Lightway is the default and the fastest. Automatic selection can fall back to OpenVPN on restrictive networks.
Split tunneling Options β†’ General Excludes chosen apps from the tunnel by design. Anything excluded here will show your real address - that is the feature working, not a leak.

Setting names and menu locations shift between app versions and platforms. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.

Common ExpressVPN Leak Scenarios

Some apps show the real IP

Check split tunneling first. Applications excluded there deliberately bypass the tunnel, and this is the most common explanation for a “partial leak” on ExpressVPN.

The DNS row shows an unexpected resolver

ExpressVPN runs DNS on every server, so an outside resolver points to a system-level override or browser-level DNS-over-HTTPS. Check your browser’s secure DNS setting before concluding the VPN is at fault.

Network Lock did not trigger

Network Lock covers unexpected drops, not a manual disconnect in some configurations. Test it by dropping the network rather than clicking disconnect, and confirm the result with our kill switch test.

How to Read Your Results

Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with ExpressVPN disconnected, once connected. Any value identical across both runs is travelling outside the tunnel.

  • IPv4: the ISP and organisation fields should name ExpressVPN or its hosting partners, not your home ISP.
  • DNS: resolvers should belong to ExpressVPN or to a filtering service it operates. Your ISP’s name here means your browsing history is going to your ISP regardless of the tunnel.
  • WebRTC: a 192.168.x.x or 10.x.x.x address is your local network and harmless. A public address differing from your exit IP is a real leak.
  • IPv6: either nothing at all, or an address belonging to ExpressVPN. Anything else escaped the tunnel.
  • Geolocation: your browser timezone should match the exit country. A mismatch does not expose your IP, but it marks the session as VPN traffic to streaming services and fraud systems.

Why a Connected VPN Can Still Leak

The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.

This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.

Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.

ExpressVPN Leak Test - FAQ

Provider-specific questions about ExpressVPN, its settings, and what a failed check actually means.

What is ExpressVPN Network Lock?

Network Lock is ExpressVPN’s kill switch. When the VPN connection drops unexpectedly, it blocks all internet traffic until the tunnel is restored or you disable it, which prevents your real IP from being exposed during a reconnection. It is on by default in the desktop apps and lives under Options β†’ General rather than under anything labelled “kill switch”.

Does ExpressVPN leak DNS?

ExpressVPN operates its own DNS resolver on every server, so a healthy connection shows ExpressVPN resolvers. Leaks that do appear usually originate outside the app - a system-level DNS override, or browser-level DNS-over-HTTPS bypassing the tunnel’s settings. The test above shows exactly which resolvers answered your queries.

Is Lightway as secure as OpenVPN?

Lightway is built on the wolfSSL cryptographic library, which is FIPS 140-2 validated, and its source has been published and independently audited. It is dramatically smaller than OpenVPN - a few thousand lines against hundreds of thousands - which reduces the surface for implementation bugs. In practical terms the two are equivalent in security and Lightway is faster.

Why does one app show my real IP on ExpressVPN?

Almost always split tunneling. ExpressVPN lets you exclude specific applications from the tunnel, and excluded apps use your real connection by design. Check Options β†’ General to see which apps are on that list. If nothing is excluded and an app still shows your real address, run the full test above to identify which channel is leaking.

How do I test ExpressVPN for leaks?

Connect to ExpressVPN as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any value that stays the same across both runs never entered the tunnel.

Do you store my ExpressVPN test results?

Not unless you ask us to. Every check runs in your browser, and by default the results exist only in the page in front of you - closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, the provider and your exit country - never your IP address.

Is this page affiliated with ExpressVPN?

No. VPNMeter is independent and this page is not endorsed by or connected to ExpressVPN. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.