Your IP address and connection check
Find out which IP address websites see and check for leaks through WebRTC, DNS and IPv6.
Checking your connection…
This usually takes a few seconds.
If the app says “Connected” but this page shows no VPN
- The page is open inside an app, not in a browser. On Android, our app’s built-in browser bypasses the VPN, and so does the built-in browser of any app on the “Apps that bypass the VPN” list. Open this page in Chrome or another browser.
- Your browser is on the “Apps that bypass the VPN” list. In the app, open Tunnel and remove the browser from the list in Manual mode.
- Your browser has its own VPN or proxy turned on, such as the VPN built into Opera, Edge Secure Network, iCloud Private Relay in Safari or a proxy extension. Websites then see that service’s address. Turn it off and check again.
- If nothing here applies, press “Copy report” and send the report to support on Telegram at @vanyasupport.
With the VanyaVPN app, websites see our server’s address in the country you choose, not yours. You can start with Vanechka, our trial.
Try VanechkaThis is the address your browser used to reach our check server. Other websites usually see the same address.
WebRTC is what makes calls and video chats work in the browser. To connect people directly, the browser learns its addresses from a STUN server, and any website can read them without asking your permission. If one of them isn’t our server’s address, websites can see it even with the VPN on.
How to fix it
Type about:config in the address bar and accept the warning. Find media.peerconnection.ice.default_address_only and set it to true. If you don’t need calls in the browser, you can turn WebRTC off completely by setting media.peerconnection.enabled to false.
Chrome, Edge and Yandex Browser have no built-in setting for this. Install Google’s WebRTC Network Limiter extension and, in its options, choose the setting that limits WebRTC to your main connection. Opera and Brave on desktop have this setting built in. Look for WebRTC in their privacy and security settings.
In the app, open Tunnel and choose Off. In this mode, all device traffic goes through the VPN.
Browsers on Android usually have no WebRTC setting. In the app, open Tunnel and choose Off. In this mode, all device traffic goes through the VPN.
After making changes, reconnect in the app and press “Check again”. If the leak is still there, contact support on Telegram at @vanyasupport.
Before opening a website, the browser asks a DNS server for the site’s address. If these requests bypass the VPN, your provider can see which sites you visit. With the VPN on, the list usually shows Cloudflare, Google, Quad9 or OpenDNS in the VPN server’s country. That’s normal.
In For Russia mode, requests to Russian services, including Yandex DNS, go directly rather than through the VPN, so in this mode the check may show Yandex as a leak.
How to fix it
Restart your computer if you haven’t done so since installing the app. DNS protection on Windows starts working after a restart.
Find “Use secure DNS” in your browser’s privacy or security settings. If it’s set to Yandex or your provider’s DNS, choose Cloudflare or turn it off.
In Firefox, open Settings → Privacy & Security and find DNS over HTTPS. Choose Cloudflare as the provider or select Off.
To send all DNS requests through the VPN, open Tunnel in the app and choose Off. Then reconnect and press “Check again”.
Many internet providers assign two kinds of addresses, IPv4 and IPv6. Our app works over IPv4 and blocks IPv6 while you’re connected. If a website still sees your IPv6 address, some requests bypass the VPN.
How to fix it
Reconnect in the app and press “Check again”. If your IPv6 address is still visible, contact support on Telegram at @vanyasupport.
We don’t store your check results.
What websites see
Connection
Headers received by our server
Browser and system
Client Hints
What else websites can learn about your browser
Websites can use these traits to recognize your browser without cookies. The values are calculated in your browser and aren’t sent anywhere.
Geolocation
Your browser determines your coordinates from GPS and nearby Wi-Fi networks, so a VPN usually doesn’t change them. A website gets them only if you allow it. This page doesn’t send them anywhere.
What this check shows
When you open a website, it sees the IP address the request came from. From that address, the site can tell your country, city and internet provider. When you’re connected to a VPN, the site sees the VPN server’s address instead of yours.
This page compares your address with the addresses of VanyaVPN servers and shows how you’re connected to the internet. Your browser then checks three channels through which a website can learn your real address or provider despite the VPN. These are WebRTC, DNS and IPv6.
