🛡️VPN Adviser
Home / Blog / How to Test If Your VPN Is Working in 2026: IP Leaks, DNS Leaks, and WebRTC Leaks Explained
VPN Guides

How to Test If Your VPN Is Working in 2026: IP Leaks, DNS Leaks, and WebRTC Leaks Explained

3 July 2026

Installing a VPN and seeing a green checkmark in the app does not guarantee your traffic is actually private. Here are the tests that confirm your VPN is doing its job -- and what to do when it is not.

The Basic IP Test: 30 Seconds to Confirm the VPN Is On

The fastest test: visit ipleak.net before and after connecting to the VPN. Without the VPN, you will see your real IP address and your approximate location (usually accurate to your city). With the VPN connected, you should see the VPN server's IP address and that server's location. If you connected to a server in Germany, the location shown should be Germany. If you still see your real IP address after connecting: your VPN connection failed silently. Disconnect and reconnect, or try a different server. Some VPN apps have a known issue where they show as connected in the app UI but the tunnel is not actually established -- the IP test catches this immediately.

DNS Leak Test: The Leak Most People Miss

The IP test passing does not mean your DNS queries are private. DNS queries (translating domain names to IP addresses) happen constantly as you browse and can leak outside the VPN tunnel to your ISP's DNS servers. This reveals your browsing activity to your ISP even when your traffic is encrypted. Test at dnsleaktest.com: run the extended test while connected to your VPN. The results show which DNS servers are processing your queries. You want to see servers belonging to your VPN provider, not your ISP. NordVPN, ExpressVPN, and Mullvad all include DNS leak protection by default -- their apps route DNS through their own servers. If you are using a manual OpenVPN or WireGuard setup without a full VPN app, DNS leak protection may not be automatic. Set your DNS manually to your VPN provider's DNS addresses.

WebRTC Leak Test: The Browser-Level Problem

WebRTC is the most commonly missed leak type. Browser-based video and audio (Google Meet, Discord web, browser games) uses WebRTC, which can expose your real IP directly to websites through a mechanism that bypasses the VPN. Test at browserleaks.com/webrtc: if you see your real IP under any category while the VPN is connected, you have a WebRTC leak. The fix is browser-level, not VPN-level: the VPN desktop app cannot stop WebRTC leaks by itself. Use your VPN provider's browser extension (most major providers have one), which typically includes WebRTC blocking. In Firefox, you can disable WebRTC entirely via about:config (media.peerconnection.enabled = false). In Chrome, WebRTC cannot be fully disabled but can be restricted with extensions like uBlock Origin with WebRTC blocking enabled.

Kill Switch: What Happens When the VPN Disconnects

VPNs sometimes disconnect unexpectedly -- server issues, network changes, sleep/wake cycles. If your VPN disconnects without a kill switch, your traffic briefly uses your real IP until the VPN reconnects. A kill switch blocks all internet traffic if the VPN connection drops, preventing any accidental exposure. Most major VPN providers include a kill switch option in settings -- enable it if you care about continuous privacy. To test if your kill switch works: connect to the VPN, enable the kill switch, then manually disconnect the VPN in the app. Your internet should stop working immediately. When you reconnect the VPN, internet access should resume. If internet access continues when you manually disconnect the VPN with the kill switch on, the kill switch is not working correctly.

Want expert VPN recommendations?

We compare every major VPN so you don't have to. See our top picks for 2026.

See Top VPN Reviews