
Your laptop can have two public addresses at once. One is IPv4, the old number everyone still screenshots. The other is IPv6, a longer number a lot of home ISPs now hand out for free. A VPN that only wraps the v4 path leaves the v6 path sitting on the physical NIC. A website that speaks v6 can see the home address. That surprise is the leak. It is also the misunderstanding. People see a v6 on a test page and declare WireGuard dead. The v4 HTTPS they just loaded may still be leaving through the tunnel.
This is not the IPv6 Leak: Why It Happens and How to Test how-to. That piece is why it happens as a procedure, how to test, how to clamp. I will point at it. I will not paste adapter checkboxes. This is not the Leak Test After You Connect a VPN either. That one is IP, DNS, WebRTC, IPv6 as a ritual. This is the English: two families, one laptop, why tunnels miss v6, what a block is versus a route, why home ISPs are louder than a cafe that only has v4.
A VPN is a tunnel for a path you configured. Wikipedia's VPN page will not disable a stack. RFC 8446 is TLS 1.3 on ordinary HTTPS. TLS did not retire IPv6. IPv6 did not retire TLS. They sit next to each other and confuse people who wanted one green toggle to mean one address forever.
Klox consumer is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. The features page lists IPv6 leak protection, next to all DNS through the VPN tunnel and WebRTC leak blocking. That sentence is a block (or equivalent client behavior), not a dual-stack product I am going to invent. I will not draw a map of v6 exits. I will not invent a city count. Test after you care. Then stop treating the other family as a broken handshake.
I have a bias. Prefer a client that blocks leaked v6 over a story about 'we support IPv6 everywhere' that we did not ship as a consumer SKU. Read the table. Then go to the test post if you need clicks.
Related reading: Dualpi2: Not a VPN Setting and Eexit: Not a Mitigation Toggle. Eextend: Not a Mitigation Toggle and Einit: Not a Mitigation Toggle. What is a VPN? and Download KloxVPN.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Two addresses, one laptop
IPv4 ran out of comfortable numbers. IPv6 is the other family: huge space, different notation, often a global address on the same Wi-Fi NIC that already has a 192.168 and a public v4 via NAT. Dual-stack means the OS can use both. Happy Eyeballs, in the browser, may try v6 first when a site has both. You did not toggle a hobby. The stack did.
A consumer VPN commonly adds a virtual adapter and a default route for v4. Packets to 0.0.0.0/0 go into WireGuard or OpenVPN and come out somewhere else. If the client never installed a matching policy for ::/0, v6 still follows the old default: out the physical NIC, home prefix, ISP. Two paths. One toggle. The screenshot of 'connected' was about the path the client actually built.
Wikipedia's IPv6 page is the protocol. You do not need the header diagram. You need to know a site can ask for AAAA, get a v6, and talk to your home prefix while your v4 web IP is a VPN egress. That stitch is the privacy hit. The padlock on the page is still real. RFC 8446 still encrypted the body. The body arrived from a home address the VPN did not move.
Farms will call this a massive failure and then sell a ranked list. Fine as marketing. As physics, it is an OS with two defaults and a tunnel that only claimed one of them. Klox's listed feature is leak protection. I will cite it. I will not pretend we shipped a dual-stack city product in this article so a competitor's IPv6-everywhere page looks copied.
- 1Skim the seating / order diagram.
- 2Do the numbered steps once on your real network.
- 3Use the FAQ if a sentence was too long.
- 4Follow one related article — not ten tabs.
How to read this page
| Path | What it is | What a site can see while VPN is up | Honest remainder |
|---|---|---|---|
| IPv4 through the tunnel | Ordinary web for most screenshots | VPN egress v4 | This is what 'connected' usually means |
| IPv6 ignored by the client | OS still has a global v6 on the NIC | Home v6, often your ISP prefix | The leak this article is about |
| IPv6 blocked by leak protection | v6 fails or never leaves; traffic falls back to tunneled v4 | No home v6, or no v6 at all | Klox lists this. Still test in the other post |
| IPv6 routed through a VPN | A real v6 path inside the tunnel | A VPN v6, if the operator has one | Not a consumer product I will invent here |
| DNS through the tunnel | Names, including AAAA lookups | VPN resolver sees names | Different job. See the DNS article |
| WebRTC ICE | Browser candidates, can include a global v6 | Home v6 as a candidate even if HTTPS is tunneled | Sibling leak. Different post |
The laptop can have two public addresses. A v4-only tunnel only moved one of them.
