IP Leak, DNS Leak & Browser Fingerprint Test
One scan for browser fingerprints, traffic paths, network environment, public IP and DNS resolvers.
- Local + network scan
- Results never uploaded
Understand your network environment
Switch between browser signals, current IP information and DNS resolver details.
What gets scanned
Eighteen local and network signals, weighted to a 0–100 risk score.
- System timezoneWeight 13Claude SameChecks the OS timezone against restricted-region zones, including mainland China, Russia and Iran.
- Chinese browser / WebViewWeight 12User agent and UA-CH brands matched against WeChat, QQ, Quark, UC, Baidu and other Chinese browsers or in-app WebViews.
- Browser languageWeight 10Checks navigator.languages for restricted-region primary languages such as Simplified Chinese, Russian and Persian.
- Chinese STUN reachabilityWeight 7OnlineCompares Chinese STUN servers with Google STUN to find UDP routing or split-tunnel patterns.
- Timezone consistencyWeight 6Cross-checks the Intl timezone with the native Date timezone name to detect an inconsistent override.
- Firewall connectivityWeight 6OnlineCompares Google and YouTube reachability with Baidu; only the combined mainland pattern counts.
- Chinese vendor fontsWeight 5Canvas probing for fonts shipped by Chinese vendors or software — MiSans, HarmonyOS Sans, OPPO Sans, WPS Founder faces. Any hit is a strong tell.
- Exit IP locationWeight 5OnlineLoad-balances ipwho.is, country.is and Cloudflare trace for the exit country and public IP.
- Installed Chinese fontsWeight 4Canvas width-probing for Simplified / Traditional Chinese fonts such as Microsoft YaHei and PingFang SC.
- Chinese-brand deviceWeight 3UA-CH device model (navigator.userAgentData) and UA matched against HarmonyOS, Huawei, Xiaomi, OPPO, vivo and other Chinese brands.
- Chinese GPUWeight 3Reads the WebGL renderer for Moore Threads, Zhaoxin, Jingjia Micro, Loongson and other Chinese GPU vendors.
- Chinese speech voicesWeight 2Checks for installed Simplified-Chinese system voices; globally bundled macOS voices are suppressed.
- Exit location providerWeight 2OnlineShows the load-balanced provider, exit country and Cloudflare colo when returned.
- IP country / timezone matchWeight 5OnlineUses the load-balanced location result; compares an IP timezone directly or falls back to the IANA country-timezone table.
- Emoji rendering styleWeight 2OS vendor guessed from the user agent; a weak, loosely correlated signal.
- Intl localeWeight 1The locale your browser resolves for date and number formatting.
- WebRTC public IPWeight 5OnlineReads a public STUN address and compares it with the HTTP exit IP.
- Regional transit patternWeight 9Combines restricted-region local signals with an unrestricted network exit.
Current public IP
Exit address, network attribution, approximate location and explainable risk signals observed by this server.
—Starts together with the main scan.This is an estimate derived from proxy and hosting signals using transparent local rules, not a universal credit score.
WebRTC exit IP check
Collects ICE candidates exposed by the browser and compares public WebRTC addresses with the HTTP exit IP.
Each service is tested independently so you can see which route exposes a public WebRTC address.
A public IP returned by a STUN service is compared with the HTTP exit IP. A mismatch can indicate that WebRTC bypassed a proxy or VPN.
DNS resolver check
Shows the recursive DNS servers that resolved the 50 IPv4/IPv6 test hostnames, including their approximate location and network.
DNS servers found: 0
Starts together with the main scan.
How the check works
When Claude Code is pointed at a proxy endpoint via ANTHROPIC_BASE_URL, public reverse-engineering reports found it reads your operating-system timezone and the proxy hostname, then hides the verdict inside the system prompt with Unicode steganography — the date separator and four look-alike apostrophes in the “Today’s date” line encode whether you look like a China user.
The scan combines browser-visible fingerprints — timezone, language, fonts, browser, device, GPU, voices, locale and emoji style — with firewall, STUN, Cloudflare, exit-IP and WebRTC probes. A final transit signal cross-checks the local environment against the network exit. Signals scoring ≥0.25 count as hits; bands are Low 0–30, Medium 31–60, High 61–100.
Also available over curl
Prefer the terminal? Hit the endpoint below — it estimates your risk from your IP geo + request headers, and replies in the language of your Accept-Language header.
$ curl https://ip.maizimi.com/api/check$ curl -H "Accept-Language: zh" https://ip.maizimi.com/api/check$ curl https://ip.maizimi.com/api/check?format=jsonChinese AI models
Chinese models are simply better
FAQ
Does Claude really check my timezone?
According to public reverse-engineering reports, when Claude Code talks to a non-official endpoint it reads the OS timezone and proxy hostname, and steganographically encodes the result into its system prompt. The timezone this page reads via Intl.DateTimeFormat is the very same OS timezone.
Is this score the exact check Claude runs?
No. Only the system timezone maps one-to-one onto Claude’s reported mechanism. The other local and network signals are correlated estimates, not an official verdict.
How do I lower my score?
Switch your OS timezone away from China zones such as Asia/Shanghai, move zh-CN off the top of your browser language list, and avoid routing Claude Code through proxies whose hostnames contain flagged domains or AI-lab keywords.
Is any data uploaded?
The score and detected-signal list are not uploaded. The DNS test backend necessarily observes test IDs and recursive resolver IPs, which expire after the configured retention period. Other network checks contact public providers; the site also loads Google Analytics.
Privacy
Scoring stays in your browser. The DNS test backend observes temporary test IDs and recursive resolver IPs so it can return the result; active tests expire automatically. Other network probes contact public providers, and the site loads Google Analytics.