Request public IP
Returns the address already visible to BrowserCheck's Cloudflare request. The browser does not call a third-party IP geolocation API.
Network address comparison
This browser leak test compares two observations: the public IP address seen by BrowserCheck's web request and a server-reflexive address that WebRTC may obtain through STUN. A different address can reveal an unexpected network path, such as traffic that is not using the same VPN route.
A matching pair is narrower evidence. It means this WebRTC check did not expose a different public address in the current session; it does not prove that DNS, every IPv6 path, other applications or all WebRTC behavior is leak-free.
The request address comes from this site. The WebRTC address uses a STUN request and may be unavailable or privacy-masked.
Copied and printed output omits IP addresses, the full User Agent, exact versions, fingerprint hashes, and precise location.
Returns the address already visible to BrowserCheck's Cloudflare request. The browser does not call a third-party IP geolocation API.
Creates a data-only peer connection and asks a STUN service for an ICE candidate. No camera or microphone permission is requested.
Labels exact text equality as a match and different comparable addresses as a mismatch. Missing values stay unavailable.
Investigate VPN split tunneling, browser-specific proxy settings, IPv4/IPv6 routing and WebRTC handling. The result identifies a difference, not its cause.
No second public address was observed through this flow. This is not a universal no-leak certificate.
The browser may hide candidates, the STUN request may fail, WebRTC may be unsupported or network policy may block it. The result remains untested.
No. It creates a data channel only and does not request camera or microphone permission.
Many browsers use mDNS hostnames to avoid exposing a private LAN address directly. That is expected protective behavior, not a public-IP result.
No. It covers only this web request and this STUN-derived WebRTC address. DNS, IPv6, split tunneling and other applications need separate verification.
Inspect fingerprint surfaces and privacy signals separately, or verify the browser version before checking vendor settings.