WebRTC Leak Test

Compare HTTPS and WebRTC addresses using two STUN providers. Inspect IPv4, IPv6 and local candidates without microphone or camera permissions.

Runs in your browser

Explicit start · Google + Cloudflare STUN · no camera or microphone access · no TURN relay test

Starts only when you press Start test. HTTPS requests go to ipify and Cloudflare; STUN requests go to Google and Cloudflare. These providers see your public IP. No microphone or camera permission is requested, and candidates are not uploaded to our server.

Google: stun:stun.l.google.com:19302, stun:stun1.l.google.com:19302
Cloudflare: stun:stun.cloudflare.com:3478

This compares addresses visible to this browser, not every application or VPN route. No STUN response is inconclusive. TURN relays are not tested. An extra address is a reason to check VPN routing, not proof that the VPN is broken.

Two address paths

HTTPS lookups reveal the address used for web requests. WebRTC gathers connection candidates. Different proxy or VPN routing rules can make these addresses differ; compare unexpected addresses with your expected VPN exit.

IPv6 and local candidates

VPNs may handle IPv4 and IPv6 differently. Host candidates describe local interfaces; mDNS .local names can conceal private addresses. Private local addresses are reported separately from additional public addresses.

No answer is inconclusive

Firewalls, extensions and browser policies can prevent STUN replies. A timeout or missing HTTPS reference makes comparison incomplete. This describes observed browser behavior, not every application or VPN path.

Two independent STUN providers

Separate peer connections query Google and Cloudflare. Comparing them can reveal different NAT mappings or a provider-specific failure. No connection to another user is established and TURN relays are not tested.

What leaves your device

After Start, ipify and Cloudflare receive HTTPS requests, while Google and Cloudflare receive STUN traffic. They see your public IP. The candidate report stays in this tab; no microphone or camera permission is requested.

How to use

  1. Indicate whether you are using a VPN or proxy.
  2. Start the test and wait about eight seconds for ICE gathering.
  3. Compare HTTPS and WebRTC addresses and read incomplete-result notices.
  4. Enable address masking before copying a report for sharing.

FAQ

Does this use a microphone or camera?

No. A data channel triggers ICE gathering without requesting media.

Does an extra address prove a VPN leak?

It warrants investigation, but NAT, multiple interfaces and incomplete HTTPS observations also affect the comparison.

Are TURN relays tested?

No. This test uses public STUN servers without TURN credentials.

Does masking fully anonymize a report?

No. Address prefixes and other network details remain; review the copied report before sharing.

Related tools

More Internet tools: Internet

Send feedback

Found a bug or have an idea? Tell us — it helps make the tools better.

Only needed if you would like a reply.

Page: /internet/webrtc-leak-test/