How to tell your VPN leaks your IP or DNS: a two-minute check
Three kinds of leaks with a VPN on: IP, DNS and WebRTC. How to check each without installing anything, what the results mean, and how to close leaks on phone and computer.
The VPN is on, the icon is lit, and a site still shows your city. That is a leak, and there are three kinds. Checking each takes under a minute and needs no software.
IP leak
The crudest one: traffic goes around the tunnel. Open the "My IP" page with the VPN on. If it shows your ISP and city, the tunnel isn't working even if the app says "connected". Causes: the app connected but routes didn't apply, another VPN took the slot, or the tunnel dropped and the app didn't notice. Reconnect; if it repeats, change the server.
DNS leak
Subtler. Sites open through the VPN, but the phone still asks your ISP's DNS server for site names. The ISP doesn't see contents, but it sees the list of sites you visited. The same "My IP" page has a DNS line: if with the VPN on it shows an ISP in your city rather than a server in the exit country, DNS is leaking. A frequent cause on Android: "Private DNS" enabled in network settings, which bypasses the tunnel. On Windows: a DNS set manually on the network adapter.
WebRTC leak
Browsers only. The technology for in-browser calls can discover your real address around the VPN. It shows up only in the browser and only on sites that deliberately ask. Test it on any WebRTC test page. Closed by an extension that disables WebRTC, or a Firefox setting. In our browser extension the proxy is set at browser level and WebRTC cannot leak through it.
Leak on drop
The tunnel works, then the network vanishes for a second, and while the app reconnects traffic goes direct. Not a permanent leak, but that is exactly the moment your messenger sends a message outside the VPN. The fix is called a kill switch: block the internet until the tunnel is back. Details in the separate article. On Android it is the system toggle "Block connections without VPN" in VPN settings.
How Surok handles it
DNS queries inside the tunnel go to our servers, not the ISP, so there is no DNS leak while the tunnel is up. Local sites go direct, and DNS for them resolves directly too: that is deliberate, otherwise banks and government sites start complaining. If you want nothing at all to bypass the tunnel, the app has a "route everything through VPN" mode.
Checklist
- Open "My IP" without the VPN, note the ISP.
- Turn the VPN on, open again: ISP and city should change to the exit country.
- Check the DNS line: your ISP should not be there.
- Test WebRTC in the browser.
- Turn on the kill switch if you use the VPN for more than "open a site".
If any step fails and changing the server doesn't help, message support with the results: they show immediately where the problem is.