What leaks are and why they matter
WebRTC leak
Browsers use WebRTC for calls. It reveals your device’s addresses to websites so that callers can connect directly. If the browser learns an address outside the VPN, websites see your provider’s address even though the VPN is on.
DNS leak
A DNS server translates a site’s name into its address. Requests that bypass the VPN show your provider which sites you visit and hint to websites which country you’re in.
IPv6 leak
If a VPN carries only IPv4 and the browser opens a site over IPv6, that request goes out directly from your real address. Our app blocks IPv6 while you’re connected.
Why the address here can differ from the one in the app
Some of our servers pick the outgoing address from a pool of several. That’s why websites may see a different address from the one shown in the app.
This is normal, and the address still belongs to our server. If the app is connected but this page shows no VPN, see the list of causes under the result.
How to fix a leak
- In Firefox, open about:config and set
media.peerconnection.ice.default_address_onlytotrue. WebRTC will then use only your main connection. - Chrome and Edge have no built-in WebRTC setting, but Google’s WebRTC Network Limiter extension does the job. For DNS, check the browser’s “Use secure DNS” setting.
- On iPhone, iPad and Mac, open Tunnel in the app and choose Off so that all device traffic goes through the VPN.
- On Windows, restart your computer after installing the app. DNS protection starts working after a restart.
- On Android, make sure your browser isn’t on the “Apps that bypass the VPN” list, and open sites in the browser rather than through a link inside our app.
In For Russia mode, Russian services and Yandex DNS are reached directly, so the DNS check may show Yandex as a leak.
What data the check sends, and where
- Our check server receives your IP address and your browser’s request headers to tell whether you’re connected to VanyaVPN. We don’t store the result.
- The DNS check loads several randomly named bash.ws addresses. The service sees your IP address and the DNS servers that handled the requests, and stores the result on its side, where the page retrieves it.
- The WebRTC check contacts STUN servers run by Cloudflare and Google. They see your IP address.
- The IPv6 check asks api6.ipify.org for your address, or ipv6.icanhazip.com if the first one is unavailable. If neither responds, the page checks the connection with a request to api4.ipify.org. If our server can’t determine your address, the page also asks api4.ipify.org for your IPv4 address, for reference.
- The page gets the HTTP and TLS versions from Cloudflare, which the site runs on. If you opened the page through a site mirror, a similar request to the site’s main address checks whether it opens for you.
- The page doesn’t send your browser fingerprint or coordinates anywhere.
All other data on this page is handled as on the rest of the site, under our personal data processing policy.
Common questions about the check
What does “Your connection is protected” mean?
It means websites see the address of a VanyaVPN server instead of yours, and the WebRTC, DNS and IPv6 checks found no leaks. If a check couldn’t be completed, the cards under the result say so. The check covers only the browser this page is open in, not other apps on your device.
The app says “Connected”, but this page shows no VPN. Why?
The page may be open in our app’s built-in browser on Android, or your browser may be on the “Apps that bypass the VPN” list. Another possible cause is a VPN or proxy built into the browser itself. The full list of causes appears under the result. If none of them fits, contact support on Telegram at @vanyasupport.
Why does the IP address here differ from the one in the app?
Some of our servers have several outgoing addresses, and websites see one of them. That’s normal, and the address still belongs to our server.
What should I do if a leak is found?
Open the card with the leak. It has tips for your browser and operating system. After making changes, reconnect in the app and press “Check again”.
Why does my browser’s time zone differ from the country of my IP address?
A VPN changes your IP address, but not your device’s clock or language. Websites can notice the mismatch, but it doesn’t mean anything is wrong with the VPN.
Are the results stored anywhere?
We don’t store them. Our server receives your IP address and browser headers to answer the request and doesn’t record the result. The DNS check result is kept by bash.ws, the service that runs that check, and the page fetches it from there. Your browser fingerprint and coordinates aren’t sent anywhere.
Can I use this page to check another VPN?
Yes. The page shows your address and provider, and the WebRTC, DNS and IPv6 cards list the addresses and servers the checks found. Leaks are evaluated only when you’re connected to VanyaVPN, and only then does the page show “Your connection is protected”.