
The toggle turns green. That is a client state. It is not a measurement of what a website, a STUN server, or a DNS resolver sees. If you care whether the tunnel is doing the job you paid for, you test after connect — IP, DNS, WebRTC, IPv6 — in that order, on the network you are actually using.
This is not the explainer on DNS Leak: Why It Matters and How to Test. That piece is the mechanism. It is not the WebRTC Leak: Can It Expose Your IP with a VPN? deep dive, and it is not the IPv6 Leak: Why It Happens and How to Test physics lesson. Those exist. This is the checklist you run in ten minutes with Klox's own tools: What is my IP, DNS leak test, WebRTC leak test, IPv6 leak test. If you only open one, open What is my IP with the VPN off and on. Then open the other three. Skipping WebRTC because the name sounds like a meeting product is how a script on a page still sees home.
A pass is modest. It means those checks did not show your home address in this browser, on this network, at this moment. It does not prove no-logs. It does not prove the kill switch will fire when Wi-Fi dies. It does not prove every app on the phone. It does not prove tomorrow's hotel portal. People screenshot a green badge and treat it like a character reference. I will not. I also will not tell you a fail on one cafe means the product is fake. It means that cafe, that radio, that browser, that moment. Change one thing. Test again. If you cannot reproduce it, you do not have a leak story. You have a story. Those are different.
Klox apps speak WireGuard, OpenVPN, OpenConnect, and Shadowsocks. Plans include five devices, from $2.83 a month, seven-day money-back. Download if you want the client. Pricing if you want the number. Privacy if you want the policy a leak test will never replace.
A virtual private network wraps traffic. Cloudflare's VPN explainer is enough vocabulary. Then stop reading theory and capture a baseline IP before you connect. Without a before, the after is a vibe. I mean that in the rude way. People screenshot an IP that was always their ISP because they never wrote the before. Do not be those people. Two minutes with the VPN off is the whole scientific method this industry will give you. Use it. Then connect. Then the four tools. Then a note. Then you can argue with evidence instead of with a green toggle.
Related reading: Android Always-On VPN: When to Use It and What is a VPN?. Android VPN setup and iOS VPN setup.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Baseline first, then connect, then measure
Disconnect. Open What is my IP. Write down the address, the ISP name if shown, IPv4 and IPv6 if both appear. That is home. Then connect the VPN. Wait until the client is actually up, not 'connecting.' Then open the same tool again. The address should change. The ISP should look like a VPN exit, not your broadband bill.
If it did not change, stop. You are not testing leaks. You are testing a client that did not take the route. Reconnect. Try OpenVPN if WireGuard is stuck on a captive portal. Try the other way around on a clean network. Then continue.
- 1Download the app from klox.app/download — not a random APK site.
- 2Sign in with the account you paid for.
- 3Press WireGuard. Wait for the connected state.
- 4If it fails, try OpenVPN. Still failing: note the network (hotel, campus, home) before you write support.
First successful connect
| Check | Klox tool | Pass looks like | Still can be wrong |
|---|---|---|---|
| Public IP | /tools/what-is-my-ip | Not the home address you wrote down | Another tab still on Direct; IPv6 you forgot |
| DNS | /tools/dns-leak-test | Resolvers that are not your ISP's | OS 'smart' multi-DNS; split tunnel apps |
| WebRTC | /tools/webrtc-leak-test | No home public IP in ICE candidates | Different browser; extension off in this window |
| IPv6 | /tools/ipv6-leak-test | No home IPv6, or IPv6 absent/blocked | Phone LTE vs Wi-Fi; a second NIC |
A green leak badge is a snapshot. It is not a character reference for the vendor, the OS, or next Tuesday's hotel Wi-Fi.
— KloxVPN operator notes
Cloudflare Learning: What is a VPN?
Write it down like a lab, not like a vibe
Phone notes are enough: time, network (home / cafe / LTE), protocol (WireGuard / OpenVPN), four results. If you cannot reproduce a fail, you cannot file a useful ticket. 'It leaked once' with no baseline is a feeling.
Incognito lies about extensions
Private windows drop many extensions. If you live in a browser with a WebRTC blocker, test that browser too. Then test a clean profile. You want both: what you actually use, and what the engine does naked.
