A free online VPN checker that measures your connection twice, before and after you connect, instead of showing one reading and leaving you to guess. It tells you what your VPN really hides, what still leaks past it, and what it costs you in speed.
Step 1 of 2
We need a picture of your ordinary connection first. Make sure your VPN is disconnected, then take the baseline.
Most VPN checker tools load a page, read your IP address, and show it back to you. That tells you what your address is now, but not whether your VPN changed anything — and changing it is the only job a VPN has. This one works differently. You run it once with the VPN off, once with it on, and it compares the two: your IP address, your network provider, your apparent location, the address your browser hands out through WebRTC, and your IPv6 address. Whatever stayed the same is something your VPN is not protecting, and the tool names it.
It works with any provider — NordVPN, Proton, Surfshark, Mullvad, ExpressVPN, your employer's corporate VPN, or a browser extension — because it never asks which one you use. It only compares what websites can see before and after — the one measurement that holds regardless of who made the software.
It is free, runs entirely in your browser with no login and no account, and stores nothing about you. The leak checks never leave your device. Speed is measured by Cloudflare's open-source engine against their nearest server, so the figures line up with the speed tests you already use.
A single reading cannot tell you, because it has nothing to compare against. The reliable way is a before-and-after check: measure what websites can see with the VPN off, connect it, measure again, and compare. Anything that stayed the same is something the VPN is not protecting. That is what this page does, for your IP address, your network provider, your apparent location, WebRTC and IPv6 — and it grades the result by how much of that identifying detail actually changed.
Your IP address is the headline, and the first thing this checker compares: with a working VPN the address sites see belongs to the VPN server, not to your provider. But an IP check alone is not enough, which is where most tools stop. Your network provider's name and your apparent city are read from the same address and should move with it. Your browser can hand out a second address through WebRTC that never passes through the tunnel at all. Your IPv6 address frequently escapes even when IPv4 is routed correctly, because many VPN clients tunnel one and ignore the other. And your device's clock still reports your real timezone, which any site can compare against your apparent location. This tool checks all five and grades them together.
Browsers ship a built-in calling system, WebRTC, that discovers your network address so calls can connect directly. Any page can quietly ask it for that address, with no permission prompt, and the answer can come from outside your VPN tunnel. That is a WebRTC leak: your real address on display while the VPN icon says connected. Browser-extension VPNs are especially prone to it, because they route web traffic but usually not WebRTC. This check compares the address WebRTC hands out against the address the site actually sees, which is the test that matters.
Every packet takes a detour through the VPN server and gets encrypted on the way, so some cost is normal; how much depends on the server's distance and load. The honest way to size it is to measure the same route before and after connecting, at the same time of day — line speed drifts across the day, which is why this page warns you when your baseline has gone stale. Free servers commonly cost more than half of your bandwidth; a good paid server nearby can cost almost nothing. One more wrinkle: many relays limit speed per connection, so a single download can crawl even when a speed test, which opens many connections at once, shows a healthy total. This page measures with parallel connections too, so its number lines up with other testers.
It hides the location guessed from your address, which moves to the VPN server's city. It does not move your device's clock or its actual position, so a site that compares your timezone with your address can still tell a VPN is in use even though it cannot see through it. Location from an address is approximate anyway: it points at provider infrastructure, often a mobile carrier's gateway city many kilometres away, not at your device. The details drawer above can measure that gap precisely, on your device, with your permission.
Location is guessed from who owns your address block, not from your device, so even with no VPN it often points at your provider's gateway city rather than your town — a mobile user in one city is routinely placed in another. With a VPN on, sites should see the VPN server's city instead. If the location shown is neither of those, something may be leaking, and the before-and-after check above will show what.
"Connected" only means a tunnel to the server exists; it says nothing about what actually travels through it. Browser-extension VPNs cover one browser and usually leave WebRTC alone, split tunneling excludes whole apps, and plenty of VPNs quietly let IPv6 out over the ordinary connection. That is why this page compares before and after instead of trusting the connected icon: it shows which parts of your identity really changed.
Open this page in the phone's browser and run the same two steps there. Coverage is per device: a VPN app on your laptop does nothing for your phone, and a browser extension protects only that one browser on that one machine, which is exactly the kind of gap a per-device check makes visible.
Partly, and it is worth knowing exactly where the limit is. This checker measures your browser. A torrent client is a separate application with its own connection, so a clean result here does not prove your torrent traffic is going through the tunnel. They genuinely diverge in common setups: split tunneling routes chosen apps around the VPN, some clients bind to a specific network adapter, and a browser extension VPN covers only that browser and nothing else on the machine. It does tell a torrent user whether the VPN works on this device at all, whether IPv6 is escaping, and what the tunnel costs in speed. To verify the client itself you need a torrent-specific IP check, which works by having your client download a tracker file that reports the address it connected from.
No, and any tool that implies otherwise is selling something. Your screen size, graphics hardware, fonts and browser version stay readable whatever you do, and together they can identify a browser with no address at all. A VPN changes where you appear to connect from. It does not change what your browser is.
The leak checks run entirely in your browser against this site alone. Your address is never written to a log or a database here, and there are no ads or third-party trackers on this page. The speed test necessarily talks to Cloudflare's nearest server, since measuring a connection needs a server near you; it is configured not to submit your results to their statistics.
Speed figures cover the route between you and this one server. Speed is measured by Cloudflare's open-source engine, the same one behind speed.cloudflare.com, against whichever of their servers is nearest you — which is why these figures line up with other speed tests. Those requests reach Cloudflare; results are not submitted to their aggregated statistics. Differences under about fifteen per cent are the line moving rather than the VPN. Latency is measured to the nearest edge of this site's network, and upload is timed end to end, which reads slightly conservative rather than inflated. Numbers still move with the moment, so a difference under about ten per cent is noise rather than a finding, and a dedicated speed test with servers next to your VPN exit may read higher than this route does.
A VPN cannot hide everything. Your screen size, graphics card and browser version stay readable whatever you do, and together they can identify you with no address at all.