vpnleakIP Leak, DNS Leak & Browser Fingerprint Test
One scan for browser fingerprints, traffic paths, network environment, public IP and DNS resolvers.
Detecting…WebRTC public IP countries: Starts together with the main scan.; DNS resolver IP countries: Starts together with the main scan.
Understand your network environment
Switch between browser signals, current IP information and DNS resolver details.
What gets scanned
Eighteen local and network signals, weighted to a 0–100 risk score.
- System timezoneWeight 13Local signalChecks the OS timezone against restricted-region zones, including mainland China, Russia and Iran.
- Chinese browser / WebViewWeight 12User agent and UA-CH brands matched against WeChat, QQ, Quark, UC, Baidu and other Chinese browsers or in-app WebViews.
- Browser languageWeight 10Checks navigator.languages for restricted-region primary languages such as Simplified Chinese, Russian and Persian.
- Chinese STUN reachabilityWeight 7OnlineCompares Chinese STUN servers with Google STUN to find UDP routing or split-tunnel patterns.
- Timezone consistencyWeight 6Cross-checks the Intl timezone with the native Date timezone name to detect an inconsistent override.
- Firewall connectivityWeight 6OnlineCompares Google and YouTube reachability with Baidu; only the combined mainland pattern counts.
- Chinese vendor fontsWeight 5Canvas probing for fonts shipped by Chinese vendors or software — MiSans, HarmonyOS Sans, OPPO Sans, WPS Founder faces. Any hit is a strong tell.
- Exit IP locationWeight 5OnlineLoad-balances ipwho.is, country.is and Cloudflare trace for the exit country and public IP.
- Installed Chinese fontsWeight 4Canvas width-probing for Simplified / Traditional Chinese fonts such as Microsoft YaHei and PingFang SC.
- Chinese-brand deviceWeight 3UA-CH device model (navigator.userAgentData) and UA matched against HarmonyOS, Huawei, Xiaomi, OPPO, vivo and other Chinese brands.
- Chinese GPUWeight 3Reads the WebGL renderer for Moore Threads, Zhaoxin, Jingjia Micro, Loongson and other Chinese GPU vendors.
- Chinese speech voicesWeight 2Checks for installed Simplified-Chinese system voices; globally bundled macOS voices are suppressed.
- Exit location providerWeight 2OnlineShows the load-balanced provider, exit country and Cloudflare colo when returned.
- IP country / timezone matchWeight 5OnlineUses the load-balanced location result; compares an IP timezone directly or falls back to the IANA country-timezone table.
- Emoji rendering styleWeight 2OS vendor guessed from the user agent; a weak, loosely correlated signal.
- Intl localeWeight 1The locale your browser resolves for date and number formatting.
- WebRTC public IPWeight 5OnlineReads a public STUN address and compares it with the HTTP exit IP.
- Regional transit patternWeight 9Combines restricted-region local signals with an unrestricted network exit.
Current public IP
Exit address, network attribution, approximate location and explainable risk signals observed by this server.
—Starts together with the main scan.This is an estimate derived from proxy and hosting signals using transparent local rules, not a universal credit score.
WebRTC exit IP check
Collects ICE candidates exposed by the browser and compares public WebRTC addresses with the HTTP exit IP.
Each service is tested independently so you can see which route exposes a public WebRTC address.
A public IP returned by a STUN service is compared with the HTTP exit IP. A mismatch can indicate that WebRTC bypassed a proxy or VPN.
DNS resolver check
Shows the recursive DNS servers that resolved the 50 IPv4/IPv6 test hostnames, including their approximate location and network.
DNS servers found: 0
Starts together with the main scan.
How the check works
An IP leak exposes a public address outside the VPN or proxy route you expect. A DNS leak sends lookups to an unexpected resolver, while a WebRTC leak exposes a different public address through ICE or STUN. A country mismatch can also come from encrypted or cross-region DNS, so it is a warning rather than proof of a leak.
The scan compares your HTTP exit IP, WebRTC candidates, observed DNS resolvers, timezone and browser/network signals. The combined consistency score is grouped as Low 0–30, Medium 31–60 or High 61–100; it is an explainable diagnostic estimate, not proof that a VPN is present or absent.
Also available over curl
Prefer the terminal? Hit the endpoint below — it estimates your risk from your IP geo + request headers, and replies in the language of your Accept-Language header.
$ curl https://ip.maizimi.com/api/check$ curl -H "Accept-Language: zh" https://ip.maizimi.com/api/check$ curl https://ip.maizimi.com/api/check?format=jsonFAQ
What is an IP leak?
An IP leak happens when a website can see a public address outside the VPN or proxy route you intended to use. Compare the HTTP exit IP with WebRTC results and with the address shown when the VPN is disconnected.
What is a DNS leak?
A DNS leak means domain lookups reach a resolver outside the network path you expected, often an ISP resolver instead of the VPN resolver. Cross-region or encrypted DNS can also create a country mismatch without exposing your real IP.
What is a WebRTC leak?
WebRTC can use ICE and STUN to discover network addresses. If it returns a public IP different from the HTTP exit IP, real-time traffic may be bypassing the VPN or proxy path. Private or mDNS addresses alone are not proof of a public-IP leak.
Is any data uploaded?
The score and matched-signal list are calculated in your browser. DNS tests temporarily send test IDs and resolver IPs to this site’s backend and expire automatically. IP and network probes may also contact the site backend and public providers.
Privacy
Scoring stays in your browser. The DNS backend temporarily processes test IDs and recursive resolver IPs so it can return results; active tests expire automatically. IP and network probes may contact the site backend and public providers.
Read the full Privacy Policy