IPv6 Leak Test & Fix
When IPv6 is enabled locally but not tunneled, websites may see your real ISP IPv6 address even if IPv4 goes through the VPN.
Many VPN tests focus on IPv4 only. Modern networks advertise IPv6 globally. If your VPN client tunnels IPv4 but leaves IPv6 on the local interface, dual-stack sites can learn your non-VPN address through IPv6 DNS or direct v6 connections.
Test with RookCheck
- Connect your VPN.
- Open rookvpn.com/check/vpn-leak-test/ipv6.
- Pass: only VPN-related IPv6 ranges appear (or IPv6 is disabled consistently).
- Fail: your ISP’s IPv6 prefix appears alongside or instead of the tunnel.
Repeat in the same browser you use for daily work — extensions and split tunnel rules differ per profile.
Operating system mitigations
Windows: Disable IPv6 on the physical adapter temporarily for testing, or use a VPN client that documents full-tunnel IPv6 support. Advanced users can adjust interface metrics so the VPN adapter wins.
macOS: System Settings → Network → your interface → Details → TCP/IP — set Configure IPv6 to Link-local only during tests, or disable if your VPN vendor recommends it.
Linux: Inspect ip -6 route. A default route via the physical interface while VPN is up often causes leaks. NetworkManager and systemd-networkd can leave stale v6 routes after reconnect — cycle airplane mode or restart networking after VPN connect.
Mobile: Cellular IPv6 is common. Verify Hiddify TUN mode on Android/iOS; proxy-only modes may not cover all v6 traffic.
Router considerations
Home routers that advertise ULA or ISP IPv6 to LAN clients can expose v6 to every device. Put the testing device on VPN before evaluating router-level IPv6 passthrough for smart TVs or consoles.
When disabling IPv6 is acceptable
Disabling IPv6 locally is a pragmatic fix when your VPN provider does not yet publish IPv6 exit addresses. You trade dual-stack reachability for consistent privacy — document the choice for your team.
Related
Check the result
Reload the IPv6 check after you disable IPv6 or switch to a profile that tunnels it. No address is a pass when you disabled IPv6 on purpose. An address in your ISP’s prefix is not. An address at the VPN provider is the tunnel working.
Confirm IPv4 is still the VPN exit on the public IP page. Disabling IPv6 must not also drop the v4 tunnel. Retest WebRTC afterward. It is a third path and it does not follow from this page.