GhostTouchTest.com

VPN Privacy Guide

Last updated: · 7 min read

This VPN privacy guide covers the three leaks a green "connected" icon never rules out — DNS, WebRTC, and IPv6 — plus every DNS, WebRTC, and VPN guide on this site in one place, organized by what you're trying to check.

VPN privacy guide shield icon

Why "Connected" Isn't the Same as "Private"

Every VPN app shows the same reassuring signal: a green dot, a lock icon, the word "Connected." None of that confirms your traffic is actually private. A VPN tunnel can be fully active for your main browsing while three specific categories of traffic — DNS lookups, WebRTC connections, and IPv6 packets — slip outside it entirely, depending on your operating system, browser, and VPN configuration. This guide exists because those three leak types get asked about constantly, and each one needs its own explanation and its own test.

The Three Leaks a Status Icon Won't Catch

🌐
DNS leak Domain lookups go to your ISP's servers instead of through the VPN tunnel, exposing which sites you visit
📹
WebRTC leak A browser feature built for video calls can expose your real IP address even with a VPN active
6️⃣
IPv6 leak IPv6 traffic bypasses a VPN that only tunnels IPv4, exposing your real network address directly

Run the two fastest checks first — both take under a minute and need nothing installed.

Run the DNS Leak Test → Run the WebRTC Leak Test →

Complete Guide Library

Every DNS, WebRTC, and VPN privacy guide on this site, grouped by what you're trying to figure out:

Is my VPN actually protecting me?

DNS leaks

WebRTC leaks

How Often to Re-Check

Leaks don't appear randomly — they cluster around specific moments: right after installing or updating a VPN app, right after switching servers or protocols, and after an operating system update that can quietly reset network settings. Building a quick DNS and WebRTC check into those moments, rather than waiting until something feels wrong, catches most leaks before they become a habit. The VPN Privacy Audit Checklist above turns this into a two-minute routine.

For more background, see the Electronic Frontier Foundation (www.eff.org).

Frequently Asked Questions

What does a VPN privacy guide need to cover?

A real VPN privacy guide covers three leak types that a simple "connected" status doesn't rule out: DNS leaks, WebRTC leaks, and IPv6 leaks. Each has its own test and its own fix, and a VPN can be protected against one while still exposed to another.

Is a DNS leak the same as a WebRTC leak?

No. A DNS leak exposes which sites you visit because lookups bypass the VPN tunnel. A WebRTC leak exposes your real IP address directly through a browser feature used for video calls. They require separate tests and separate fixes.

How often should I re-check my VPN for leaks?

Re-check after every VPN app update, after switching servers or protocols, after any operating system update, and periodically during regular use, since leaks are often introduced silently by a routine update.

Can incognito or private browsing mode stop a WebRTC leak?

Not by itself. Private browsing mode clears history and cookies, but it does not disable the WebRTC feature that can expose your real IP address, so a separate WebRTC leak test is still necessary.

Where do I start if I've never tested my VPN before?

Start with a DNS leak test and a WebRTC leak test — together they take under two minutes and catch the two most common leak types, then work through the IPv6 and audit-checklist guides above for a complete check.