Why "Connected" Isn't the Same as "Private"
Every VPN app shows the same reassuring signal: a green dot, a lock icon, the word "Connected." None of that confirms your traffic is actually private. A VPN tunnel can be fully active for your main browsing while three specific categories of traffic — DNS lookups, WebRTC connections, and IPv6 packets — slip outside it entirely, depending on your operating system, browser, and VPN configuration. This guide exists because those three leak types get asked about constantly, and each one needs its own explanation and its own test.
The Three Leaks a Status Icon Won't Catch
Run the two fastest checks first — both take under a minute and need nothing installed.
Run the DNS Leak Test → Run the WebRTC Leak Test →Complete Guide Library
Every DNS, WebRTC, and VPN privacy guide on this site, grouped by what you're trying to figure out:
Is my VPN actually protecting me?
- Is My VPN Working? — the three-step check beyond the status icon
- Check VPN Leaks: VPN Privacy Audit Checklist — a repeatable checklist to run every time you connect
- How to Hide Your IP Address — four methods that actually work, and their trade-offs
DNS leaks
- What Are DNS Leaks? — the plain-language explanation
- How to Prevent DNS Leaks — fixes by platform and VPN client
- DNS Leak Test — How to Run One and Read Your Results — what a clean result looks like vs. a leak
WebRTC leaks
- What Is a WebRTC Leak? Why It Matters and How to Check — the plain-language explanation
- WebRTC Leak Test — How to Run One and What the Results Mean — reading your test results
- Test Browser for WebRTC Leaks — a browser-by-browser walkthrough
- How to Disable WebRTC in Every Major Browser — step-by-step settings for each browser
- Does Private Mode Prevent WebRTC Leaks? — why private browsing alone isn't enough
- What Is a WebRTC Leak Shield? — extensions that block the leak at the source
How Often to Re-Check
Leaks don't appear randomly — they cluster around specific moments: right after installing or updating a VPN app, right after switching servers or protocols, and after an operating system update that can quietly reset network settings. Building a quick DNS and WebRTC check into those moments, rather than waiting until something feels wrong, catches most leaks before they become a habit. The VPN Privacy Audit Checklist above turns this into a two-minute routine.
For more background, see the Electronic Frontier Foundation (www.eff.org).
Frequently Asked Questions
What does a VPN privacy guide need to cover?
A real VPN privacy guide covers three leak types that a simple "connected" status doesn't rule out: DNS leaks, WebRTC leaks, and IPv6 leaks. Each has its own test and its own fix, and a VPN can be protected against one while still exposed to another.
Is a DNS leak the same as a WebRTC leak?
No. A DNS leak exposes which sites you visit because lookups bypass the VPN tunnel. A WebRTC leak exposes your real IP address directly through a browser feature used for video calls. They require separate tests and separate fixes.
How often should I re-check my VPN for leaks?
Re-check after every VPN app update, after switching servers or protocols, after any operating system update, and periodically during regular use, since leaks are often introduced silently by a routine update.
Can incognito or private browsing mode stop a WebRTC leak?
Not by itself. Private browsing mode clears history and cookies, but it does not disable the WebRTC feature that can expose your real IP address, so a separate WebRTC leak test is still necessary.
Where do I start if I've never tested my VPN before?
Start with a DNS leak test and a WebRTC leak test — together they take under two minutes and catch the two most common leak types, then work through the IPv6 and audit-checklist guides above for a complete check.