WebRTC Leak Test
See which public IPs your browser exposes beyond the web connection, checked by six sources.
Testing…
WebRTC Leak Test
Testing…- Addresses WebRTC exposes
- Testing…
- NAT type (inferred)
- Testing…
Current networkPublic IPs seen by web requests
- Current public IPv4
- Testing…
- Current public IPv6
- Testing…
WebRTC sources6 independent STUN sources
| Source | Public IP | Protocol | Network comparison |
|---|---|---|---|
| Testing… | |||
| Cloudflare | Testing… | ||
| Twilio | Testing… | ||
| FreeSWITCH | Testing… | ||
| Nextcloud | Testing… | ||
| BlackBerry | Testing… |
How the WebRTC leak test works
-
Record your current public addresses
Public echo services return your current IPv4 and IPv6 as the baseline.
-
Collect addresses from 6 STUN sources
Before WebRTC connects, a STUN service observes the connection externally and returns a server-reflexive address: the public IP the browser may expose.
-
Compare IPv4 and IPv6 separately
Web requests and WebRTC can take different paths. When a VPN or proxy handles web traffic while WebRTC leaves through another interface, an additional public address appears.
Reading the result
- Current network IPThe WebRTC address matches the current public address in its family and is part of the current exit.
- Additional public IPIt matches no current address in its family, and the page reports a leak.
- Cone NATOne local port keeps the same public port for every server.
- Symmetric NATEach destination sees a different public port, so direct peer-to-peer connections are harder to set up.
- Cannot tellToo few sources answered, or there are several network paths.
Frequently asked questions
What is WebRTC?
WebRTC is a browser capability for real-time audio, video, and peer-to-peer data. Before a connection can be made, the browser has to discover network addresses that both sides can reach. A STUN service observes the connection externally and returns a server-reflexive address, which is the public IP shown in the result.
Why can web requests and WebRTC see different addresses?
A normal web request and a WebRTC connection can use different network paths. If a VPN or proxy handles web traffic while WebRTC leaves through another interface, a site may see a public address outside the expected exit. The test finds that additional address.
Why is there no leak when both IPv4 and IPv6 are found?
A dual-stack network can normally use one public IPv4 and one public IPv6 at the same time. When each WebRTC address matches the current public address for its own family, both are normal exits for the current network.
When does the page report a WebRTC IP leak?
When a WebRTC public IP does not match a current address in the same family, the page lists it as an additional exit and reports a leak.
What should I change after a WebRTC leak is found?
Turn on WebRTC protection in your proxy or VPN client, or switch to a mode that carries all traffic (such as TUN or global mode) so WebRTC uses the same exit; a browser setting or extension can also limit WebRTC to the proxy. Run the test again afterwards; the additional address should be gone.
Why did none of the 6 sources answer?
The most common cause is a proxy app in TUN or fake-ip mode: the names of the STUN servers resolve to placeholder addresses in 198.18.0.0/15 and the browser reports a failed address lookup; or the proxy or firewall does not pass UDP, so STUN requests get no answer. The page then shows No public address obtained and the details give the reason for each source. A site that wants your public IP through WebRTC has to use STUN in the same way; when STUN does not get through, the site cannot get it either, so this is not a leak. To find out whether WebRTC would expose another address, test again on a network or mode that passes UDP.
How is the NAT type inferred?
While the 6 independent sources are checked, the page opens one more connection in which a single local port asks the first three sources (Google, Cloudflare, Twilio) together. One mapped port for a public address, with at least two of those three answering their own check, suggests a cone NAT; several mapped ports suggest a symmetric NAT; otherwise the result is Cannot tell. When the device is on several networks at once, several ports need not mean a symmetric NAT, so that case also shows Cannot tell.
Start an IP lookup
See location, network ownership, network property, and provider risk results.