Is TunnelBear Leaking Your Real IP?
First, the quick question: does your traffic leave through TunnelBear’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.
Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.
What This Test Tells You About TunnelBear
TunnelBear’s settings go by their own names: VigilantBear is the kill switch, GhostBear the obfuscation and SplitBear the split tunnelling. Its help centre says its servers handle all DNS requests through the tunnel, and that a DNS test should show the address of the VPN server you are connected to. The service is run by TunnelBear LLC from Toronto, Canada.
The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on TunnelBear as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.
Supported protocols: WireGuard, OpenVPN, IKEv2 (not on Android)
TunnelBear Settings That Affect Leak Results
Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.
| Setting | Where to find it | What it does |
|---|---|---|
| VigilantBear | Settings → Security | The kill switch: blocks traffic while TunnelBear connects and reconnects. TunnelBear describes it as covering the seconds of a reconnection, for example when you move between Wi-Fi networks. |
| GhostBear | Settings → Security | Makes VPN traffic harder to detect and block on restrictive networks. TunnelBear advises leaving it off unless you cannot connect without it, as it can slow the connection. Windows, macOS (v4) and Android. |
| SplitBear | In the app, per platform | Exempts apps or websites from the tunnel: apps and websites on Windows, websites on macOS and iOS, apps on Android. Anything exempted uses your real address and is not encrypted by TunnelBear. |
| VPN Protocol | Settings → Connections (desktop) | Auto is the default and chooses for you; WireGuard, OpenVPN and IKEv2 can be picked by hand, IKEv2 not on Android. On mobile the option is in the Settings menu. |
| Browser extension | Chrome, Firefox and Edge | Encrypts only that browser’s traffic, unlike the apps, which encrypt the whole device. TunnelBear advises against running the extension and the desktop app at the same time. |
Settings as described in TunnelBear’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.
Common TunnelBear Leak Scenarios
Traffic got out after the app was force-quit
Check that VigilantBear is switched on under Settings → Security. TunnelBear describes it as protecting the seconds while the app reconnects, and an older TunnelBear post says it does not protect you when the app is open but not connected; its help pages do not say what happens when the app itself is closed or killed. Our kill switch test does exactly that, so its result is the answer for your device.
Some sites or apps show your real IP
Check SplitBear. Exempted apps and websites leave through your own connection by design, and TunnelBear notes they are not encrypted.
The DNS row shows an unexpected resolver
TunnelBear says its servers handle all DNS while you are connected. On Android 10 and later a Private DNS setting takes priority over the VPN, and TunnelBear recommends turning it off; on a computer, check your browser’s secure DNS setting.
How to Read Your Results
Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with TunnelBear disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.
- IPv4: the ISP and organisation fields should name TunnelBear or its hosting partners, not your home ISP.
- DNS: resolvers should sit in the same network as your TunnelBear exit. Your ISP’s name, or a public resolver such as
1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak. - WebRTC: a
192.168.x.xor10.x.x.xaddress is your local network and harmless. A public address differing from your exit IP is a real leak. - IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through TunnelBear escaped the tunnel.
- Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.
Why a Connected VPN Can Still Leak
The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.
This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.
Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.
🧰 Test TunnelBear Further
The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.
📚 Read next
The longer version: what this test is looking for, and what to do with the answer.
TunnelBear Leak Test - FAQ
Provider-specific questions about TunnelBear, its settings, and what a failed check actually means.
What is TunnelBear VigilantBear?
It is TunnelBear’s kill switch, available on Windows, macOS, iOS and Android; on desktop it sits under Settings → Security. TunnelBear describes it as blocking traffic in the seconds while the app reconnects after a dropped connection. Its help pages do not say what it does if the app itself is force-quit, which is what our kill switch test asks you to do, so run that test rather than relying on the description.
Does TunnelBear leak DNS?
TunnelBear says all traffic, DNS included, goes through the tunnel once it is up, that its servers handle all DNS requests, and that a DNS test should show the address of the VPN server you are connected to. The DNS row on this page compares the network of the resolver that actually reached our servers with the network of your exit and reports anything outside it as a leak, so it checks that statement against your own connection.
Does TunnelBear protect against IPv6 leaks?
TunnelBear’s help centre does not say whether its apps carry IPv6 in the tunnel or block it, so this page does not claim either. The IPv6 test answers it for your connection: no IPv6 address, or one on VPN or hosting infrastructure, is fine; an IPv6 address on your ISP’s network while IPv4 goes through TunnelBear is a leak.
Is the TunnelBear browser extension the same as the app?
No. TunnelBear says the extensions for Chrome, Firefox and Edge encrypt only that browser’s traffic, while the desktop and mobile apps encrypt everything on the device, and it advises against running the extension and the desktop app together. This test runs in the browser, so with only the extension connected it can show a TunnelBear address while the rest of the device uses your own.
How do I test TunnelBear for leaks?
Connect to TunnelBear as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.
Do you store my TunnelBear test results?
Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.
Is this page affiliated with TunnelBear?
No. VPNMeter is independent and this page is not endorsed by or connected to TunnelBear. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.