IP: the check people skip because it feels obvious
It is obvious until it is not. Two addresses on a dual-stack host. A browser that prefers IPv6. A page cached from before connect. Run What is my IP twice. Hard refresh. If IPv4 moved and IPv6 did not, you already know your next tool.
Competitor 'what is my IP' widgets exist. Use ours for the checklist so the steps stay in one place. If you use another site, you still need a before and after. A single after with no before is how people celebrate a VPN IP that is actually their ISP because they never looked.
Local addresses are not the fail
192.168.x, 10.x, fc00::/7 — those can show up. The fail is your ISP's public IPv4 or IPv6 sitting next to the VPN IP. Learn the difference before you panic in a comment thread.
Geo labels are sloppy
MaxMind-class databases guess cities. A 'wrong city' on an IP page is not automatically a leak. Compare the address to your baseline, not the city name to your vacation photos.
DNS: queries should not go home
Open DNS leak test while connected. You want resolvers that are not the ones your ISP handed out over DHCP. If you see your ISP's DNS, the tunnel is encrypting some things and still introducing your browsing names to the broadband company. That is the leak the other article explains. Here you only need the action: fail means fix the client or the OS DNS, then retest.
Do not 'help' by setting 1.1.1.1 or 8.8.8.8 on the adapter 'for speed.' That is how you bypass the VPN's DNS on purpose and then blame the VPN.
Windows is extra messy
Smart multi-homed name resolution can spray queries. A good client fights that. If only Windows fails, say so in a ticket. If every OS fails, you have a bigger problem than one checkbox.
DoH in the browser
Browser DNS-over-HTTPS to a third party encrypts the query to that third party. Your ISP may not see the names. The third party still does, and it may see you off-tunnel. For a VPN user who wanted the VPN to own DNS, DoH in the browser is often a second path. Test with it on and off. Know which world you are in.
WebRTC: the browser can still gossip
Connect. Open WebRTC leak test. The page asks the browser for ICE candidates. If your home public IP appears, a site with a script can see it even while the HTTP(S) you think about is going through the tunnel. Disable or restrict WebRTC, or use a browser mode that does not volunteer the address, then test again.
This is browser-shaped. A passing Chrome and a failing Firefox is normal until you fix Firefox. A passing desktop and a failing phone browser is also normal. Test the surface you use for the thing you care about.
Video calls will complain
If you need in-browser meetings, killing WebRTC has a cost. That is a trade. Privacy people pick the cost. People who live in Meet pick the meeting. Do not pretend there is no trade. Retest after you change the setting.
Extensions are not the VPN
A WebRTC blocker extension is a browser patch. The tunnel is an OS-level route (or a per-app VPN). If you uninstall the extension, the leak can return. Know which layer saved you.
IPv6: the quiet second internet
Connect. Open IPv6 leak test. If your home IPv6 is visible, IPv4 through the VPN is not the whole story. Dual-stack networks prefer IPv6 more than people think. A VPN that only grabbed IPv4 left a door.
Fix is a client that tunnels or blocks IPv6, or you disable IPv6 on that interface and accept the breakage. Disabling is a hammer. Prefer a client that handles it. Then retest on Wi-Fi and on LTE. Phones lie when the radio changes.
No IPv6 is a pass, not a personality
If the test shows no IPv6, you may be on IPv4-only, or the VPN blocked it. Either can be fine. The fail is a real home IPv6. Do not fail yourself for a missing protocol.
Second interfaces
Ethernet plus Wi-Fi. VM adapters. USB tethering. IPv6 can leave on the path you forgot. Disconnect the spare NIC if you are doing a serious check. Then live your real life and test that too, because the spare NIC is your real life on Tuesdays.
What a pass does not prove
It does not prove the vendor's privacy page is true. A leak test cannot see a disk in a datacenter. It does not prove malware-free. It does not prove split tunnel is honest — excluded apps will use the physical path by design. It does not prove the kill switch. Drop the VPN on purpose and see whether traffic continues. That is a different test. Android Always-On VPN: When to Use It is a different test again.
It does not prove TLS on websites is correct. RFC 8446 is still the site's job. A VPN is not a certificate for every origin.
