VPNRank.io

Is My VPN Working?

Your VPN is working if websites see the VPN server's IP address, not your home connection's, and WebRTC exposes no other public address. This free test checks both in under a minute, adds a timezone check that flags fingerprinting risk, and returns one verdict: WORKING, LEAKING or NOT CONNECTED. It does not test DNS leaks.Updated · free, no account

Check 1 of 3 — Your public IP & location

Check 2 of 3 — WebRTC quick check

Waiting for check 1 — answer the location question above to start.

Check 3 of 3 — Timezone consistency

Compares your device timezone with your IP's timezone once the checks above finish.

What Does a VPN Test Check? The 5 Checks, and the 3 This Page Runs

A VPN test checks that your traffic really leaves through the VPN server. A complete one covers five things: the IP address and location websites see belong to the VPN server; WebRTC exposes no other public address; your device timezone doesn't contradict the server's location; DNS lookups go to the VPN's resolvers, not your ISP's; and the kill switch blocks traffic when the tunnel drops. The test above runs the first three in under a minute. The last two are not run here: vpnrank.io has no DNS leak test, and the kill switch has its own tool. Speed is a separate question, answered by our benchmark.

The five checks in a full VPN test, which ones this page runs, how to do the other two yourself, and what a pass does not prove
CheckWhat it catchesRun on this page?What a pass doesn't prove
1. IP and locationA tunnel that never formed, or split tunneling that routes your browser outside the VPNYes, automatic: we look up the IP and location websites see, and you confirm whether that's really where you areThat other apps on the device use the tunnel; split tunneling works per app
2. WebRTCYour browser handing out a public address other than the one websites seeYes, automatic: a STUN request from your browser, up to 5 secondsThat other browsers on the same device are protected; test each one
3. TimezoneA device clock that contradicts the IP's location, a signal fingerprinting scripts useYes, automatic; advisory only, it never changes the verdictAnything about leaks; it's a consistency check
4. DNS leakSite lookups going to your internet provider's resolver instead of the VPN'sNo — vpnrank.io does not run a DNS leak test.Do it yourself: with the VPN on, run a DNS leak test (Surfshark publishes a free one): the servers listed should belong to your VPN provider or the DNS service it says it uses, not your ISPThat every app uses the same resolver
5. Kill switchTraffic leaving with your real IP when the VPN dropsNot on this page — it has its own tool.Do it yourself: open our kill switch test with the VPN on, press Start, then disconnect the VPN: it re-checks your IP every 2 seconds for up to 3 minutesThat it fires in every situation, such as waking from sleep or switching networks

The first check is the fatal one. If websites can see your real IP address, nothing else the VPN does matters — encryption of a tunnel your traffic isn't using protects nobody. That's why the checker above starts there, and why our What Is My IP tool is the single most useful bookmark for any VPN user. Checks two and four are sneakier: your main connection is masked, but a side channel — the browser's WebRTC stack, or the operating system's DNS resolver — quietly reports back to your real network. A DNS leak matters because the resolver that answers your lookups sees which sites you use (RFC 9076). IPv6 is the other side door: if your VPN neither carries IPv6 nor blocks it, the IP in check 1 may be an IPv6 address from your own ISP, so look at whose address it is. When this test passes, finish with the DNS check and the kill switch test.

VPN Status Check: What "Connected" Tells You, and What It Doesn't

A VPN can look perfectly healthy — app open, button green, "Connected" in the menu bar — while protecting nothing. The status only tells you the software thinks a tunnel exists; it says nothing about what your traffic is actually doing. Here is where each system shows VPN status:

Where Windows, macOS, iPhone, Android and VPN apps show whether a VPN is connected
DeviceWhere to see VPN status
Windows 11Settings > Network & internet > VPN shows “Connected” under the connection's name; a blue shield appears on the taskbar when you're connected to a recognized VPN
macOSSystem Settings > Menu Bar > VPN adds a VPN status menu that connects, disconnects and can show how long you've been connected
iPhoneA VPN icon in the status bar, which Apple describes as “iPhone is connected to a network using VPN”
AndroidSettings > Network & internet > VPN shows “VPN on” while you're connected (menu names vary by manufacturer)
Your VPN appIts own Connected / Disconnected label, plus any split-tunneling list that decides which apps skip the VPN

Every one of these confirms that a tunnel is up on that device. None of them shows what websites see, whether WebRTC or DNS leak around the tunnel, or whether split tunneling has left your browser outside it. That is the gap an outside check fills: the test above looks at your connection the way a website does, which is why it can say NOT CONNECTED while your app says Connected.

