🩸 Windscribe Leak Test

Is Windscribe Leaking Your Real IP?

First, the quick question: does your traffic leave through Windscribe’s network at all? Then the full test checks IPv4, IPv6, DNS, WebRTC and geolocation - the five channels that can expose you while the app still reports a healthy connection.

Reads your IPv4 and IPv6 addresses from ipify, then looks up the network behind each one via ip-api.com. Your addresses are not stored.

🛡️
Ready to test
Connect to Windscribe, then start the test
-
Leak Score
🌐
IPv4 Address Test
Checks if your visible IP matches your VPN - not your real ISP
Pending ▼
Run the test to see your IPv4 status.
🔢
IPv6 Leak Test
A VPN that carries only IPv4 can leave IPv6 going around the tunnel
Pending ▼
Run the test to check for IPv6 leaks.
📡
DNS Leak Test
Checks which resolvers answer your lookups - outside your VPN exit's network = leak
Pending ▼
Run the test to check your DNS servers.
🎥
WebRTC Leak Test
Browser WebRTC can bypass VPNs and reveal your local/real IP
Pending ▼
Run the test to check for WebRTC leaks.
📍
Geolocation Consistency
Checks if your browser timezone fits the continent of your exit IP
Pending ▼
Run the test to check geolocation consistency.

What This Test Tells You About Windscribe

Windscribe has no setting called kill switch: the equivalent is the Firewall, which has several modes on desktop. Its apps send DNS over the tunnel to Windscribe’s own internal DNS servers, which is where R.O.B.E.R.T. does its domain blocking, and it also makes a browser extension that works as a proxy for that browser only - so which of the two is connected decides what this test sees. Windscribe is headquartered in Toronto, Canada.

The result you see above measures your own connection, right now - your device, your operating system, your version of the app and the server you happen to be on. It is not a verdict on Windscribe as a product, and it is not a lab benchmark. Leak behaviour varies enormously between platforms and client versions, which is precisely why measuring your own setup beats reading anyone’s provider ranking.

Supported protocols: WireGuard, IKEv2, OpenVPN (UDP and TCP), Stealth, WStunnel

Windscribe Settings That Affect Leak Results

Before concluding anything from a failed row, check these: a setting can be the explanation, and it is quicker to rule out than a defect.

SettingWhere to find itWhat it does
Firewall Mode Preferences → Connection → Firewall Mode The kill switch. Automatic switches the firewall on when you connect and off when you disconnect, and Windscribe says it also cuts the internet if the app crashes. Manual leaves it to you. Always On blocks everything outside the VPN with or without the app running, including after a restart. On Android and iOS, Windscribe points to the system’s Always On VPN setting instead.
Connected DNS Preferences → Connection → Connected DNS Auto uses Windscribe’s own DNS, which is where R.O.B.E.R.T. applies. Custom sends lookups to a resolver you choose, and this test reports any resolver outside the exit’s network as a leak - even one you picked on purpose.
R.O.B.E.R.T. Account page on windscribe.com Server-side blocking of domains and IPs, applied through Windscribe’s DNS while you are connected. It changes which domains load, and Windscribe says it stops applying when Connected DNS is set to Custom.
Split Tunnel Preferences → Connection → Split Tunnel Exclusive or Inclusive mode, built from a list of apps or of IPs and hostnames. Whatever the rules leave outside the tunnel uses your real address by design.
Browser extension Installed separately in the browser A proxy for that browser only: with just the extension connected, everything outside the browser uses your own address. Connected together with the desktop app it makes a Double Hop, and websites see the extension’s server.

Settings as described in Windscribe’s own apps and help pages. Menus move between app versions - check yours. If a control is not where this table says, search the app’s settings for the nearest equivalent term rather than assuming the feature is absent.

Common Windscribe Leak Scenarios

The WebRTC row shows your real address

If only the browser extension is connected, this is the case Windscribe itself warns about: WebRTC can get around a browser proxy. Turn on WebRTC Slayer in the extension’s Privacy menu, or connect the desktop app, which tunnels the whole system, and run the test again.

The browser and other apps show different addresses

With the desktop app and the extension both connected, that is Double Hop: websites see the extension’s server, while apps outside the browser leave from the desktop app’s location. This test runs in the browser, so it reports the extension’s exit.

Traffic got out after the app was force-quit

Check the Firewall mode. Windscribe says Manual turns the firewall off when you close the app yourself, Automatic holds the block if the app crashes, and Always On blocks with or without the app running. Set the mode you want, then re-run our kill switch test.

How to Read Your Results

Expand any row to see the raw values. The single most reliable way to interpret an ambiguous result is to run the test twice - once with Windscribe disconnected, once connected. Any address or resolver identical across both runs is travelling outside the tunnel.

