IPv6 leak test

An IPv6 leak happens when your VPN or proxy only handles the older IPv4 traffic, so everything your device sends over IPv6 goes out directly through your provider – and websites see the real address of your connection. To check, open this page with the VPN off and note both addresses, then turn the VPN on and reload. If the IPv4 line changed but the IPv6 line did not, it is leaking. The check runs on our own servers, we do not store visitor addresses, and there is nothing to sign up for.

Updated 11 August 2026

Your address right now 216.73.217.21 full check

Leak checks

If you use a VPN, these checks show whether the browser reveals your real address around it.

  • WebRTC leakchecking…
  • IPv6 addresschecking…
  • Timezonechecking…

Two addresses, not one

Every device on the internet needs an address, or the answers to your requests would have nowhere to come back to. The old system, IPv4, dates from the early 1980s and writes addresses as four numbers, like 203.0.113.42. There are about four billion of them in total. That seemed endless at the time, and they ran out anyway.

IPv6 is the replacement. Its addresses are much longer and mix numbers with letters, separated by colons – 2001:db8:85a3::8a2e:370:7334 – and there are enough of them for every device on the planet several times over. Most home connections and almost all mobile networks now hand out both kinds at once: one IPv4 address and one IPv6 address.

That is the whole problem in one sentence. Your device has two addresses, and any tool that thinks about only one of them leaves the other one out in the open.

Why IPv6 slips past a VPN

When a VPN or a proxy is running, your traffic is supposed to leave through its servers, so a website sees that server's address instead of yours. Plenty of these tools were built when IPv4 was the only thing that mattered, and they pick up IPv4 traffic only.

So this happens. You open a site that has both an IPv4 and an IPv6 address. Your system prefers IPv6 – that is the default on Windows, macOS, Android and iOS – so the request goes out over IPv6, straight through your provider and past the VPN entirely. The site records your real IPv6 address. The connection indicator stays green the whole time.

An IPv6 address can say more about you than an IPv4 one. Providers usually hand a whole block of IPv6 addresses to a single household, and that block often stays with the same line for months, so it works as a steady label even when the individual address changes.

The reverse happens on connections that are IPv6-only, where the IPv4 request is the one that escapes. Either way, the first step is the same: find out which address is actually visible right now.

How to test for an IPv6 leak

A leak test is really just a comparison – the address your provider gave you, against the address a website actually sees.

  1. Turn your VPN or proxy off and open the IPgeo front page. Write down both addresses it shows: the IPv4 one, and the IPv6 one if your provider gives you one.
  2. Turn the VPN or proxy back on and reload the page.
  3. Compare. If the IPv4 line changed but the IPv6 line is still the address you wrote down, that is an IPv6 leak. If the IPv6 line is empty or says there is no address, nothing is getting out over IPv6.

The same page also checks WebRTC – a separate way a browser can give out your local and public addresses – and it compares your time zone with the country of the address it sees. Everything is worked out on our own servers. We do not store visitor addresses, there are no third-party trackers and no ads, and none of it needs an account.

If you want the raw result for a script or a status page, api.ipgeo.ru returns the same data as plain JSON – no keys, no sign-up.

The test found a leak – now what

First, what the result actually means. A visible IPv6 address means every site you open can see the address your provider assigned to your line, and so can anything loaded inside those pages – analytics, ad scripts, comment widgets. It does not mean anyone has your name or your street. It does mean the address is a dependable way to recognize the same household again and again.

There are two practical ways out. One is to switch IPv6 off on the device or on the router, so there is no second address to leak – the instructions are below. The other is to use a tool that handles both versions of the address, so your requests leave through its servers whichever version they use.

That second option is what our own Chrome extension, AnonVPN, does: it sends browser traffic through our servers over both IPv4 and IPv6, so sites see the server address rather than the one your provider gave you. It is not a cloak – your provider still sees that you are connected, and any site you sign in to still knows exactly who you are – but the address on the page stops being yours.

How to turn IPv6 off on Windows

Windows lets you switch IPv6 off for each network adapter separately, and the change takes effect straight away.

  1. Press Win + R, type ncpa.cpl and press Enter. The list of network connections opens.
  2. Right-click the connection you actually use – Wi-Fi or Ethernet – and choose Properties.
  3. In the list of items, find Internet Protocol Version 6 (TCP/IPv6) and clear its checkbox. Leave Version 4 alone.
  4. Click OK, then disconnect and reconnect the network, or simply restart the computer.