— KloxVPN consumer notes
Cloudflare Learning: What is a VPN?
You did not have to opt in
If the ISP delegated a prefix, the OS accepted it. Dual-stack is default on a lot of home routers now. 'I never turned on IPv6' is not a measurement. The NIC list is.
AAAA is not a VPN setting
A site with an AAAA record can be reached on v6. The browser may prefer it. That preference is not a Klox city. It is DNS plus Happy Eyeballs. The DNS hop is a different article.
What a leak looks like
The useful picture is a split. VPN off: write down the v4 and the v6 a test page shows, if any. VPN on: v4 should be a VPN egress. If v6 is still the same home number, that family walked around the tunnel. If v6 vanishes, the client likely blocked it. If v6 becomes a different number that is not yours, that would be a routed v6. I am not claiming Klox ships that as a consumer map. Do not screenshot a farm page and call the new number a city we listed.
What it does not look like: a red banner in the OS. A toast that says leak. The green toggle going yellow. Leaks are quiet. The site that wanted a v6 just got one. Ad networks that speak v6 just got a stable-ish prefix that can last longer than a CGNAT v4. That stability is why people who hide an IP should care. A home v6 prefix can be a better tracking handle than a v4 that changes at the router.
What it also does not look like: WireGuard failing to handshake. Handshake failure is no route, a portal, a rude AP. You would notice mail not loading. A v6 leak can sit next to a perfectly fast v4 YouTube tab. That is why the test article exists as a separate ritual. This English is so you know what the ritual is for.
ipleak.net and similar pages will print both families. Follow those as tools if you want. I linked IVPN's leak note as a competitor specimen of how another operator writes the same physics. Their product is not ours. The physics is shared. Do not paste their dual-stack claims onto Klox. Read our features list. Then measure.
Same v6 on and off is the tell
If the number did not move when Connect went green, that path did not enter the tunnel. If you never took an off baseline, you are guessing which number is home.
No v6 at all can be a win
Many leak-protected clients make v6 disappear for the session. Sites fall back to v4 through the tunnel. Boring. Correct. Do not file a ticket that IPv6 stopped working unless you needed it for a reason you can name.
Why tunnels miss v6
History, not a conspiracy. Most consumer VPN code grew up in a v4 world. The virtual adapter got a v4. The routing table got 0.0.0.0/0. Kill switches, leak tests, and support macros were written around that. IPv6 on the NIC was 'someone else's problem' until ISPs started handing it out without asking.
Adding a real v6 path through the tunnel is not a checkbox. The operator needs v6 on the exit, addressing, firewalling, and a story when a user in a v4-only cafe suddenly has no v6 (they never did). Blocking is cheaper and honest: while connected, do not let global v6 leave the physical NIC. Traffic that wanted v6 fails or retries on v4 inside the tunnel. You keep one public address: the VPN v4.
Some networks are v6-mostly or v6-only with translation. Those are getting less rare on mobile. A client that only blocks, on a network that has no working v4, can strand you. That is a real edge. It is also not a reason for me to invent a dual-stack Klox SKU in a blog post. If you are on a v6-only carrier and the app cannot get a route, that is a support fact. Try OpenVPN. Try another network. Seven days on first purchase if the product cannot live on the network you actually have.
Do not confuse 'the protocol supports IPv6' with 'this app routed yours.' WireGuard as a protocol can carry v6. OpenVPN can too. The packaged client still has to install the policy. Features-page leak protection is that policy as we document it for consumers: protection, not a pin map.
A protocol is not a routing table
WireGuard can encapsulate v6. Your laptop still needs a route and an exit that answers. Missing either looks like a leak or like no v6. Those are different tickets.
Support macros that only ask for IPv4
If a ticket only includes a v4 screenshot, we have not seen the leak. Send both families, on and off. The test article says how. This paragraph is why we ask.
Block vs route
Block: while the VPN is up, global v6 is not allowed out the physical NIC. The OS may still show a v6 on the interface. Outbound is what mattered. Sites that only exist on v6 will fail until they fail over, or they will fail period. Most of the web still has v4. You notice this when you were using a v6-only lab, not when you were reading mail.
Route: v6 goes into the tunnel and comes out a VPN v6. The site sees a VPN address in that family too. That is the prettier sentence. It requires the operator to run v6 on exits you actually land on. I will not invent that inventory. I will not count cities. If a competitor's page says they are dual-stack in every location, that is their claim. Ours, on the features page, is IPv6 leak protection. Protection language is how you talk about a block (or a block-like fail-closed) without pretending we shipped a second internet.
