🩸 ProtonVPN Leak Test

Is ProtonVPN Leaking Your Real IP?

Connect to ProtonVPN, then run the test below. We check IPv4, IPv6, DNS, WebRTC and geolocation consistency - the five channels that can expose you while the app still reports a healthy connection.

πŸ›‘οΈ
Ready to test
Connect to ProtonVPN, then start the test
-
Leak Score
🌐
IPv4 Address Test
Checks if your visible IP matches your VPN - not your real ISP
Pending β–Ό
Run the test to see your IPv4 status.
πŸ”’
IPv6 Leak Test
Many VPNs fail to tunnel IPv6 - exposing your real address
Pending β–Ό
Run the test to check for IPv6 leaks.
πŸ“‘
DNS Leak Test
Checks which DNS servers resolve your queries - ISP servers = exposed
Pending β–Ό
Run the test to check your DNS servers.
πŸŽ₯
WebRTC Leak Test
Browser WebRTC can bypass VPNs and reveal your local/real IP
Pending β–Ό
Run the test to check for WebRTC leaks.
πŸ“
Geolocation Consistency
Checks if IP location, timezone, and browser language are consistent
Pending β–Ό
Run the test to check geolocation consistency.

What This Test Tells You About ProtonVPN

ProtonVPN publishes the source of all its client apps and has had them independently audited. It offers a permanent kill switch that survives reboots, NetShield DNS filtering, and Stealth - an obfuscated protocol for networks that block VPNs outright.

The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on ProtonVPN as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.

Supported protocols: WireGuard, OpenVPN, Stealth

ProtonVPN Settings That Affect Leak Results

Before concluding anything from a failed row, check these. Most reported leaks turn out to be a setting rather than a defect.

SettingWhere to find itWhat it does
Kill switch Settings β†’ Connection Blocks traffic when the tunnel drops.
Permanent kill switch Settings β†’ Connection Stricter variant: blocks all traffic whenever the VPN is not connected, including at boot before the app starts. This closes the startup gap a normal kill switch leaves open.
NetShield Settings β†’ NetShield DNS filtering for ads, trackers and malware. Determines which resolver answers your queries.
Stealth protocol Settings β†’ Protocol Obfuscates VPN traffic to look like ordinary HTTPS. Use on networks that actively block VPN connections.
Secure Core Server list Routes through a second server in a privacy-friendly jurisdiction before exiting. Costs speed; changes the exit address the test reports.

Setting names and menu locations shift between app versions and platforms. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.

Common ProtonVPN Leak Scenarios

Slower than expected

Secure Core routes through two servers by design and roughly halves throughput. Disable it and re-test before concluding the connection is slow.

Exposure right after boot

A standard kill switch only acts once the app is running. Enable the permanent kill switch, which blocks traffic from startup onward.

The DNS row shows a Proton resolver you did not choose

That is NetShield selecting a filtering resolver based on your blocking level. It is expected behaviour, not a leak.

How to Read Your Results

Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with ProtonVPN disconnected, once connected. Any value identical across both runs is travelling outside the tunnel.

  • IPv4: the ISP and organisation fields should name ProtonVPN or its hosting partners, not your home ISP.
  • DNS: resolvers should belong to ProtonVPN or to a filtering service it operates. Your ISP’s name here means your browsing history is going to your ISP regardless of the tunnel.
  • WebRTC: a 192.168.x.x or 10.x.x.x address is your local network and harmless. A public address differing from your exit IP is a real leak.
  • IPv6: either nothing at all, or an address belonging to ProtonVPN. Anything else escaped the tunnel.
  • Geolocation: your browser timezone should match the exit country. A mismatch does not expose your IP, but it marks the session as VPN traffic to streaming services and fraud systems.

Why a Connected VPN Can Still Leak

The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.

This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.

Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.

ProtonVPN Leak Test - FAQ

Provider-specific questions about ProtonVPN, its settings, and what a failed check actually means.

What is ProtonVPN’s permanent kill switch?

The standard kill switch reacts when an established connection drops. The permanent version blocks all internet traffic whenever the VPN is not connected - including during boot, before the client has started. That closes the startup window a normal kill switch cannot cover, and it is the setting to enable if your reason for using a VPN would be undermined by a few seconds of exposure.

Does ProtonVPN leak DNS?

ProtonVPN routes DNS through its own resolvers inside the tunnel, and NetShield may direct you to a filtering resolver depending on your blocking level - both are expected and neither is a leak. A genuine leak shows your ISP’s resolver, which normally means a system-level DNS override or browser DNS-over-HTTPS bypassing the tunnel.

What is ProtonVPN Stealth?

Stealth is an obfuscated protocol that disguises VPN traffic as ordinary HTTPS, for networks that detect and block VPN connections - some corporate networks, campus Wi-Fi and national filtering systems. It is slower than WireGuard because of the extra encapsulation, so use it only where a standard connection fails.

Is ProtonVPN’s free tier as secure as the paid one?

The encryption and no-logs policy are identical; the free tier limits you to servers in a few countries, restricts speed, and omits extras such as Secure Core and NetShield. Importantly the kill switch is available on the free tier, so the core leak protections are intact. What you give up is capacity and convenience, not security.

How do I test ProtonVPN for leaks?

Connect to ProtonVPN as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any value that stays the same across both runs never entered the tunnel.

Do you store my ProtonVPN test results?

Not unless you ask us to. Every check runs in your browser, and by default the results exist only in the page in front of you - closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, the provider and your exit country - never your IP address.

Is this page affiliated with ProtonVPN?

No. VPNMeter is independent and this page is not endorsed by or connected to ProtonVPN. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.