It does not prove five devices. Test the ones that matter. The laptop you wrote the blog on is the one that always passes. The tablet that sleeps wrong is the one that leaks. Klox plans include five devices. That is a slot count, not a blessing on device four.
Streaming and 'it loaded Netflix'
A stream playing is not a leak test. It is a CDN test. Do not use a show as a substitute for DNS and WebRTC.
Speed tests
Throughput is not privacy. A fast leak is still a leak. Run speed if you care about speed. Do not skip DNS because the megabits looked pretty.
Competitor badges
Other VPNs host leak widgets too. A pass on a vendor's own page is still a snapshot. I linked a competitor elsewhere in this series with a sponsored rel because they exist. I will not tell you their widget is gospel. Ours is a tool on our site. Use it. Then keep your skepticism.
When to run it again
New OS version. New browser. New cafe. New phone. After you enable split tunnel. After you 'fix' DNS. After a client update. After you switch WireGuard to OpenVPN or back. After you turn on always-on. Not every hour. After the world changed.
Hotel captive portals deserve a special run: connect, authenticate the portal if you must, connect again, then the four tools. Portals lie. So do first handshakes.
Family devices
If a kid's iPad is on the plan, test that iPad. Safari is not Chrome. If you only test your ThinkPad, you tested your ThinkPad.
Work laptop with MDM
Corporate DNS and always-on policies can fight a consumer VPN. A fail here may be policy, not a broken Klox client. Know who owns the device before you file a rage ticket.
The ten-minute script I actually want you to use
1. Note network and protocol. 2. VPN off, What is my IP, write both families. 3. Connect. Wait. 4. What is my IP again. 5. DNS leak test. 6. WebRTC leak test in the browser you use. 7. IPv6 leak test. 8. If any fail, change one thing, retest that thing. 9. Optional: drop VPN and see whether traffic continues (kill switch). 10. Save the note.
If you skip 2, I do not believe 4. If you skip 6 because 'I do not use video,' remember that a tracker script does not need your permission to ask ICE.
One change at a time
Do not toggle WebRTC, IPv6, and split tunnel in the same minute. You will not know which lever worked. This is not exciting. It is how you stop superstition.
Then go live your life
A checklist is for after connect and after changes. It is not a new personality. If you retest every site load, you are coping. Fix the fail or accept the trade. Then close the tools tab.
Split tunnel, kill switch, and protocol switches
Split tunnel means some apps skip the tunnel. Their IP, DNS, and WebRTC can show home on purpose. If you leak-test in a browser that is excluded, you will 'fail' a VPN that is doing what you asked. Include the browser, or accept that the test is for the included path only.
Kill switch is the opposite mood: when the tunnel dies, traffic should die. A leak test while connected does not prove that. Disconnect or kill the client and see whether What is my IP returns to home while you still expected a block. If traffic continues, you learned something the four-tool pass never said.
WireGuard is the weekday default for a reason. OpenVPN still wins on some portals and some networks that hate UDP. After you switch protocols, run the four tools again. A pass on one protocol is not a pass on the other. Five-device households will have one person on each without telling you.
Per-app VPN on phones
If only some apps are in the VPN, Safari can pass and a game can leak. Test the browser you care about and, if you can, a second app that fetches an IP. Phone OS settings matter more than a desktop checkbox. Android Always-On VPN: When to Use It changes the story again: the OS may block off-tunnel, which is not the same as a WebRTC pass.
Extensions versus system VPN
A browser extension VPN is not this checklist. This article assumes an app that takes the system route. If you only installed an extension, you will pass on that browser and fail in everything else. Download the real client if you wanted the real client.
Captive portals and 'connected but no internet'
You cannot leak-test if you cannot load the tools. Authenticate the portal, then connect, then test. If the client cannot complete a handshake, you do not have a leak. You have a connect problem. OpenVPN on TCP is the usual next try. Then the tools.
How to read mixed results without superstition
IP pass, DNS fail: names still go to the ISP. Fix DNS. Do not celebrate the IP. IP pass, WebRTC fail: the browser gossiped. Fix the browser. DNS pass, IPv6 fail: you have a second internet. Fix IPv6. All fail: you might not be in the tunnel. Go back to baseline.