Automatic on all servers, in the same features cluster, means you should not have to pick a special node to get the leak row. It does not mean every server has a v6 address I can publish. Geography is not the mechanism. The client is.
White-label IPv6 toggle copy is a different article. That one is strings a brand prints next to a switch. You are a consumer. You get whatever the Klox client does, not a branded toggle essay. Do not file a ticket asking for the white-label wording. Do not ask me for a custom DNS picker while you are here. We are not selling you one in this post.
Kill switch is fail-closed for the tunnel you built. If the tunnel is v4-only and v6 is not blocked, fail-closed on v4 can still leave v6 alive. That is the nasty version of the leak: you thought nothing leaves, and the other family left. Leak protection exists so that story is less true. Still test. Features are not a substitute for a measurement.
Block is a product sentence we can stand on
Hide the home v6. Fall back to tunneled v4. That matches 'leak protection.' Route-everywhere is a bigger sentence. I will not write the bigger sentence without the bigger product.
A toggle in another brand's app is not ours
If a farm screenshot shows Enable IPv6, that is their client. Klox documents leak protection. I will not invent an On Demand row or a dual-stack switch to match the screenshot.
ISP v6 at home
Home is where this leak actually lives for most people. Fiber and cable ISPs have been handing out prefixes for years. The router advertises it. The laptop configures a global address. You never opened a setting named IPv6. Then you connected a VPN that only moved v4. The test page prints the prefix next to a VPN v4. You think the app lied. The app told the truth about the path it built.
Privacy angle: a home v6 prefix can be long-lived. Tracking that prefix across sites is easier than tracking a CGNAT v4 that twenty neighbors share. If you paid for a VPN to stop the site seeing home, a leaked v6 undoes that for any host that prefers v6. TLS still hid the password. The address still pointed at your ISP allocation.
Practical angle: disable v6 on the OS as a blunt hammer if you like pain. It will break things you will not remember. Prefer a client that blocks for the session. Re-enable nothing. When you disconnect, the home prefix comes back because it was always the ISP's. That is correct.
Five devices means five NICs with five moods. A Windows laptop with v6 and a phone on a carrier that also has v6 are two tests. Fixing the laptop does not fix the phone. The seat count is not an IPv6 setting. It is why you test the surface you actually use for the thing you care about.
DNS through the tunnel still matters at home. AAAA queries should not go to the ISP resolver while you are connected. That is the What DNS Does on a VPN (Plain English) hop. A leaked v6 data path plus leaked DNS is two gifts. Do not stack browser DoH as a hobby on top of that until the tunnel DNS default makes sense.
The prefix is the tracking handle
You may get a new interface ID. The prefix can still say 'this ISP customer.' If hiding home was the point, the prefix on a test page is the failure, even if the last bits rotated.
Do not disable v6 forever as a personality
Session block while connected is the product I want. Permanent off on the OS is how you break a printer, a lab, or a carrier in two years. Say which you meant.
Cafe that only has v4
Plenty of shop and hotel APs are v4-only. No prefix, no global v6, nothing to leak. You can still have a leak later at home and think the cafe 'proved' the VPN. Tests are per network. A clean cafe test is not a clean home test. The after-connect ritual exists because people test once on airplane Wi-Fi and then trust a fiber line they never measured.
Cafe still has the splash-page fight. That is the habit article. IPv6 does not change the garden. If the AP has no v6, leak protection has nothing to block. You still want the tunnel for the v4 hop before mail and banks. Do not skip Connect because a v6 test would have been empty anyway.
Some cafes give you v6. Then the same home-prefix story applies, except the prefix belongs to the shop's upstream, not your house. Still a leak relative to 'the site should see a VPN.' Still not proof WireGuard died. Still a reason to want the block.
Smart Connect, if the row exists, is untrusted Wi-Fi. It does not know about address families. It knows about SSIDs. After you are up, leak protection is the family policy. Do not mash them. Do not invent an On Demand toggle that fires on v6. We did not document that.
If the cafe is rude to UDP, OpenVPN. That is a handshake issue. Switching protocols will not cure a v6 leak by magic, and it will not cause one by magic either. Protocol picker is for 'will not connect.' Family policy is for 'connected and still showing home v6.' Look at your own test page.
Empty v6 on cafe Wi-Fi is not a certificate of health
It may mean the AP has no v6. Test at home, on cellular, on the office LAN. One network is one data point.
