Two address paths
HTTPS lookups reveal the address used for web requests. WebRTC gathers connection candidates. Different proxy or VPN routing rules can make these addresses differ; compare unexpected addresses with your expected VPN exit.
IPv6 and local candidates
VPNs may handle IPv4 and IPv6 differently. Host candidates describe local interfaces; mDNS .local names can conceal private addresses. Private local addresses are reported separately from additional public addresses.
No answer is inconclusive
Firewalls, extensions and browser policies can prevent STUN replies. A timeout or missing HTTPS reference makes comparison incomplete. This describes observed browser behavior, not every application or VPN path.
Two independent STUN providers
Separate peer connections query Google and Cloudflare. Comparing them can reveal different NAT mappings or a provider-specific failure. No connection to another user is established and TURN relays are not tested.
What leaves your device
After Start, ipify and Cloudflare receive HTTPS requests, while Google and Cloudflare receive STUN traffic. They see your public IP. The candidate report stays in this tab; no microphone or camera permission is requested.