The icon says Connected. The app shows a server in Amsterdam. And yet a website you visit can still see the address your internet provider gave you, or a list of every domain you looked up today.
This is called a leak, and it is more common than most people assume. It rarely means the VPN is broken. It usually means one part of your device is quietly taking a different road to the internet than the rest.
The good news: you can check for the three common leaks yourself, in a few minutes, with nothing but a browser.
Before you start: write down your real IP
Disconnect the VPN and visit any "what is my IP" page. Note the address and the city it shows. That is what your provider assigned you, and it is exactly what should not appear once the VPN is on.
If your connection has an IPv6 address too (many mobile and fibre connections do), note that as well. It will look like a long string of letters and numbers separated by colons.
Now reconnect the VPN and run the three tests below.
Test 1: the IP leak
Reload the same "what is my IP" page with the VPN connected.
- Pass: the address and location belong to the VPN server you chose.
- Fail: you still see your own address or your own city.
A fail here is the serious kind. It usually means the tunnel did not actually come up, or a browser extension or system proxy is routing traffic around it. Disconnect, reconnect, and test again before you do anything sensitive.
Test 2: the DNS leak
Every time you open a site, your device first asks a DNS server to translate the name into an address. If those questions go to your internet provider instead of through the tunnel, the provider sees a list of every site you visit, even though the pages themselves are encrypted.
Open a DNS leak test site and run the extended test. It shows which servers answered your lookups.
- Pass: the servers belong to your VPN provider, or to a resolver in the same location as your VPN server.
- Fail: you see your internet provider's name, or servers in your home city.
Common causes are a router that forces its own DNS, a "secure DNS" setting in the browser that points somewhere else, or an operating system that keeps using the old resolver after the VPN connects.
Test 3: the IPv6 and WebRTC leak
Two quieter leaks catch a lot of people.
IPv6. Some VPN setups only tunnel IPv4. If your connection also has IPv6, websites that support it can be reached directly, outside the tunnel. On an IPv6 test page, the result with the VPN on should show either no IPv6 address or one that belongs to the VPN, never the one you wrote down earlier.
WebRTC. This is the browser feature that powers video calls. To set up a call efficiently, it can reveal your local and public addresses to the page that asks. A WebRTC leak test will show which addresses your browser is willing to share. Your real public address should not be among them.
What to do if you find a leak
- Reconnect first. A surprising number of leaks happen in the seconds after a network change, such as moving from Wi-Fi to mobile data.
- Turn off browser-level DNS overrides unless you set them up on purpose.
- Disable IPv6 on the device if your VPN does not tunnel it, or choose a provider that does.
- Limit WebRTC in the browser settings or with a reputable extension, if you do not use browser video calls.
- Test again on every network you use regularly: home, office, mobile data. A setup that is clean at home can leak on a hotel network.
Make it a habit
You do not need to test every day. Test when you install a new VPN, after a major operating system update, and the first time you connect from a new network. It takes five minutes and tells you whether the privacy you are paying for is actually there.
Korp VPN routes your traffic through an encrypted tunnel with a strict no-logs policy, and these same tests are the right way to check it, or any other VPN, for yourself.