Free VPN leak test for WebRTC and IPv6, plus a DNS resolver identity check. Connect your VPN, run each check, and confirm only expected VPN IPs appear.
IP leaks show your real public address. The DNS check reports which resolver answers your queries so you can compare it to your VPN. WebRTC leaks expose local/public IPs via STUN. IPv6 leaks bypass tunnels that only handle IPv4.
1) Note your real IP while disconnected. 2) Connect the VPN. 3) Run WebRTC, DNS, and IPv6 tests. 4) Confirm only VPN IPs and resolvers appear. 5) Disconnect and re-check to compare.
Pair this suite with curl IP checks on rookvpn.com/curl so terminal and browser exit paths both look clean.
VPN Leak Test exists to run WebRTC, DNS, and IPv6 checks as one leak suite while the VPN is connected. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.
Work through VPN Leak Test in order. 1. Record the disconnected IP first. 2. Connect the VPN. 3. Open WebRTC, DNS, and IPv6 on this suite. 4. Pass only if each channel shows the VPN path or is absent on purpose. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.
The suite does not configure your VPN for you. A single DNS address is an identity to compare, not an automatic fail. It cannot test apps that do not use this browser. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.
Example: WebRTC lists only the VPN address, DNS is the VPN resolver, and IPv6 shows no address because you disabled it. That is a pass. If IPv6 shows the ISP prefix, the v4 tunnel is fine and v6 is not. Fix v6 before you call the VPN sealed.
After you finish VPN Leak Test, open the individual WebRTC, DNS, and IPv6 pages if one channel failed if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.
Use a tool that checks IP, WebRTC, IPv6, and DNS resolver identity — not just one address. RookCheck runs those channels for free.
Any path where traffic or metadata exits outside the encrypted VPN tunnel, revealing your real IP or DNS queries.
Disabling or limiting WebRTC prevents STUN-based IP leaks. Many privacy browsers block non-proxied UDP by default.
Any path that still reveals your home IP or sends DNS to a resolver you did not choose, while the client says connected.
Yes. IP-only tests miss WebRTC and IPv6.
After every VPN profile change, browser update, or new network, including hotel and phone hotspots.