WebRTC Leak Test

Does your browser expose your real IP address through WebRTC while you use a VPN? The test takes a few seconds and runs in your browser.

What Is a WebRTC Leak?

WebRTC is the technology that lets browsers make video calls, voice calls and file transfers without plugins. To connect directly to the other party, the browser asks a STUN server which IP address it appears to have on the internet, and that information is also available to the JavaScript running on the page. If this request travels outside your VPN tunnel while you're using a VPN, the website can see your real IP address instead of the VPN server's. That's a WebRTC leak.

How Does the Test Work?

  1. Your browser uses WebRTC to contact Cloudflare's public STUN server (stun.cloudflare.com:3478) and collects the public IP addresses WebRTC reveals.
  2. Those addresses are compared with the IP address our site sees over HTTP and with the IPv4/IPv6 addresses found by the dual-stack test.
  3. If WebRTC exposes an IP address that belongs to a different network (ASN), it's flagged as a possible leak. A different IP from the same network is normal, because carriers, especially mobile ones, may send your traffic out through a pool of shared addresses.

An ASN (autonomous system number) identifies the network that manages a group of IP address blocks, such as an internet provider, a VPN company or a data center; you can see which network any address belongs to with our IP lookup. By the nature of STUN, your IP address is sent to Cloudflare's server during the test. If WebRTC is disabled in your browser or the STUN request is blocked, the test finds no addresses, which also means no leak shows up through WebRTC.

Why Doesn't My Local IP Address Show Up?

WebRTC used to expose local network addresses such as 192.168.1.25 to any website. Since Chrome 76 (2019), Chrome has hidden them behind randomly generated mDNS names ending in .local, and current versions of Firefox and Safari do the same. That's why this test focuses on what actually matters today: public IP leaks.

How to Read Your Results

  • With your VPN off, it's normal for WebRTC to show your own IP address; there's nothing else to hide.
  • With your VPN on, if WebRTC shows only the VPN server's address, you're protected.
  • With your VPN on, if WebRTC shows an address that belongs to your internet provider, your real IP is leaking. This happens most often with browser-extension VPNs and proxies, which only route web traffic.
  • IPv6 leaks: some VPNs tunnel only IPv4 traffic and leave your IPv6 address exposed. Because the test also compares the IPv6 address from the dual-stack check, it can catch this too.

How to Prevent WebRTC Leaks

  • Turn on your VPN app's protection: use the VPN's desktop or mobile app rather than a browser extension, enable its WebRTC/leak protection and kill switch if it has them, and make sure it handles IPv6 traffic.
  • Firefox: type about:config in the address bar and set media.peerconnection.ice.default_address_only to true so WebRTC only uses your default connection (the VPN, when it's on). Setting media.peerconnection.enabled to false turns WebRTC off completely, but it also breaks video calls in the browser.
  • Brave: under Settings → Privacy and security, set the WebRTC IP handling policy to “Disable non-proxied UDP.”
  • Chrome and Edge: there's no built-in menu setting for this, so rely on your VPN app's protection or an extension you trust.
  • uBlock Origin: its “Prevent WebRTC from leaking local IP addresses” option only hid local IP addresses and never protected your public IP. Now that browsers hide local addresses themselves, the option has been removed from the desktop versions.

After changing a setting, restart the browser and run the test again. You can also check whether your IP address changes when the VPN is on from our home page, and see your IPv6 status on the IPv6 test page.

WebRTC Leak FAQ

What is a WebRTC leak?

WebRTC is the browser technology behind video calls and peer-to-peer connections. To connect, the browser asks a STUN server for its public IP address, and that information is also available to the page's code. If this request bypasses your VPN tunnel, websites can see your real IP address instead of the VPN's. That's a WebRTC leak.

What should I do if the test shows my real IP while my VPN is on?

Use your VPN provider's app instead of a browser extension and turn on its WebRTC/leak protection and kill switch. In Firefox, you can set media.peerconnection.ice.default_address_only to true; in Brave, set the WebRTC IP handling policy to “Disable non-proxied UDP.” Then restart the browser and run the test again.

Does turning off WebRTC completely cause problems?

It can. Setting media.peerconnection.enabled to false in Firefox reliably prevents WebRTC leaks, but video calls in the browser and some sites that rely on WebRTC stop working. If you use those services, rely on your VPN app's protection instead of disabling WebRTC.

Why doesn't my local IP address show up in the test?

Current versions of Chrome, Edge, Firefox and Safari hide local IP addresses such as 192.168.x.x behind randomly generated .local names (mDNS). Websites can't see your local address, so the test checks for what actually matters: public IP leaks.