Run a free VPN leak test for WebRTC and IPv6, identify your DNS resolver, or check your public IP via browser and curl. RookCheck shows what websites actually see when your VPN is on.
A connected VPN icon is not enough. WebRTC STUN requests and untunneled IPv6 can still expose your real IP. Identify which DNS resolver you use and compare it to your VPN's expected DNS.
Compare your terminal exit IP with the browser result. If they differ, split tunneling or a misconfigured client may be leaking.
curl -s https://rookvpn.com/check/api/ip/address
Public IPv4/IPv6 visibility, DNS resolver ownership, WebRTC ICE candidates, canvas/WebGL/font fingerprint signals, and browser system info — all free, no account required.
Free VPN Leak Test & Public IP Checker exists to show what a website can still see while a VPN says connected: public IP, DNS resolver, WebRTC candidates, and IPv6. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.
Work through Free VPN Leak Test & Public IP Checker in order. 1. Disconnect the VPN and note the IP and DNS you see on the home network. 2. Connect the VPN and reload the leak test. 3. Confirm the public IP changed and that WebRTC does not still list the home address. 4. Run the curl IP check from a terminal on the same machine and compare. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.
A green VPN icon is not a test. One resolver address is not automatically a leak; compare it to the DNS your VPN claims to use. Browser checks do not see traffic from other devices on your LAN. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.
Example: at home the page shows a cable-ISP address and the ISP resolver. After connecting, the public IP should be the VPN exit. If WebRTC still prints 192.168.x.x or the old public IP, the browser is punching out beside the tunnel. Fix WebRTC or the VPN profile, then reload. Do not declare success from the IP box alone.
After you finish Free VPN Leak Test & Public IP Checker, open the curl IP example and the written leak-test guide if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.
Use Free VPN Leak Test & Public IP Checker for one job: to show what a website can still see while a VPN says connected: public IP, DNS resolver, WebRTC candidates, and IPv6. Bring the before-and-after evidence with you if you change a setting. A VPN icon, a decoded token, a generated password, or a stripped file is not finished until you have checked the output the way this page describes. Then follow the related guide for the long version, and the sibling tool only when the next job is actually different. Keep secrets out of the same message as the link or the file that needs them. If a second run does not match the first, stop and find what changed instead of publishing the first result.
Example: at home the page shows a cable-ISP address and the ISP resolver. After connecting, the public IP should be the VPN exit. If WebRTC still prints 192.168.x.x or the old public IP, the browser is punching out beside the tunnel. Fix WebRTC or the VPN profile, then reload. Do not declare success from the IP box alone. Work the page in this order: Disconnect the VPN and note the IP and DNS you see on the home network. Connect the VPN and reload the leak test. Confirm the public IP changed and that WebRTC does not still list the home address. Run the curl IP check from a terminal on the same machine and compare. Limits that still apply after a clean result: A green VPN icon is not a test. One resolver address is not automatically a leak; compare it to the DNS your VPN claims to use. Browser checks do not see traffic from other devices on your LAN.
Yes. Every RookCheck privacy and leak test on rookvpn.com/check is free with no signup.
Yes. Connect NordVPN, ExpressVPN, Mullvad, WireGuard, OpenVPN, Hiddify, or any other client, then run the leak tests and compare to your disconnected IP.
A VPN leak is any path where your real IP or WebRTC candidates leave the encrypted tunnel — even while the VPN client says Connected. DNS should be compared to your VPN's expected resolver.
Yes. The checks on rookvpn.com/check run without an account.
Yes. It measures the network you are on. It does not require a RookVPN subscription.
Compare the connected result with a disconnected result, and compare the browser with curl on the same computer.