Is Your IPv6 Address Leaking?
A VPN that carries only IPv4 has to block IPv6 as well. If it does not, and your device has IPv6, your real IPv6 address is visible to every site you reach over it.
What Is an IPv6 Leak?
An IPv6 leak happens when your device sends traffic over the IPv6 protocol while your VPN only protects IPv4. The result is a connection that looks encrypted - your VPN client shows a green “connected” badge, and an ordinary IP checker reports the VPN server’s address - while any website that supports IPv6 quietly receives your real address, assigned by your own ISP.
IPv6 is easy to miss: a check that only looks at IPv4 passes an IPv6 leak without a warning. That is exactly why this page exists: it asks an endpoint that answers over IPv6 whenever your connection has it, and separately probes WebRTC, so a leak has nowhere to hide.
Why Does IPv6 Leak in the First Place?
IPv6 is the successor to IPv4, created because the world ran out of 32-bit addresses. Internet providers can hand out an IPv6 prefix alongside the IPv4 address, and modern operating systems prefer IPv6 whenever it is available - that behaviour is defined in RFC 6724 and is on by default in Windows, macOS, Linux, iOS and Android.
The problem is a VPN client designed around IPv4. When such a client connects, it installs routes that capture IPv4 traffic and simply ignores the IPv6 stack. Your operating system, seeing a perfectly working IPv6 route that the VPN never touched, sends traffic straight out through your ISP - outside the tunnel, unencrypted, and stamped with an address that maps directly back to your household.
IPv6 addresses are also a worse privacy problem than IPv4 addresses. A home connection can be given a /64 or /56 prefix of its own that stays the same for months, with no carrier-grade NAT sharing it between subscribers. An IPv4 address shared through carrier-grade NAT identifies a neighbourhood at best; a leaked IPv6 prefix can identify a single household, and an address within it a single device.
How to Read Your Results
The test runs four independent checks. Here is what each outcome actually means for your privacy.
| Result | What it means | Action needed |
|---|---|---|
| No IPv6 connectivity | Your device has no working IPv6 route at all, so nothing can leak over it. | None. This is the safest state. |
| IPv6 present, matches VPN | You have IPv6, and it exits through your VPN provider’s network. Your provider tunnels IPv6 properly. | None - this is the ideal outcome. |
| IPv6 leak via HTTP | Ordinary web traffic is escaping the tunnel. Every IPv6-capable site you visit sees your real address. | Fix immediately - see the steps below. |
| IPv6 leak via WebRTC | Your page traffic is tunnelled, but WebRTC bypasses it. Any site can extract your real IPv6 with three lines of JavaScript. | Block WebRTC or disable IPv6. |
The two leak checks are deliberately separate, because they fail independently. It is possible to pass the HTTP check and fail the WebRTC one - WebRTC asks the operating system for local interface addresses directly, sidestepping the routing table your VPN modified.
How to Fix an IPv6 Leak
There are two valid strategies: tunnel IPv6 properly, or switch it off so there is nothing to leak. Both work; the first is better if you need IPv6-only services.
1. Turn on your VPN’s IPv6 leak protection
Check your client’s settings for “IPv6 leak protection”, “Block IPv6” or “IPv6 tunnelling”. This is the one-click fix and it is the right place to start - a properly implemented client will either route IPv6 through the tunnel or firewall it off entirely.
2. Check how your provider handles IPv6
Some providers carry IPv6 inside the tunnel, others block it; we have not measured which do it reliably. Check your provider’s own documentation, then re-run this test - provider behaviour changes between client versions, so trust the measurement rather than the marketing page.
3. Disable IPv6 at the operating-system level
- Windows: Settings → Network & Internet → Change adapter options → right-click your adapter → Properties → uncheck
Internet Protocol Version 6 (TCP/IPv6) - macOS: System Settings → Network → your interface → Details → TCP/IP → Configure IPv6 →
Off. On older releases:networksetup -setv6off Wi-Fi - Linux: add
net.ipv6.conf.all.disable_ipv6 = 1andnet.ipv6.conf.default.disable_ipv6 = 1to/etc/sysctl.conf, then runsysctl -p - Router: if your router has an IPv6 toggle (look under WAN or Internet settings), disabling it there covers every device on the network at once
4. Deal with WebRTC separately
If only the WebRTC check fails, install a WebRTC-blocking extension or set media.peerconnection.enabled to false in Firefox’s about:config. Note that this breaks video calling in the browser - a browser profile dedicated to private browsing can be the more practical arrangement. Our WebRTC leak test covers this failure mode in detail.