How to Read Your Verdict

The verdict comes from two things: your answer to check 1 and the WebRTC result. The timezone check adds an advisory note but never changes the verdict, and a browser with no WebRTC at all counts as a pass, since it can't leak that way. Here is exactly what each verdict means and what to do next:

VerdictWhat it meansWhat to do
WORKINGYou said the location shown isn't where you are, and WebRTC revealed no other public addressNothing — optionally fix a timezone mismatch if you care about fingerprinting
LEAKINGThe main tunnel works, but WebRTC exposed a different public IP — very likely your real oneEnable WebRTC protection in your VPN's browser extension, or disable WebRTC; re-test
NOT CONNECTEDYou confirmed the detected location is really yours — the VPN isn't masking anythingReconnect, disable split tunneling for your browser, and run the check again

One honest caveat: no browser-based test can prove a VPN is perfect. We can see what your browser exposes to websites — which is what matters most — but we can't see inside your operating system's routing table or watch what happens when your Wi-Fi blips at 2 a.m. A WORKING verdict means you pass the checks any website could run against you right now. For the full picture of how a VPN behaves under stress, that's what our lab methodology is for, and our step-by-step guide to testing your VPN walks through every manual check in depth.

What Each of the Three Checks Actually Tests

Check 1: IP and location — why we ask you

The first check fetches the public IP address your connection presents to every website, plus the city and country it geolocates to. Then it asks you a question no algorithm can answer: is that where you really are? Geolocation databases are accurate at country level but fuzzy at city level, and we have no way of knowing your true location — nor should we. You do, instantly. If the page says Amsterdam and you're on a sofa in Manchester, your VPN is masking you; if it names your actual city, it isn't. This human-in-the-loop step is more reliable than any datacenter-name heuristic, because some VPN exits deliberately use residential-looking addresses. To dig into any specific address — yours or a server's — use the IP address lookup.

Check 2: the WebRTC quick check

WebRTC is the browser technology behind in-page video calls. To connect two peers directly, it asks a STUN server "what address do I appear from?" — and historically, browsers would hand the answer, including your real IP, to any webpage that asked, even with a VPN connected. RFC 8828 names the VPN case directly: with a split-tunnel VPN, WebRTC can discover both the VPN's public address and the ISP address the VPN runs over. Our check runs the same request a malicious page would: it asks Google's public STUN server (stun.l.google.com) for your browser's WebRTC candidate addresses, waits up to 5 seconds, and compares any public ones against the IP from check 1. Private, link-local and carrier-grade NAT ranges (RFC 1918, RFC 6598) and anonymized .local mDNS names are ignored, because they identify nobody; a public address that matches check 1 is no leak either. Modern browsers use those mDNS names for local addresses, so most people pass — but a VPN misconfiguration can still expose the real address. If this check fails, the full WebRTC leak test shows every candidate address and the exact fix for your browser, and our WebRTC leak glossary entry explains the mechanism in depth.

Check 3: timezone consistency

Any website can read your device's timezone with a single line of JavaScript — Intl.DateTimeFormat().resolvedOptions().timeZone returns an IANA name such as Europe/Rome, with no permission prompt and no warning. Check 3 reads it and compares it with the timezone of the place your IP geolocates to. If your IP says New York but your device says Europe/Rome, a site fingerprinting its visitors knows something doesn't add up. This won't unmask your identity by itself, and it never changes your verdict — but it's exactly the kind of signal streaming platforms and payment processors use to flag VPN users. If passing as local matters for what you do, set your device timezone to match your VPN server's region before you browse.

The Kill Switch: Protection for the Moment Your VPN Fails

Everything this page tests is a snapshot: your VPN's state right now. But VPN connections drop — when your laptop wakes from sleep, when you switch from Wi-Fi to mobile data, when a server restarts. In that gap, your operating system helpfully falls back to the regular connection, and every open app continues talking with your real IP. You usually notice nothing.

A kill switch closes that gap: it blocks all internet traffic the instant the tunnel dies, so nothing escapes unprotected while the VPN reconnects. It's the difference between a VPN that works when conditions are perfect and one that protects you when they aren't. Every provider we recommend ships one, but defaults vary — some enable it out of the box, others hide it behind a settings toggle. Turn it on, then verify it actually fires with our step-by-step VPN kill switch test. A kill switch you've never tested is a hypothesis, not a safety net.

If you leave this page with one habit, make it this: treat "VPN on" as a claim to verify, not a fact. The full routine is IP, WebRTC, timezone, DNS and kill switch. This page automates the IP, WebRTC and timezone checks; the DNS check and the kill switch test are the two extra steps in the five-check table near the top of this page.