If you have several adapters – a cable one, Wi-Fi, a virtual adapter added by a VPN app – do this for every one of them, or traffic will just take whichever adapter still has IPv6 switched on. Run the leak test again afterwards to confirm the IPv6 line is now empty.

macOS, Android and the router

macOS. Open System Settings, go to Network, select the connection, click Details, then the TCP/IP tab. Set Configure IPv6 to Link-local only. Local network features keep working, but IPv6 traffic no longer reaches the internet. If the menu is grayed out, the same thing can be done in Terminal with: networksetup -setv6off Wi-Fi (use Ethernet instead of Wi-Fi if you are on a cable).

Android. There is no single switch for the whole phone, and it depends on how you are connected. On mobile data, open Settings, then Network and internet, then SIMs, then Access Point Names, tap your APN and set APN protocol to IPv4. On Wi-Fi the IPv6 address comes from the router, so the router is the sensible place to fix it.

Router. Open the admin page in a browser – usually 192.168.0.1 or 192.168.1.1 – sign in, and look for an IPv6 section under the internet or WAN settings. Set it to Disabled and save. Every device in the house then stops receiving IPv6 addresses. This is the most thorough option and the right one if you also have phones, a TV and consoles on the same network. Some providers deliver IPv6 in a way that survives this setting, so run the test again once the router has restarted.

iPhone and iPad. iOS gives you no IPv6 switch at all, so the router is the only lever you have.

Should you switch IPv6 off at all

Not always. IPv6 is not a flaw – it is the version the internet is slowly moving to, and on some mobile networks it is the main way you connect. Switching it off can make a few things slower, and now and then a site that is only reachable over IPv6 will not open.

A reasonable rule of thumb: if you do not use a VPN or proxy, leave IPv6 on. It changes nothing about who can see your address, because your IPv4 address is just as visible anyway. If you do use one, either check that it handles IPv6 properly, or switch IPv6 off so there is only one address to think about.

And keep the expectations honest. Switching IPv6 off closes one specific way your provider's address reaches a website. It does not make you anonymous, it does nothing about cookies, logins or browser fingerprinting, and your provider still knows which connections you opened. One door closed, not the whole house.

If the check keeps showing the address your provider gave you, our Chrome extension AnonVPN sends browser traffic through our own servers – over both IPv4 and IPv6 – so sites see the server address instead of yours.

AnonVPN extension in Chrome Web Store

Frequently asked questions

What is an IPv6 leak?

It means your VPN or proxy is handling IPv4 traffic only, while requests that go over IPv6 leave directly through your provider. Websites then see the real IPv6 address of your connection, even though the VPN looks like it is working.

How do I test for an IPv6 leak?

Open the IPgeo front page with your VPN off and note both addresses, then turn the VPN on and reload. If the IPv4 line changed but the IPv6 line is exactly the same address as before, it is leaking. An empty IPv6 line means nothing is getting out that way.

What is the difference between IPv4 and IPv6?

IPv4 addresses look like 203.0.113.42, and there are only about four billion of them, which is why they ran out. IPv6 addresses are much longer, mixing numbers and letters separated by colons, and there are effectively no limits on how many exist. Most connections today use both at the same time.

How do I disable IPv6 on Windows?

Press Win + R, type ncpa.cpl and press Enter, right-click the connection you use, choose Properties, and clear the checkbox next to Internet Protocol Version 6 (TCP/IPv6). Do this for every adapter you have, then reconnect the network and run the test again.

Will turning IPv6 off slow anything down?

Usually you will not notice. A few sites take a moment longer to open, and very occasionally a site that is only reachable over IPv6 will not load at all. If that happens, switch IPv6 back on for the adapter and use a tool that handles both address versions instead.

Does disabling IPv6 make me anonymous?

No. It removes one address from the picture, nothing more. Cookies, accounts you sign in to and browser fingerprinting still identify you, and your provider still sees which connections you open.

Can I get the result as JSON?

Yes. api.ipgeo.ru returns the same data in plain JSON, with no keys and no sign-up, so you can use it in a script or on a status page.

More on this