Portal first, then measure
Do not leak-test in the splash garden. Finish the page, connect, then open a test. The cafe habit piece is the sequence. This piece is what v6 means after you have a route.
How this differs from WebRTC
WebRTC is a browser call stack. STUN and ICE gather candidates, including a global v6 on the NIC, and a page script can read them. That can print a home v6 even when ordinary HTTPS v6 was blocked, or even when you had no v6 HTTPS at all. Different API. Different leak. The WebRTC and a VPN, in Plain English post is that story. Do not merge the tickets.
Ordinary IPv6 leak: the OS routed a web or app packet out the physical NIC because the VPN never claimed ::/0 and never blocked it. WebRTC leak: JavaScript asked ICE, ICE asked the NIC, the NIC answered. You can fix one and still have the other. You can have both on the same tab. Farms collapse them into 'IP leak' and then sell an extension. Keep the nouns.
Klox lists both: IPv6 leak protection and WebRTC leak blocking, plus DNS through the tunnel. Three jobs. Three tests if you are being thorough. The after-connect checklist is the order. This article is only the OS-family job in English.
A STUN candidate that shows a v6 is not proof the kernel routed YouTube on v6. A YouTube host that shows home v6 is not proof ICE ran. Measure the thing you meant. Send both screenshots if you write in. We will send you two URLs if you send one red farm graphic with no labels.
Cookies on klox.app live at /cookie. They are not an IPv6 setting. A tracker that got your v6 plus a logged-in cookie at some other site is a stitch. The tunnel was supposed to stop the address half of that stitch for ordinary traffic. ICE is the volunteer half. Different desks.
Kernel path versus browser volunteer
If icanhazip-style HTTPS on v6 shows home, that is this article's leak. If only the ICE list shows it, that is WebRTC. If both show it, you have two chores.
DNS is a third chore
Names can leak to the ISP while both families look clean on a web IP test. Do not stop at one widget. The DNS post is the hop. The checklist is the ritual.
When to read the test article
Read it when you want clicks: connect, open a v6 test, compare to baseline, clamp or confirm the client, retest. Browserleaks, ipleak, our own tool if you use it: procedure lives in IPv6 Leak: Why It Happens and How to Test. I am not cloning the checkboxes so this URL can rank for the same query.
Read this English when you want to know why the procedure has a v6 row at all. Dual-stack. Missed family. Block versus route. Home versus cafe. WebRTC as a sibling. Then stop. You do not need a city. You do not need a custom DNS picker. You do not need an On Demand fairy tale.
If HTTPS v4 already shows home, fix the tunnel first. Do not start in IPv6 settings. The checklist order exists because people reverse it. They disable v6, still leak v4, and call the product haunted.
Seven days if the client cannot protect the family on the network you actually have, and this is a first purchase. A test page on a third-party site is not, by itself, a billing defect. If both families show home on ordinary HTTPS, that is a connect defect. Measure before you ask for the window.
Download the apps on /download. Features on /features. Yearly from $2.83 a month. Five seats. WireGuard first, OpenVPN when the AP is rude. Then take the measurement on the laptop you will actually use, not on a VM you will never bank from.
This URL is not the how-to
If you came for Windows adapter steps, you want the other IPv6 post. If you came for white-label toggle strings, you want that copy article. If you came for English, you are done after the FAQs.
Test the device you care about
Passing desktop and failing phone is normal. Five seats, five stacks. The how-to is per OS. This English is shared.
Key Takeaways
IPv6 leak, in English, is a laptop with two public addresses and a tunnel that only moved one of them. Dual-stack is common at home. Cafes are often v4-only, which is why a single cafe test lies. Block is the honest consumer sentence: hide the home v6, fall back to tunneled v4. Route-everywhere is a bigger product. I will not invent dual-stack Klox exits or a city count to make the bigger sentence true.
WebRTC can volunteer a v6 through ICE even when the kernel path is clean. DNS is a third hop. Features lists IPv6 leak protection next to those two. Test in the IPv6 Leak: Why It Happens and How to Test post. This post was the English.
Klox consumer remains WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. If you want the client, download it. If you want the list, see features. Then measure both families. Do not treat a green toggle as a v6 policy you never checked.
Related Resources
Install the client, then look at both families
KloxVPN lists IPv6 leak protection next to DNS through the tunnel and WebRTC leak blocking. WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, seven-day money-back. Download the app. Test on the network you actually use.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.