Is IVPN Leaking Your Real IP?
First, the quick question: does your traffic leave through IVPN’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.
Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.
What This Test Tells You About IVPN
IVPN’s kill switch is the IVPN Firewall, which filters packets in the operating system rather than in the app and can be set to block everything outside the tunnel from boot. Over WireGuard it can give you an IPv6 address inside the tunnel, and its DNS, including the AntiTracker blocking resolvers, runs on internal servers on each VPN server. IVPN is operated by IVPN Limited, registered in Gibraltar.
The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on IVPN as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.
Supported protocols: WireGuard, OpenVPN, IKEv2 (iOS only)
IVPN Settings That Affect Leak Results
Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.
| Setting | Where to find it | What it does |
|---|---|---|
| IVPN Firewall | Settings → IVPN Firewall | The kill switch. On-demand switches it on and off with the connection; the Always-on firewall blocks non-VPN traffic all the time, including during boot. IVPN says it works independently of the app, so a crashed client does not lift the block. |
| Enable IPv6 in VPN tunnel | Settings → Connection | WireGuard only. Gives you an IPv6 address inside the tunnel, so an IPv6 address on IVPN’s network in your results is the tunnel, not a leak. IVPN does not yet offer IPv6 DNS. |
| AntiTracker | Main window, below the IVPN Firewall switch | DNS-level blocking of trackers, ads and malicious domains. Hardcore Mode, under Settings → AntiTracker, also blocks Google and Meta domains. Both use separate internal resolvers on the VPN server instead of the regular one. |
| Custom DNS | Settings → DNS | “Use custom DNS server when connected to IVPN” sends lookups to a server you enter. This test reports a resolver outside the exit’s network as a leak, even one you chose on purpose. |
| Split Tunnel | Settings → Split Tunnel | Windows, Linux and Android. Listed apps skip the tunnel, or in Inverse mode only listed apps use it, and either way traffic outside the tunnel uses your real address. IVPN notes the Firewall cannot be used in Inverse mode, and that without it, DNS from excluded apps may go to your ISP. |
Settings as described in IVPN’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.
Common IVPN Leak Scenarios
An IPv6 address appears
With Enable IPv6 in VPN tunnel on and WireGuard selected, check whether the address is on IVPN’s network - the IPv6 row counts a tunnelled address as a pass. One on your ISP’s network while IPv4 is tunnelled is a leak; IVPN says the IVPN Firewall stops IPv6 from leaving outside the tunnel, so confirm the Firewall is on.
The DNS row shows a resolver outside IVPN
Check Settings → DNS for a custom server, then your browser’s secure DNS setting. IVPN says the Firewall blocks plain-text DNS to non-IVPN servers but cannot detect DNS-over-HTTPS or DNS-over-TLS, so a browser with its own encrypted resolver shows that resolver here.
Exposure at startup
In On-demand mode the Firewall blocks only once you connect. The Always-on firewall blocks from boot; IVPN describes that boot-time protection as fully reliable on Windows and best-effort on macOS and Linux.
How to Read Your Results
Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with IVPN disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.
- IPv4: the ISP and organisation fields should name IVPN or its hosting partners, not your home ISP.
- DNS: resolvers should sit in the same network as your IVPN exit. Your ISP’s name, or a public resolver such as
1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak. - WebRTC: a
192.168.x.xor10.x.x.xaddress is your local network and harmless. A public address differing from your exit IP is a real leak. - IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through IVPN escaped the tunnel.
- Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.
Why a Connected VPN Can Still Leak
The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.
This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.
Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.
🧰 Test IVPN Further
The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.
📚 Read next
The longer version: what this test is looking for, and what to do with the answer.
IVPN Leak Test - FAQ
Provider-specific questions about IVPN, its settings, and what a failed check actually means.
Where is IVPN’s kill switch?
It is the IVPN Firewall, under Settings → IVPN Firewall on Windows, macOS and Linux. It can switch on with each connection or stay on permanently as the Always-on firewall. IVPN says it filters packets in the operating system independently of the client, so if the client crashes, nothing leaves the computer until you disable the Firewall or a tunnel is re-established. Our kill switch test asks you to force-quit the app, which is that case.
Does IVPN support IPv6?
Yes, as an option for WireGuard connections: IVPN gives you an IPv6 address inside the tunnel (IPv6 over IPv4), though IPv6 DNS is not yet available. On this site’s IPv6 test, an address on VPN or hosting infrastructure counts as tunnelled. An address on your ISP’s network while IPv4 goes through IVPN is a leak - IVPN says the Firewall prevents it, and the test is how you confirm that on your own device.
Does AntiTracker change the DNS result?
It changes which domains are blocked. IVPN says its regular, AntiTracker and Hardcore resolvers are all internal servers on each VPN server, reachable only while you are connected. The DNS row checks that description on your server: it compares the network of the resolver that actually reached our servers with the network of your exit, and reports anything outside it as a leak.
Do Multi-hop or obfuscation change what this test sees?
Multi-hop, chosen from the Multi-hop tab on the main screen, routes your traffic through an entry and an exit server in different countries; this test sees only the address your traffic finally leaves from, so it reports one server, not two. Obfuscation (V2Ray or obfsproxy, under Settings → Connection) disguises only the connection between you and the VPN server, and IVPN says the server’s outgoing address stays the same with or without it.
How do I test IVPN for leaks?
Connect to IVPN as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.
Do you store my IVPN test results?
Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.
Is this page affiliated with IVPN?
No. VPNMeter is independent and this page is not endorsed by or connected to IVPN. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.