🩸 Mullvad Leak Test

Is Mullvad Leaking Your Real IP?

Connect to Mullvad, then run the test below. We check IPv4, IPv6, DNS, WebRTC and geolocation consistency - the five channels that can expose you while the app still reports a healthy connection.

πŸ›‘οΈ
Ready to test
Connect to Mullvad, then start the test
-
Leak Score
🌐
IPv4 Address Test
Checks if your visible IP matches your VPN - not your real ISP
Pending β–Ό
Run the test to see your IPv4 status.
πŸ”’
IPv6 Leak Test
Many VPNs fail to tunnel IPv6 - exposing your real address
Pending β–Ό
Run the test to check for IPv6 leaks.
πŸ“‘
DNS Leak Test
Checks which DNS servers resolve your queries - ISP servers = exposed
Pending β–Ό
Run the test to check your DNS servers.
πŸŽ₯
WebRTC Leak Test
Browser WebRTC can bypass VPNs and reveal your local/real IP
Pending β–Ό
Run the test to check for WebRTC leaks.
πŸ“
Geolocation Consistency
Checks if IP location, timezone, and browser language are consistent
Pending β–Ό
Run the test to check geolocation consistency.

What This Test Tells You About Mullvad

Mullvad is unusual on two counts relevant to leak testing. It actually supports IPv6 rather than merely blocking it, and its lockdown mode blocks traffic whenever the VPN is not connected. Accounts are random numbers with no email address attached.

The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on Mullvad as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.

Supported protocols: WireGuard, OpenVPN

Mullvad Settings That Affect Leak Results

Before concluding anything from a failed row, check these. Most reported leaks turn out to be a setting rather than a defect.

SettingWhere to find itWhat it does
Always require VPN Settings β†’ VPN settings Lockdown mode. Blocks all traffic whenever the tunnel is down, including at boot.
Enable IPv6 Settings β†’ VPN settings β†’ Advanced Carries IPv6 inside the tunnel instead of blocking it. Genuinely uncommon - most providers only block.
DNS content blocking Settings β†’ DNS Optional filtering of ads, trackers and malware at the resolver level.
Custom DNS Settings β†’ DNS Overrides Mullvad’s resolver. A stale entry here is the usual cause of an unexpected DNS result.
Quantum-resistant tunnel Settings β†’ VPN settings Adds post-quantum key exchange to WireGuard. No effect on leak behaviour; slightly slower handshake.

Setting names and menu locations shift between app versions and platforms. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.

Common Mullvad Leak Scenarios

An IPv6 address appears in the results

Unlike most providers, this may be correct. If IPv6 is enabled, check whether the address belongs to Mullvad - a tunnelled IPv6 address is a pass, not a leak.

No internet before the app starts

That is lockdown mode working as intended. It blocks traffic until the tunnel is up.

Unexpected DNS resolver

Check the Custom DNS field and the content-blocking level, both of which change which resolver answers.

How to Read Your Results

Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with Mullvad disconnected, once connected. Any value identical across both runs is travelling outside the tunnel.

  • IPv4: the ISP and organisation fields should name Mullvad or its hosting partners, not your home ISP.
  • DNS: resolvers should belong to Mullvad or to a filtering service it operates. Your ISP’s name here means your browsing history is going to your ISP regardless of the tunnel.
  • WebRTC: a 192.168.x.x or 10.x.x.x address is your local network and harmless. A public address differing from your exit IP is a real leak.
  • IPv6: either nothing at all, or an address belonging to Mullvad. Anything else escaped the tunnel.
  • Geolocation: your browser timezone should match the exit country. A mismatch does not expose your IP, but it marks the session as VPN traffic to streaming services and fraud systems.

Why a Connected VPN Can Still Leak

The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.

This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.

Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.

Mullvad Leak Test - FAQ

Provider-specific questions about Mullvad, its settings, and what a failed check actually means.

Does Mullvad support IPv6?

Yes, and this genuinely distinguishes it. Most providers block IPv6 because their infrastructure is IPv4-only; Mullvad carries IPv6 inside the tunnel when you enable it under Advanced settings. The practical consequence for this test is that an IPv6 address in your results is not automatically a leak - check whether the address belongs to Mullvad before treating it as a failure.

What is Mullvad’s lockdown mode?

It is called “Always require VPN”, and it blocks all internet traffic whenever the tunnel is not connected - including at boot and during reconnection. This is stricter than a conventional kill switch, which only reacts after an established connection drops, and it removes the startup exposure window entirely.

Why does Mullvad not ask for an email address?

By design. Signing up generates a random account number and nothing else, so there is no email, name or payment identity linked to your traffic. They accept cash sent by post for the same reason. It is a data-minimisation stance rather than a technical leak protection, but it means a subpoena finds far less to hand over.

Is Mullvad’s flat pricing a downside?

It is a fixed monthly rate with no long-term contracts or discount tiers, which makes it more expensive than heavily discounted two-year plans elsewhere. In exchange there is no renewal price jump, which is where most cheap VPN deals recover their margin. For leak behaviour specifically, pricing is irrelevant - what matters is the lockdown mode and IPv6 handling above.

How do I test Mullvad for leaks?

Connect to Mullvad as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any value that stays the same across both runs never entered the tunnel.

Do you store my Mullvad test results?

Not unless you ask us to. Every check runs in your browser, and by default the results exist only in the page in front of you - closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, the provider and your exit country - never your IP address.

Is this page affiliated with Mullvad?

No. VPNMeter is independent and this page is not endorsed by or connected to Mullvad. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.