What a WebRTC leak is
WebRTC is the browser technology behind video calls, voice chat and screen sharing. To connect two devices directly it has to learn the addresses that can reach them, so it gathers candidates: local network addresses, addresses discovered through a public STUN server, and relay addresses.
Normally this is harmless. A leak happens when the browser reports an address that was not supposed to be visible, most often the real address of your home connection while the rest of your traffic goes through a VPN. The website sees the VPN address from ordinary requests and the real one from WebRTC, and the two do not match.
This is not malware and it is not unusual. It happens because WebRTC traffic can take a different path from the rest of the browser, especially when the VPN only covers certain routes or only IPv4.
How this test works
The test opens a WebRTC connection in your browser, points it at a public STUN server and records the candidates it receives. Each candidate is described by type and address: host candidates are local addresses, server-reflexive candidates are the public address as seen from outside, and relay candidates come from a TURN server.
The results are then compared with the IP addresses that ordinary web requests show for your connection. If a WebRTC public address matches, there is no mismatch to report. If it does not match, the page lists it so you can decide whether that address should be reachable. Local addresses that appear as random .local names are generated by the browser itself to avoid exposing your private network address.
The test has limits. It checks WebRTC, IPv6 and time zone signals in your browser. It does not test DNS yet: a DNS leak test needs a different method, explained further down.
How to control WebRTC in each browser
There is no single switch that fits every browser. The options below are the ones each browser actually provides. Turning WebRTC off stops browser-based video calls from working, so change it only if you need the protection.
Chrome and Edge
These browsers have no user-facing WebRTC address setting. An administrator can set the WebRtcIPHandlingPolicy policy to limit or disable non-proxied UDP, and extensions can block WebRTC candidates, but the extension then needs permission to modify pages. The most reliable approach with Chrome or Edge is a VPN client that blocks traffic outside the tunnel.
Firefox
Open about:config, search for media.peerconnection.enabled and set it to false to turn WebRTC off completely. A middle option is media.peerconnection.ice.no_host, which stops local addresses from being shared while keeping calls working. These settings are advanced preferences and can be reset by a browser refresh.
Safari
Safari hides local addresses by default: it replaces them with mDNS names such as a random sequence ending in .local. There is no simple user setting to disable WebRTC in Safari, so a public address can still be gathered through a STUN server if the browser is allowed to use one.
Brave
Brave exposes a WebRTC IP handling policy in its settings, with choices such as using only the default public interface or disabling non-proxied UDP. Selecting the stricter option prevents WebRTC from revealing addresses outside your proxy or VPN path.
VPN clients
Many VPN applications include a WebRTC or leak protection option, and some include a kill switch that cuts traffic if the tunnel drops. Check the client's settings and documentation. If the client offers no such control, restrict WebRTC in the browser instead.
IPv6 leaks
A VPN that only handles IPv4 can leave IPv6 traffic on its original path. If your network has working IPv6, sites that support it can then be reached through your provider while IPv4 goes through the tunnel, and the two addresses point to different networks.
The privacy summary points this out when the IPv4 and IPv6 addresses belong to different networks. The fix depends on the client: look for an IPv6 option in the VPN settings, or disable IPv6 on the connection when the tunnel does not carry it. Blocking IPv6 entirely is a trade-off, because IPv6-only services will then be unreachable.
DNS leaks
DNS is the system that turns names into addresses. When you open a site, your device asks a resolver which address belongs to that name. If those questions are sent to the provider's resolver instead of through the tunnel, the provider can see every name you look up even though your web traffic is encrypted.
Encrypted DNS, using DNS-over-HTTPS or DNS-over-TLS, protects the question on the path between your device and the resolver, but it does not by itself stop a mismatch between the resolver you chose and the tunnel you use. A well-configured VPN sends DNS through the tunnel; a misconfigured one can leak it.
This site does not run a DNS leak test yet. Doing it properly requires querying dedicated test domains and observing which resolver answers, and that is planned as a separate feature. For now the leak page reports WebRTC, IPv6 and time zone mismatches only, and it says so instead of guessing.
Time zone and language mismatches
Your browser reports a time zone and a list of languages, and sites can compare them with the country inferred from your IP address. A VPN exit in another country often leaves the browser time zone and language untouched, so the mismatch itself can reveal that a tunnel is in use.
This is not a leak in the same sense as an exposed address, because these values are deliberately available to every page. It is useful context: if you want the profile to be consistent, match the browser time zone and language to the exit location, or accept that the combination is unusual.
Frequently asked questions
Does WebRTC reveal my real IP address even when a VPN is connected?
It can. WebRTC gathers candidate addresses independently of the rest of the browser's traffic, so if the VPN does not capture that traffic the STUN-derived public address can be your real one. The test on this page exists precisely to show whether the addresses match.
Does disabling WebRTC break video calls?
In-browser calls and screen sharing that use WebRTC will stop working, including many conferencing tools. If you only want to stop local addresses from being shared, prefer a narrower setting, such as media.peerconnection.ice.no_host in Firefox, or the stricter WebRTC IP handling policy in Brave.
What is an mDNS candidate?
It is a local address that the browser hides behind a random name ending in .local, resolved only on your own network. Safari uses this by default, and other browsers use it in some conditions. Seeing an mDNS name means your private address was not handed out in readable form.
Can I test DNS leaks on this site?
Not yet. The current test covers WebRTC, IPv6 and time zone signals in the browser. A DNS leak test requires dedicated test domains and a different kind of query, and it is on the roadmap rather than silently skipped.
What is an IPv6 leak?
It happens when a tunnel protects IPv4 but IPv6 traffic still leaves through your original connection. Sites that support IPv6 can reach you on the untouched address, so the network seen by WebRTC or by the IPv6 request differs from the network seen over IPv4.
Do proxies and Tor prevent WebRTC leaks?
Not automatically. A proxy usually covers only the browser's ordinary requests, and WebRTC can bypass it the same way it bypasses a partial VPN. Tor Browser ships with WebRTC disabled by default for this reason. Whatever tool you use, run the test afterwards and check that the addresses match.