Free WebRTC leak test: see whether your browser exposes local or public IPs through STUN even when a VPN is active.
Browsers use ICE/STUN for peer connections. Those requests can return your real public IP before the VPN adapter is used, leaking identity to any page running JavaScript.
Pass: only your VPN exit IP (and expected local/mDNS candidates). Fail: your ISP public IP appears alongside or instead of the VPN IP.
Disable WebRTC in Firefox (media.peerconnection.enabled), use a leak-prevention extension in Chrome/Edge, or pick a VPN client that forces WebRTC through the tunnel.
WebRTC Leak Test exists to list ICE candidates from a browser STUN check so you can see addresses WebRTC exposes beside the VPN. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.
Work through WebRTC Leak Test in order. 1. Connect the VPN first. 2. Start the WebRTC check and wait for candidates. 3. Look for private LAN addresses and for your real public IP. 4. If they appear, restrict WebRTC in the browser and test again. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.
A candidate that matches the VPN exit is expected. Host candidates in 10/8, 172.16/12, or 192.168/16 are local, and a site can still learn them. Turning WebRTC off can break legitimate calls. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.
Example: candidates include 192.168.1.20 and the ISP public IP while the page header shows the VPN IP. The page header is the HTTP path. WebRTC took another path. Install a WebRTC control or use a browser that forces non-proxied UDP through the tunnel, then rerun until those two addresses are gone.
After you finish WebRTC Leak Test, open the DNS check next, because a clean WebRTC result says nothing about resolvers if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.
It can. Unless WebRTC is disabled or the VPN blocks STUN, browsers may still expose your real IP to websites.
Yes. Run it anytime at rookvpn.com/check/vpn-leak-test/webrtc with no account.
An address the browser discovered for a peer connection, gathered by asking a STUN server.
It tells the page your LAN address. Treat it as a leak if you expected the VPN to hide the machine.
Blocking WebRTC stops the leak and also stops browser calling. Use a per-site exception if you need both.