A poorly configured VPN can let your real IP address or DNS requests slip through — what's known as "leaks." These leaks cancel out part of the protection the VPN is supposed to provide.

Types of VPN leaks

1. IP leaks (IPv4 and IPv6)

If your real IP address remains visible despite an active VPN, you have an IP leak. This is the most common issue.

2. DNS leaks

Your DNS requests (translating domain names into IP addresses) may go through your ISP's servers instead of the VPN. Your ISP can then see which sites you visit.

3. WebRTC leaks

Modern browsers use WebRTC for video and voice calls. This technology can reveal your real IP address even with an active VPN.

How to test your VPN

IP leak test

  1. Go to an IP leak test service with your VPN active
  2. Check that the IP shown matches your VPN server's country
  3. Check that your real IP doesn't appear anywhere

DNS leak test

  1. Go to a DNS leak test service
  2. Run the standard test
  3. Check that the DNS servers listed belong to your VPN provider

WebRTC leak test

  1. Install a WebRTC leak prevention extension in your browser
  2. Go to a WebRTC test service
  3. Check that no local IP is exposed

PureVPN: built-in leak protection

PureVPN natively includes:

  • Automatic DNS protection
  • IPv6 blocking (a frequent source of leaks)
  • WebRTC protection via its browser extension
  • Kill Switch that cuts internet access if a leak is detected

Our tests found no significant leaks on PureVPN during our checks.

What to do if you detect a leak

  1. Check that the Kill Switch is enabled
  2. Manually disable IPv6 in Windows/macOS if needed
  3. Install your VPN provider's browser extension
  4. Contact your VPN provider's support team

Conclusion

Regularly testing your VPN is a good basic security practice. It lets you verify that the advertised protection actually matches reality.