Is Hotspot Shield Leaking Your Real IP?
First, the quick question: does your traffic leave through Hotspot Shield’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.
Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.
What This Test Tells You About Hotspot Shield
Hotspot Shield, a Pango Group brand, selects a protocol automatically by default and has its own, Hydra, which older help pages call Catapult Hydra. It says DNS requests go encrypted to its own DNS servers, and a help article adds that they do not travel through the VPN tunnel - which matters here, because this test judges a resolver by its network, not by whether the lookup was encrypted.
The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on Hotspot Shield as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.
Supported protocols: Hydra (proprietary), WireGuard, IKEv2/IPSec
Hotspot Shield Settings That Affect Leak Results
Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.
| Setting | Where to find it | What it does |
|---|---|---|
| Kill switch | Settings → Advanced (Windows), Settings (Android, iOS) | Stops internet traffic when the VPN disconnects unexpectedly; Android calls it Internet Killswitch. Hotspot Shield’s settings guide lists it for Windows, Android and iOS, and lists Always-on VPN, which reconnects, for Mac. |
| Split Tunneling (Smart VPN) | Settings → Split Tunneling (Windows), Settings (Android) | Two modes. Bypass VPN sends the apps and sites you list around the tunnel; Route via VPN sends only what you list through it. With Route via VPN on, check whether this site is on the list before reading a result. |
| Prevent IP leak | Settings → Advanced (Windows) | Hotspot Shield says it stops sites, cache or cookies from exposing your IP while connected. The WebRTC and IPv6 rows above show what it covers on your setup. |
| VPN protocol | Settings → VPN protocol | Automatic (Smart on Android) chooses for you. Hydra is Hotspot Shield’s own TLS-based protocol; WireGuard and IKEv2 are also offered, IKEv2 not on Android. |
| Always-on VPN | Settings (Android, iOS, Mac) | Reconnects the VPN automatically if the connection fails; on iOS it cannot be turned off. It is listed separately from the kill switch, which is the setting described as stopping traffic. |
Settings as described in Hotspot Shield’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.
Common Hotspot Shield Leak Scenarios
The DNS row reports a leak
Hotspot Shield says its DNS requests are encrypted but do not travel through the VPN tunnel, and that leak-test sites flagging this are wrong. This test reports a resolver outside your exit’s network as a leak whether or not the lookup was encrypted. Expand the row to see whose network the resolver is on.
Some sites see your real IP
Check Split Tunneling. In Bypass VPN mode the apps and sites on the list skip the tunnel; in Route via VPN mode only what is on the list goes through the VPN.
Chrome shows a Hotspot Shield address but other apps do not
That is the Chrome extension rather than the app. Hotspot Shield describes it as a proxy connection set up in the browser; the desktop app is what covers the rest of the device.
How to Read Your Results
Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with Hotspot Shield disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.
- IPv4: the ISP and organisation fields should name Hotspot Shield or its hosting partners, not your home ISP.
- DNS: resolvers should sit in the same network as your Hotspot Shield exit. Your ISP’s name, or a public resolver such as
1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak. - WebRTC: a
192.168.x.xor10.x.x.xaddress is your local network and harmless. A public address differing from your exit IP is a real leak. - IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through Hotspot Shield escaped the tunnel.
- Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.
Why a Connected VPN Can Still Leak
The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.
This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.
Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.
🧰 Test Hotspot Shield Further
The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.
📚 Read next
The longer version: what this test is looking for, and what to do with the answer.
Hotspot Shield Leak Test - FAQ
Provider-specific questions about Hotspot Shield, its settings, and what a failed check actually means.
Does Hotspot Shield leak DNS?
Hotspot Shield says no: its DNS requests go encrypted to its own DNS servers, and a help article explains that leak-test sites report a leak because the requests do not travel through the VPN tunnel. This test draws the line by network, not encryption: if the resolver that answers sits outside the network of your Hotspot Shield exit, the DNS row reports a leak, because that resolver and not the exit is handling your lookups. Both can be true at once - a lookup that is encrypted and still leaves outside the tunnel.
What is Hydra?
Hydra is Hotspot Shield’s own VPN protocol, which older help pages call Catapult Hydra. Hotspot Shield describes it as TLS-based, with a TLS 1.2 handshake, 2048-bit RSA certificates and ephemeral ECDHE key exchange, and says it looks like regular encrypted web traffic. The protocol does not change how this test reads your result: each row judges where traffic comes out, not how it was carried.
Does the Hotspot Shield Chrome extension protect my whole device?
No. Hotspot Shield lists it as a VPN proxy and describes a secure proxy connection between your device and the website, set up inside Chrome. With only the extension running, this test shows Chrome’s view: the address the proxy gives the browser, and nothing about other apps on the device. To test the device, connect the desktop app and run the test in a browser where the extension is off.
How do I check the Hotspot Shield kill switch?
Turn it on first: Settings → Advanced on Windows, Internet Killswitch in the Android settings, Kill Switch in the iOS settings. Then start our kill switch test and force-quit the Hotspot Shield app while your network stays up. Blocked, then back on a Hotspot Shield address when you restart it, is a pass; your real IPv4 address appearing at any check is a fail.
How do I test Hotspot Shield for leaks?
Connect to Hotspot Shield as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.
Do you store my Hotspot Shield test results?
Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.
Is this page affiliated with Hotspot Shield?
No. VPNMeter is independent and this page is not endorsed by or connected to Hotspot Shield. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.