Is IPVanish Leaking Your Real IP?
First, the quick question: does your traffic leave through IPVanish’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.
Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.
What This Test Tells You About IPVanish
IPVanish, a Ziff Davis company, carries IPv4 only and blocks IPv6 in its apps rather than tunnelling it - automatically on Android and iOS, through a setting on Windows. While connected, the apps assign 198.18.0.1 and 198.18.0.2 as DNS servers, which work only inside the tunnel. Split tunneling sends apps and domains through your ISP on Windows, and domains only on macOS.
The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on IPVanish as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.
Supported protocols: WireGuard, OpenVPN, IKEv2
IPVanish Settings That Affect Leak Results
Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.
| Setting | Where to find it | What it does |
|---|---|---|
| Kill Switch | Settings → Connection (Windows), Settings → Network Security (macOS) | Stops all internet traffic if the VPN connection drops. It can only be switched on while disconnected. On Windows, Block LAN traffic extends the block to your local network. |
| DNS/IPv6 Leak Protection | Settings → Connection (Windows) | Keeps DNS lookups and IPv6 traffic from leaving outside the tunnel. On macOS, WireGuard and IKEv2 block IPv6 on their own, and the IPv6 leak protection setting under Settings → Protocol applies to OpenVPN. |
| Threat Protection | Settings → Network Security | Blocks ads and malicious sites using IPVanish’s own DNS and allow lists, so it changes which resolver answers your lookups. Switch it on while disconnected, then reconnect. |
| Split Tunneling | Settings → Split Tunneling | Apps and domains on the list go through your ISP instead of the VPN; on macOS the list takes domains only. Anything on it uses your real address by design. |
| Double Hop | Locations → Double Hop | Routes your connection through two IPVanish locations. The second is the exit, and it is the address and network this test reports. |
Settings as described in IPVanish’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.
Common IPVanish Leak Scenarios
An IPv6 address appears
IPVanish does not carry IPv6, so an IPv6 address on your ISP’s network means the block is not covering you. On Windows check DNS/IPv6 Leak Protection; on macOS with OpenVPN, the IPv6 leak protection setting. IPVanish also suggests disabling IPv6 on the device or router.
The DNS row shows an unexpected resolver
If Threat Protection is on, lookups go to IPVanish’s filtering DNS by design. A resolver belonging to your ISP or a public service points to a DNS setting outside the app, or to DNS-over-HTTPS in the browser - check the browser’s secure DNS setting first.
The real IP shows on an iPhone or iPad
IPVanish’s help centre describes iOS leaks it attributes to Apple: connections opened before the VPN started, apps using cellular data, and some Apple DNS queries. Connect the VPN first, then switch Airplane mode on and off to restart open connections.
How to Read Your Results
Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with IPVanish disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.
- IPv4: the ISP and organisation fields should name IPVanish or its hosting partners, not your home ISP.
- DNS: resolvers should sit in the same network as your IPVanish exit. Your ISP’s name, or a public resolver such as
1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak. - WebRTC: a
192.168.x.xor10.x.x.xaddress is your local network and harmless. A public address differing from your exit IP is a real leak. - IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through IPVanish escaped the tunnel.
- Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.
Why a Connected VPN Can Still Leak
The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.
This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.
Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.
🧰 Test IPVanish Further
The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.
📚 Read next
The longer version: what this test is looking for, and what to do with the answer.
IPVanish Leak Test - FAQ
Provider-specific questions about IPVanish, its settings, and what a failed check actually means.
Does IPVanish support IPv6?
No. IPVanish says it currently supports IPv4 only, and its apps block IPv6 instead: by default on Android and iOS, automatically for WireGuard and IKEv2 on macOS, and through a setting for OpenVPN on macOS and for every protocol on Windows. On a working setup this test shows no IPv6 address at all. One on a consumer network while IPv4 goes through IPVanish is a leak.
Does IPVanish leak DNS?
The apps assign 198.18.0.1 and 198.18.0.2 as DNS servers while you are connected. This test does not see those addresses: it sees the resolver that forwards your lookups to the internet, and reports it as a leak if it sits outside the network of your IPVanish exit. With Threat Protection on, lookups go through the filtering DNS IPVanish describes as its own.
How do I check the IPVanish kill switch?
Turn it on while disconnected: Settings → Connection on Windows, Settings → Network Security on macOS, Settings on iOS. On Android 8 and later it is the Android OS Kill Switch, which hands over to Android’s Always-on VPN and Block connections without VPN; split-tunnelled apps are then blocked too. Then start our kill switch test and force-quit the IPVanish app while your network stays up: blocked, then back on an IPVanish address, is a pass; your real IPv4 address appearing is a fail.
Is the IPVanish Secure Browser the same as the VPN?
No. The Secure Browser, offered as a browser extension or a web app on higher-tier IPVanish plans, runs a browser on an IPVanish server in the cloud and streams it to you as video. A leak test opened inside it measures that remote browser, not your device. To test your IPVanish connection, open this page in your normal browser with the app connected.
How do I test IPVanish for leaks?
Connect to IPVanish as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.
Do you store my IPVanish test results?
Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.
Is this page affiliated with IPVanish?
No. VPNMeter is independent and this page is not endorsed by or connected to IPVanish. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.