What a working tunnel looks like
Two checks tell you whether the tunnel is doing its job. An IP check with the VPN off and then on should show a different address and a different network owner. A DNS leak test should list servers that belong to the VPN's network, not to your home internet company. Both take about a minute in any browser.
Running an IP check
- 1
Turn the VPN off and open an IP lookup page.
- 2
Write down the address and the provider name it shows, which is usually your ISP.
- 3
Turn the VPN on and reload the page.
- 4
Compare: the address should change and the provider should no longer be your ISP.
- 5
Repeat on each device you protect, since each one runs its own client.
Reading a DNS leak test
Every time you open a site, the device first asks a DNS server for its address. If those questions go to your ISP's servers while the VPN is on, the ISP still sees the names of the sites you visit. That is a DNS leak, and a leak test page shows which servers answered.
If the list shows your ISP, switch the client from proxy mode to full-device mode, often called VPN or TUN, and run the test again.
The browser can tell on you too
Browsers support WebRTC, the technology behind calls in a web page, and it can reveal an IP address directly. With the client in full-device mode, a WebRTC test should show the VPN address only. If it shows your home address, check the mode first; a browser setting or extension that limits WebRTC is the second step.
Why the location looks wrong
- IP location comes from commercial databases, not from GPS.
- A server's address can be listed under the city where its owner registered it.
- Databases update at different speeds, so two lookup sites can disagree.
- Without a VPN, mobile carriers often place you in a city far from where you are.
Which page to use
We do not run a checker of our own yet. Independent pages such as browserleaks.com show the IP, DNS and WebRTC results on separate tabs. Avoid lookup pages packed with download buttons, and never install anything a test page asks you to install. Run the page once with the VPN off, so you know what your own results look like before you judge the tunnel.
Questions
What is an IP check for?
To see the address and network that websites see when you visit them, and to confirm it changes when the VPN is on.
Is a DNS leak dangerous?
It does not expose passwords. It shows the names of the sites you visit to whoever runs the DNS server.
The IP changed but the city did not. Is the VPN broken?
Not necessarily. If the provider name changed, the tunnel works; the database may simply place the server near you.
How often should I run these checks?
After installing a client, after changing its mode, and on any device you set up for the first time.
Can a website still find my real location?
Through the IP, no. Through GPS permission or an account with your address, yes.