Is PureVPN Leaking Your Real IP?
First, the quick question: does your traffic leave through PureVPN’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.
Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.
What This Test Tells You About PureVPN
PureVPN, a brand of GZ Systems, runs its own DNS servers and says DNS leak protection is on by default in its apps. Its kill switch is the Internet Kill Switch, or IKS, documented for Windows, macOS and Linux. On Windows, split tunneling picks the programs that use the VPN, so a browser left off the list goes around it.
The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on PureVPN as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.
Supported protocols: WireGuard, OpenVPN, IKEv2
PureVPN Settings That Affect Leak Results
Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.
| Setting | Where to find it | What it does |
|---|---|---|
| Internet Kill Switch (IKS) | More → Settings → Connection (Windows), Preferences → Advanced (macOS) | Cuts internet access when the VPN connection drops. On Windows the toggle reads Enable IKS - check that it is on rather than assuming it. |
| Split Tunneling | More → Settings → Connection (Windows), More → VPN → Advanced (Android) | On Windows the programs you add are the ones routed through the VPN, and everything else uses your own connection. Android offers both directions: only selected apps use the VPN, or selected apps do not. A browser outside the tunnel shows your real address here by design. |
| DNS leak protection | On by default | PureVPN says its apps encrypt DNS requests and send them through the tunnel to its own servers. The DNS row checks whether the resolver that answers sits in the network of your exit. |
| Protocol | More → Settings → Protocol | Automatic Protocol Selection chooses for you; turn it off while disconnected to pick WireGuard, OpenVPN or IKEv2. The Android list also has Proxy, which PureVPN says does not offer encryption. |
| WebRTC leak protection | Browser extension → Settings → Advanced Features | A toggle in the PureVPN browser extension, not the desktop app. It covers the WebRTC row only in the browser the extension is installed in. |
Settings as described in PureVPN’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.
Common PureVPN Leak Scenarios
The browser shows your real IP but other apps do not
On Windows, check the Split Tunneling list. Only the programs on it use the VPN, and PureVPN’s guide asks you to add all of a program’s processes - a browser missing from the list, or only partly on it, can send traffic around the tunnel.
The IPv4 row names a home ISP while connected
If that ISP is your own, the traffic is not reaching PureVPN at all. If it is a different one, check for the Residential Network add-on: PureVPN says it gives you an address from a real ISP, in the US or the UK, which this test will not attribute to PureVPN.
An IPv6 address appears
PureVPN lists IPv6 leak protection among its app features, so an IPv6 address on your ISP’s network means it is not covering your setup. PureVPN’s help centre has a guide to switching IPv6 off in the Windows network settings; re-run this test afterwards.
How to Read Your Results
Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with PureVPN disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.
- IPv4: the ISP and organisation fields should name PureVPN or its hosting partners, not your home ISP.
- DNS: resolvers should sit in the same network as your PureVPN exit. Your ISP’s name, or a public resolver such as
1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak. - WebRTC: a
192.168.x.xor10.x.x.xaddress is your local network and harmless. A public address differing from your exit IP is a real leak. - IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through PureVPN escaped the tunnel.
- Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.
Why a Connected VPN Can Still Leak
The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.
This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.
Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.
🧰 Test PureVPN Further
The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.
📚 Read next
The longer version: what this test is looking for, and what to do with the answer.
PureVPN Leak Test - FAQ
Provider-specific questions about PureVPN, its settings, and what a failed check actually means.
What is PureVPN’s Internet Kill Switch?
It is PureVPN’s kill switch, called IKS in the app: it disconnects your internet access when the VPN connection drops. PureVPN documents it for Windows (More → Settings → Connection, Enable IKS), macOS (Preferences → Advanced) and Linux. To see whether it holds on your device, start our kill switch test and force-quit the PureVPN app while your network stays up: blocked, then back on a PureVPN address when you restart it, is a pass; your real IPv4 address appearing is a fail.
Does PureVPN leak DNS?
PureVPN says it runs its own DNS servers, encrypts DNS requests and sends them through the tunnel, with DNS leak protection on by default. The DNS row above reports any resolver outside the network of your exit as a leak - your ISP’s, a public resolver you set yourself, or one your browser reaches over DNS-over-HTTPS. If you see one, check the system and browser DNS settings before the app.
Does PureVPN protect against IPv6 leaks?
PureVPN lists IPv6 leak protection among its app features and describes it as keeping IPv6 traffic from leaking outside the tunnel. This test counts IPv6 as a leak when your IPv4 traffic goes through PureVPN while an IPv6 address on a consumer network, such as your ISP’s, still answers. No IPv6 address at all, or one on VPN or hosting infrastructure, is a pass.
Does the PureVPN browser extension protect my whole device?
No. PureVPN says the extension connects only your browser to a proxy server, and other apps keep using a direct connection. Run with the extension alone, this test shows the browser’s view and nothing about the rest of the device. The extension’s own WebRTC leak protection is a toggle under Settings → Advanced Features, and its Bypass proxy list sends the domains on it around the proxy.
How do I test PureVPN for leaks?
Connect to PureVPN as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.
Do you store my PureVPN test results?
Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.
Is this page affiliated with PureVPN?
No. VPNMeter is independent and this page is not endorsed by or connected to PureVPN. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.