WebRTC leak test
Which addresses can a web page get through WebRTC, and are they on the same network as your proxied exit?
Why WebRTC can leak your IP
WebRTC is the browser API behind video calls and peer-to-peer transfers. To set up a connection the browser gathers ICE candidates: addresses of local interfaces (host), the public address a STUN server sees (srflx), and possibly relay addresses. Page JavaScript can read them.
If your VPN or proxy only carries the browser's HTTP traffic, STUN requests may take another route, so the page sees an address that differs from your HTTP exit, possibly your real ISP's.
How n0.wiki judges it
The question is not whether the addresses match, but whether they point at the same network identity:
- Same prefix is normal. IPv6 is compared at /64 (temporary addresses make one machine's addresses differ routinely), IPv4 at /24.
- Network identity is compared across address families. The most common real leak: the VPN only takes over IPv4 and native IPv6 escapes through WebRTC, while the user believes the VPN covers everything.
- When your exit is anonymized, exposing any address from a different ASN is a leak. Whether it is residential only changes wording and confidence; it is downgraded to a plain mismatch only when the candidate is shown to be infrastructure (multi-hop VPN and the like).
- Not observed is not safe. With no candidates gathered the result is "no observation", not "no leak".
- If every candidate is relayed through TURN or local addresses are hidden by mDNS (
*.local), no extra address is exposed.
The WebRTC test describes your device setup, not a property of the IP, so it is not part of the IP purity score.
How to prevent WebRTC leaks
- Use a VPN that captures all traffic (system-wide or TUN mode) and make sure it handles IPv6; if it doesn't, disable IPv6 on the device.
- Firefox: set
media.peerconnection.enabledtofalseinabout:config(this disables web calls). - Chrome / Edge: use an extension that limits WebRTC network interfaces to proxied connections.
- Then run the test again.
Privacy
The test contacts Google's and Cloudflare's public STUN servers to obtain public candidates. The candidates are sent to our server, judged with local databases only, not forwarded to third-party intelligence sources, and not stored. See about & privacy.