What to Do If Your VPN Failed the Check

Work through these in order — most failures resolve at step one or two:

  1. Reconnect properly. Fully disconnect in the VPN app, wait five seconds, reconnect to a different server, then run this check again. Transient drops and half-dead connections cause most NOT CONNECTED verdicts.
  2. Check split tunneling. If your VPN has a split tunneling or "bypass" list, make sure your browser isn't on it — a browser routed outside the tunnel shows your real IP no matter how healthy the VPN is.
  3. Fix WebRTC. For a LEAKING verdict, install your provider's browser extension (most include WebRTC protection) or disable WebRTC in your browser's settings, then confirm with the full WebRTC leak test.
  4. Enable the kill switch so the next silent drop doesn't expose you for minutes before you notice.
  5. If it keeps failing, change providers. A VPN that repeatedly fails basic exposure checks is not worth troubleshooting forever. In our lab testing, NordVPN, ExpressVPN, and Surfshark passed every leak and kill switch test we threw at them; the complete comparison is in our best VPN rankings. All of our top picks offer 30-day money-back guarantees, so you can run this exact page against a new provider risk-free.

VPN Testing Questions, Answered

Does this VPN test check for DNS leaks?

No. The test runs three checks — IP and location, WebRTC, and timezone — and none of them can see which DNS resolver your device uses. vpnrank.io does not run a DNS leak test. To check DNS yourself, keep the VPN connected and run a DNS leak test (Surfshark publishes a free one): the servers it lists should belong to your VPN provider or the DNS service it says it uses, not your internet provider.

Does this test measure my VPN's speed?

No. It checks what your connection exposes, not how fast it is. For speed, our Q3 2026 benchmark (25 August 2026) is the reference: on a 1 Gbps fiber line the 8 VPNs we benchmark delivered 415–478 Mbps (42–48% of the line), and on 200–300 Mbps home lines with a nearby server the providers we measured kept 80–93%. The VPN speed test results list every provider and location.

How often should I check that my VPN is working?

Run a check whenever the stakes change: after installing or updating the VPN app, after changing any setting, when joining an untrusted network like hotel or airport Wi-Fi, and before doing anything you specifically need the VPN for. Connections that worked yesterday can fail today — an app update can reset your split tunneling rules, and a new browser version can change WebRTC behavior.

Can a VPN say "Connected" and still not protect me?

Yes — that's the whole reason this tool exists. The app status reflects the tunnel's handshake, not your traffic's actual path. Split tunneling exclusions, IPv6 traffic escaping an IPv4-only tunnel, WebRTC side channels, and DNS requests routed outside the VPN can all leak while the app shows a reassuring green checkmark. Trust external checks, not the app.

Why does the tool ask me if the location is real instead of deciding itself?

Because you are the only reliable source for that fact. Software can guess from network names — a datacenter ISP suggests a VPN, a consumer ISP suggests a home connection — but the guess fails on residential-style VPN exits and corporate networks. You know in half a second whether "Frankfurt, Germany" is where you're sitting. Asking beats guessing.

The verdict says WORKING but a streaming site still blocks me. Why?

Masking your IP and defeating a streaming platform's VPN detection are different problems. Platforms maintain blocklists of known VPN server addresses, so a perfectly working VPN can still be recognized and blocked. Switching to a different server from the same provider usually helps, and fixing a timezone mismatch (check 3) removes one more detection signal.

Is a timezone mismatch actually a problem?

It depends on your goal. For basic privacy — hiding your browsing from your ISP or a public Wi-Fi operator — it's irrelevant. For appearing local to a website, it's a real tell: your IP claims one country while your device clock says another. Fingerprinting scripts combine dozens of such signals. If it matters, align your device timezone with the VPN server's and re-run the check.

Do I need to test on every device separately?

Yes. A VPN's state is per device — and sometimes per app. Your laptop can be fully tunneled while your phone sits exposed on the same Wi-Fi, and a browser with a VPN extension protects only that browser, not the rest of the system. Open this page on each device you rely on. If you run the VPN on your router instead, one test from any device behind it covers everything on that network.

Does this page send my data anywhere or store my results?

We store nothing, and two outside services are involved. The IP check calls our own endpoint (which sees what every website you visit sees anyway), then your browser asks ipwho.is, a free IP lookup service, for the location and network details of that address. The WebRTC check runs inside your browser against Google's public STUN server, and the timezone comparison happens locally. We don't keep your answers, your addresses, or your verdict.

Sources

Standards and vendor documentation behind the facts on this page, re-read on 7 October 2026.

Failed the Check? Your VPN Failed You

Our rankings weigh leak protection — IP, WebRTC, DNS and the kill switch — as part of how we test every VPN we list. See the VPNs we rank and stop guessing.

See Our Top-Rated VPNs

8 VPNs benchmarked on real hardware — see how we test.