IPv6 Leak Test

Free IPv6 leak test for VPN users. Many VPNs tunnel IPv4 only — dual-stack networks can still reveal your identity over IPv6.

IPv6 and VPN tunnels

When IPv6 is on at the router but the VPN has no IPv6 address, browsers may prefer IPv6 for dual-stack sites and bypass the encrypted tunnel.

How to stop IPv6 leaks

Disable IPv6 on the OS/router, or use a VPN that supports IPv6 and blocks native IPv6 when disconnected.

How this page is different

IPv6 Leak Test exists to see whether this browser still has a working IPv6 path when the VPN only tunnels IPv4. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.

Do this on the page

Work through IPv6 Leak Test in order. 1. Check whether the page shows an IPv6 address. 2. If it does, see whether that prefix belongs to your ISP. 3. Disable IPv6 or switch to a VPN profile that tunnels it. 4. Reload until IPv6 is gone or belongs to the VPN. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.

What this page will not decide for you

No IPv6 address is a pass if you disabled IPv6 on purpose. An IPv6 address at the VPN provider is not a leak. The test only sees this browser. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.

A concrete example

Example: IPv4 on the main check is a datacenter address, and this page shows 2001:db8 from the ISP. Dual-stack sites will prefer IPv6 and skip the tunnel. Disable IPv6 on the adapter or use a profile with IPv6, then confirm this page no longer shows the ISP prefix.

Where to go next

After you finish IPv6 Leak Test, open the public IP check to confirm IPv4 is still the VPN exit if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.

Frequently asked questions

Should I disable IPv6 for VPN privacy?

If your VPN lacks IPv6 support, disabling IPv6 prevents accidental bypass leaks.

How common are IPv6 leaks?

Common on home networks with ISP IPv6 and VPN clients that only handle IPv4.

Is missing IPv6 a problem?

Not for leak testing. It means there is no second path.

Should I disable IPv6 forever?

Disable it when the VPN cannot carry it. Turn it back on if you move to a VPN that tunnels IPv6.

Does this test DNS?

No. DNS is the resolver page. IPv6 here is the address family of the connection.

Check home VPN leak testing guide Run curl online Free VPN profiles
RookCheck Home VPN Leak Test WebRTC Leak Test DNS Leak Test Check Public IP Fingerprint Test Online Curl Tool Encrypted File Sharing Free VPN