Is NordVPN Leaking Your Real IP?
Connect to NordVPN, then run the test below. We check IPv4, IPv6, DNS, WebRTC and geolocation consistency - the five channels that can expose you while the app still reports a healthy connection.
What This Test Tells You About NordVPN
NordVPN runs NordLynx, its own WireGuard-based protocol, and operates DNS resolvers on every server. It does not carry IPv6 traffic - the client blocks IPv6 rather than tunnelling it - so on a dual-stack connection the correctness of that block is the thing worth verifying.
The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on NordVPN as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.
Supported protocols: NordLynx (WireGuard-based), OpenVPN, IKEv2/IPSec
NordVPN Settings That Affect Leak Results
Before concluding anything from a failed row, check these. Most reported leaks turn out to be a setting rather than a defect.
| Setting | Where to find it | What it does |
|---|---|---|
| Kill Switch | Settings β General | Two variants on desktop: an app-level switch that closes chosen programs, and an internet-level switch that blocks all traffic. The internet-level one is what you want. |
| Threat Protection | Settings β Threat Protection | DNS-level blocking of ads, trackers and malicious domains. Changes which resolver answers your queries, so it affects what the DNS row reports. |
| Custom DNS | Settings β Connection | Overrides NordVPN’s own resolvers. A misconfigured entry here is a common cause of an unexpected DNS result. |
| Protocol | Settings β Connection | NordLynx is the fastest option and the default. Switch here if you are diagnosing a speed rather than a leak problem. |
Setting names and menu locations shift between app versions and platforms. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.
Common NordVPN Leak Scenarios
The DNS row shows your ISP
Check whether Custom DNS is enabled with a stale entry, and confirm Threat Protection is not interacting with a system-level DNS setting. Reconnect afterwards - DNS configuration is applied when the tunnel comes up, so changes do not take effect until the next connection.
An IPv6 address appears
NordVPN blocks rather than tunnels IPv6, so any IPv6 address in your results means the block is not covering your interface. Disable IPv6 in your adapter settings as a definitive fix, then re-run this test.
Traffic continues after disconnecting
The app-level kill switch only closes the programs you listed. Switch to the internet-level kill switch, then verify it with our kill switch test rather than trusting the setting.
How to Read Your Results
Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with NordVPN disconnected, once connected. Any value identical across both runs is travelling outside the tunnel.
- IPv4: the ISP and organisation fields should name NordVPN or its hosting partners, not your home ISP.
- DNS: resolvers should belong to NordVPN or to a filtering service it operates. Your ISP’s name here means your browsing history is going to your ISP regardless of the tunnel.
- WebRTC: a
192.168.x.xor10.x.x.xaddress is your local network and harmless. A public address differing from your exit IP is a real leak. - IPv6: either nothing at all, or an address belonging to NordVPN. Anything else escaped the tunnel.
- Geolocation: your browser timezone should match the exit country. A mismatch does not expose your IP, but it marks the session as VPN traffic to streaming services and fraud systems.
Why a Connected VPN Can Still Leak
The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.
This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.
Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.
π§° Test NordVPN Further
Every test runs entirely in your browser - nothing is stored unless you choose to share the result.
NordVPN Leak Test - FAQ
Provider-specific questions about NordVPN, its settings, and what a failed check actually means.
Does NordVPN leak DNS?
NordVPN routes DNS through its own resolvers on every server, so a correctly working connection shows NordVPN-operated resolvers rather than your ISP’s. When users do see a DNS leak, the cause is usually a Custom DNS entry left over from earlier troubleshooting, or a system-level resolver override outside the app. Run the test above to see which resolvers actually answer for you.
Does NordVPN support IPv6?
No. NordVPN carries IPv4 traffic only and blocks IPv6 at the client rather than tunnelling it. That is a legitimate design choice - a blocked protocol cannot leak - but it depends on the block covering every interface on your device. If an IPv6 address shows up in the test above, the block is not doing its job on your setup, and disabling IPv6 at the OS level is the reliable fix.
What is the difference between NordVPN’s two kill switches?
The app kill switch closes a list of programs you specify when the tunnel drops; anything not on the list keeps running unprotected. The internet kill switch blocks all traffic regardless of which program generated it. Only the second one gives you the guarantee most people assume they are getting, and it is worth confirming with an actual test.
Is NordLynx safer than OpenVPN?
They are equivalent in cipher strength; both are unbroken. NordLynx is built on WireGuard, whose implementation is a small fraction of OpenVPN’s size and correspondingly easier to audit, and it is considerably faster. NordLynx adds a double-NAT layer to address WireGuard’s habit of keeping static IPs assigned to users. For leak behaviour specifically, protocol choice matters far less than the kill switch and DNS settings.
How do I test NordVPN for leaks?
Connect to NordVPN as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any value that stays the same across both runs never entered the tunnel.
Do you store my NordVPN test results?
Not unless you ask us to. Every check runs in your browser, and by default the results exist only in the page in front of you - closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, the provider and your exit country - never your IP address.
Is this page affiliated with NordVPN?
No. VPNMeter is independent and this page is not endorsed by or connected to NordVPN. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.