Why You Need to Audit Your VPN
A VPN can appear connected while leaking your real IP address, DNS requests, or WebRTC data. These leaks happen silently and are often caused by system or browser updates that change how traffic is routed. Running a privacy audit takes 10 minutes and gives you certainty that your VPN is actually providing the protection you are paying for.
Step 1: Check Your IP Address
Navigate to ipleak.net or whatismyip.com while connected to your VPN. The IP address shown should match your VPN server location, not your real location. If it shows your city or a nearby city that is not the VPN server location, your real IP is leaking. This is rare with reputable VPN clients but worth confirming after updates.
Step 2: DNS Leak Test
Navigate to dnsleaktest.com. Run the extended test. The DNS servers listed should belong to your VPN provider or a neutral DNS provider. If you see your ISP's DNS servers listed, your DNS requests are leaking outside the VPN tunnel. This exposes which websites you visit to your ISP even though your traffic is encrypted. Fix: in your VPN client settings, look for DNS leak protection or force DNS over VPN option and enable it.
Step 3: WebRTC Leak Test
WebRTC is a browser technology that can expose your real IP even when a VPN is active. Navigate to browserleaks.com and check the WebRTC section. If it shows an IP address that is not your VPN's IP, you have a WebRTC leak. Fix: disable WebRTC in your browser settings, or use a browser extension that blocks WebRTC.
Step 4: Kill Switch Test
Enable your VPN client's kill switch if it has one. Then disconnect your VPN while connected to the internet. Your internet should stop working immediately (that is what a kill switch does). If browsing continues normally after disconnecting the VPN, the kill switch is not functioning. This matters because whenever your VPN drops connection briefly, your traffic continues through your regular ISP connection without protection.