  • IPv4: the ISP and organisation fields should name Windscribe or its hosting partners, not your home ISP.
  • DNS: resolvers should sit in the same network as your Windscribe exit. Your ISP’s name, or a public resolver such as 1.1.1.1, means your lookups are leaving the tunnel - even if you chose that resolver deliberately, this test reports it as a leak.
  • WebRTC: a 192.168.x.x or 10.x.x.x address is your local network and harmless. A public address differing from your exit IP is a real leak.
  • IPv6: either nothing at all, or an address on VPN or hosting infrastructure. One on your ISP’s network while IPv4 goes through Windscribe escaped the tunnel.
  • Geolocation: your browser timezone should be on the same continent as the exit. A mismatch does not expose your IP, but it tells a site the address is not where you are.

Why a Connected VPN Can Still Leak

The word “connected” in any VPN client describes one thing: the IPv4 tunnel came up. It says nothing about DNS resolution, IPv6 routing or WebRTC, each of which uses a different part of the operating system and can bypass the tunnel independently. A client that fails to capture them will still display a green badge.

This is why single-number IP checkers are misleading. They query one endpoint over IPv4, see the VPN’s address, and report success - while DNS queries go to your ISP and your IPv6 prefix identifies your household to every site that supports it.

Re-test after anything that touches the network stack: a client update, an OS upgrade, a protocol change or a new server. Those are the moments when leak protection regresses, and a regression produces no visible symptom at all - which is the entire problem.

🧰 Test Windscribe Further

The tests run in your browser. Where one needs to know whose network an address is on, our server looks it up and keeps no address. Nothing is stored unless you choose to share the result.

📡
DNS Leak Test
See which DNS resolvers actually answer your queries
🔢
IPv6 Leak Test
Detect IPv6 traffic escaping your VPN tunnel
🎥
WebRTC Leak Test
Check if WebRTC exposes your real IP to any website
🔌
Kill Switch Test
Verify your VPN blocks traffic the moment it drops

Windscribe Leak Test - FAQ

Provider-specific questions about Windscribe, its settings, and what a failed check actually means.

Where is the kill switch in Windscribe?

Windscribe does not have a setting called kill switch; the equivalent is the Firewall, under Preferences → Connection → Firewall Mode in the desktop apps. Automatic switches it on when you connect, Manual leaves it to you, and Always On blocks every connection outside the VPN whether or not the app is running, including after a restart. Windscribe’s feature page also lists Always-on+, which blocks the app’s own connections to Windscribe as well. Our kill switch test asks you to force-quit the app, which is where the modes differ, so it shows what your mode actually does.

Does Windscribe tunnel or block IPv6?

It depends on where you connect. Windscribe says IPv6 support is rolling out across its apps and server locations: where your app and location support it, IPv6 goes through the tunnel over WireGuard, on paid locations only, and elsewhere the app blocks IPv6. This test reads either as correct - no IPv6 address at all, or one on VPN or hosting infrastructure. A leak is IPv4 going through Windscribe while IPv6 leaves through your ISP’s network.

Why does the DNS test flag my resolver on Windscribe?

Windscribe says that when you are connected, all DNS queries go over the tunnel to its own internal DNS servers. The DNS row compares the network of the resolver that actually reached our servers with the network of your exit, and reports anything outside it as a leak. Two settings send lookups elsewhere on purpose: Connected DNS set to Custom, and a secure DNS setting in your browser that uses its own provider.

Is the Windscribe browser extension enough for this test?

It covers only that browser. Windscribe describes the extension as a lightweight browser proxy: with only the extension connected, traffic outside the browser uses your own address, and WebRTC can get around the proxy unless WebRTC Slayer is on. Because this test runs inside the browser, it can show a Windscribe address while the rest of the device is not tunnelled. Connect the desktop app to test the device as a whole.

How do I test Windscribe for leaks?

Connect to Windscribe as you normally would, then run the test at the top of this page. It checks IPv4, IPv6, DNS, WebRTC and geolocation consistency in a single pass. For a definitive reading, run it once disconnected and once connected - any address or resolver that stays the same across both runs never entered the tunnel.

Do you store my Windscribe test results?

Not unless you ask us to. The checks run in your browser - only the lookup of which network an address belongs to goes through our server, which keeps no address - and by default the results exist only in the page in front of you; closing the tab discards them. After a test you can tick a box to share the result anonymously for our public VPN database; it is off by default. When you do share, we store the outcome, your VPN provider, the exit network, country and city, your browser and OS family, and where your visit came from - never your IP address. The privacy page lists every field.

Is this page affiliated with Windscribe?

No. VPNMeter is independent and this page is not endorsed by or connected to Windscribe. We describe settings you can verify in the app yourself, and the test measures your own connection rather than reporting results from a lab. Provider and product names are trademarks of their respective owners.