All pass except on LTE: cellular IPv6 or a carrier setting. Test both radios. All pass at home, fail at the office: corporate DNS or a proxy. That may be unsolvable on a locked PC. Say so. Do not burn a support ticket that cannot change MDM.
False fails
VPN IP geolocated to a city you dislike. A local IP in the WebRTC list. A DNS resolver you do not recognize that still is not your ISP. Compare to baseline. If it is not home, it may be the exit. Ask before you tweet 'leak.'
False passes
You tested Chrome with an extension and then used Edge for banking. You tested IPv4-only Wi-Fi and then moved to a dual-stack cafe. You tested with split tunnel off and then turned it on. The badge was true for the lab. The lab was not your afternoon.
What to send in a ticket
OS, app version, protocol, network type, baseline IP (you can mask the last octet if you are shy), after IP, DNS result, WebRTC result, IPv6 result, one change you already tried. That is a ticket. 'It leaks' is a mood.
Using the Klox tools pages without treating them as magic
The tools live under /tools. They are browsers talking to the internet. They are not inside the Klox app. If a corporate proxy intercepts HTTPS, the tool can lie. If you are on IPv6-only, What is my IP may show a different family than you expected. Read the result, then compare to baseline. If the page fails to load, you learned the tunnel or the network cannot reach the tool. That is data. It is not a pass.
DNS leak test is for names. WebRTC leak test is for ICE. IPv6 leak test is for the other stack. Do not run one and declare the VPN 'safe.' I linked all four in the table because people skip the ones with scary names. WebRTC is the one they skip. It is also the one a tracker script likes.
Five devices, four tools, one lazy laptop
Klox plans include five devices. If you only test the machine you work on, you have one known-good. Test a phone on LTE. Test a tablet on the house Wi-Fi. You will find the weird one. That is the point of a household SKU. From $2.83 a month does not mean you only paid for the laptop's badge.
After you download
Install from download. Connect. Wait. Then this checklist. Do not leak-test the website in a browser while the app is still connecting. Race conditions make excellent superstition. The seven-day money-back window is a refund policy, not a leak SLA. If a test fails, you still have time to decide. Use the time to change one setting and retest, not to write a novel in a review.
What 'the VPN is working' should mean in your notes
Connected. IP changed. DNS not ISP. WebRTC not home public. IPv6 not home. Optional: kill switch holds. That sentence is enough. If you cannot write it, you are not done. If you can write it for this cafe and not for the next, you are done for this cafe. Repeat when the world changes. That is the whole method. It is not a personality. It is ten minutes.
Privacy policy still sits beside the tools
A pass does not mean we 'proved' privacy. Policies are about records. Tools are about addresses this page could see. Keep the distinction when you argue on a forum. People who mash them will call every vendor a liar or a saint on the same screenshot.
Key Takeaways
After you connect, measure. IP, DNS, WebRTC, IPv6, on the network you are standing on, in the browser you actually use. Klox's tools are built for that loop. A pass is a snapshot. Treat it like a snapshot.
Do not confuse a green badge with a no-logs audit, a kill switch, or a promise about device four in a five-device household. Do not skip the baseline. Do not set 'helpful' DNS that bypasses the tunnel and then write a review. Do not test only Chrome and then live in Safari. Do not test only Wi-Fi and then travel on LTE. The checklist is short because the excuses are long. Run it when the world changes. Then close the tab.
If you want the client that speaks WireGuard, OpenVPN, OpenConnect, and Shadowsocks, download it. If you want the price, it starts from $2.83 a month with a seven-day money-back window. If a test fails, fix the layer that failed — client, OS, browser — and run that test again. Then stop treating the internet like it signed an affidavit. Save the note with the time and the network. Next time the world changes, you will not be guessing whether last month's pass still counts. It does not. Snapshots expire when the radio changes, when the browser updates, when you flip split tunnel. That is not cynicism. That is how networks work. Ten minutes after connect is cheaper than a week of forum superstition. If you skipped a tool because you were late for a meeting, you did not fail as a person. You just do not get to claim a pass you did not measure. Finish the four when you sit down. Then you can mean it.
Related Resources
Connect, then check what the internet sees
KloxVPN apps include WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, from $2.83 a month, seven-day money-back. Download the client, connect, then run the leak tools on this site.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.