How This IPv6 Leak Test Works
The checks run in your browser. To tell whose network each address is on, your IPv4 and IPv6 addresses are sent to our server, which looks them up with ip-api.com and does not store them (see the privacy policy). No result is stored, and no account is required.
- IPv4 baseline: we read your visible IPv4 address first, from an endpoint that has no IPv6 address, and show it beside the IPv6 results.
- Dual-stack endpoint: the browser fetches a host that has both an IPv4 and an IPv6 address, and browsers prefer IPv6 when it works. If the answer is an IPv6 address, your traffic uses IPv6 and we capture the address that arrived.
- WebRTC candidate harvesting: we open an
RTCPeerConnectionand read the ICE candidates the browser generates. These come from the OS network stack, not the routing table, which is why they can expose addresses that HTTP requests do not. - Verdict: each address is looked up on its own. The IPv6 address sites see is a leak only when your IPv4 goes through a VPN and your IPv6 through a consumer network - your ISP’s. When both are on VPN or hosting infrastructure, IPv6 is tunnelled. When your IPv4 is not a VPN’s, there is no tunnel to bypass, and the page says so. Any other public IPv6 address WebRTC shows is a leak; local ones (fc00::, fd00::, fe80::) are not. A lookup that does not answer gives no verdict either way.
The full scoring rules are published on our methodology page.
π§° Related Leak Tests
The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.
π Read next
The longer version: what this test is looking for, and what to do with the answer.
IPv6 Leak Test - FAQ
Common questions about IPv6 leaks, how they happen, and what to do about them.
What is an IPv6 leak?
An IPv6 leak occurs when your device sends traffic over IPv6 while your VPN only protects IPv4. Your VPN client reports a successful connection and IPv4-based leak tests pass, but websites that support IPv6 receive your real address - the one your ISP assigned to your home connection. Because a test that only inspects IPv4 passes it, this can go unnoticed.
How do I know if my VPN leaks IPv6?
Run the test at the top of this page while your VPN is connected. If the IPv6 Leak (HTTP) or IPv6 Leak (WebRTC) row returns an address on your ISP’s network while your IPv4 goes through the VPN, you have a leak. A useful cross-check: run the test once with the VPN off and note the IPv6 address, then reconnect and run it again. If the same address appears both times, that traffic never entered the tunnel.
Is an IPv6 leak worse than an IPv4 leak?
In practice, yes. An IPv4 address can be shared by many subscribers behind carrier-grade NAT, and then it identifies a region rather than a person. IPv6 prefixes can be assigned per household - a /64 or /56 that can stay the same for months - with no NAT in between. A leaked IPv6 address can therefore identify a specific home connection, and even a specific device, with far greater precision.
Should I just disable IPv6 completely?
It is the simplest and most reliable fix. The cost: a service reachable only over IPv6 stops working while IPv6 is off, so turn it back on if something you use breaks. Disabling IPv6 makes a leak structurally impossible rather than dependent on your VPN client behaving correctly. The exception is anyone who needs IPv6-only resources, such as certain corporate networks or self-hosted services; in that case, use a provider that tunnels IPv6 properly instead.
Which VPNs handle IPv6 correctly?
We have not measured that: our lab’s server has no IPv6, so it reports “not tested”. Either approach - carrying IPv6 inside the tunnel or blocking it - can fail on a particular interface or client version, and the same provider can be safe on desktop and leaky on mobile. Test your own configuration above.
Why does the WebRTC check fail when the HTTP check passes?
They use different parts of the operating system. Normal web requests follow the routing table, which your VPN modifies on connect. WebRTC asks the OS for the addresses configured on your network interfaces directly, so it can report addresses that no longer have a usable route. The consequence is real: any website can run a few lines of JavaScript and read those addresses without asking permission.
Does my ISP see my traffic during an IPv6 leak?
Yes. Leaked IPv6 traffic never enters the encrypted tunnel - it travels over your ISP’s network in exactly the state it would be in with no VPN at all. Your ISP sees the destinations you connect to, and the destinations see your real address and approximate location. Encryption at the HTTPS layer still protects the contents of each page, but not who you are or what you are connecting to.
Do I need to re-test after updating my VPN app?
It is worth doing. IPv6 handling is a regression to watch for in VPN clients, because it depends on routing and firewall rules that get rewritten during updates and on OS network-stack changes outside the provider’s control. Re-running this test after a client update, an operating-system upgrade, or a switch to a new server location takes a few seconds and catches the failure if it has happened.