IPv6 leak test

Many VPNs only tunnel IPv4. If your network has IPv6 and the VPN doesn't handle it, your real IPv6 address can leak.

IPv4
IPv6

How to use the ipv6 leak test

  1. Open the page — IPv4 and IPv6 are detected automatically.
  2. If an IPv6 address shows while your VPN only tunnels IPv4, that's a leak.
  3. Disable IPv6 or switch to a VPN that handles it.

Why IPv6 leaks happen

Many VPNs only route IPv4 traffic. If your network also has IPv6 and the VPN doesn't tunnel or block it, websites can reach you over IPv6 and see your real address — completely bypassing the tunnel. A proper VPN either routes IPv6 through the tunnel or disables it while connected.

Code & API examples

Use this from the command line or your code.

IPv6 (curl)
curl -6 https://api6.ipify.org
IPv4 (curl)
curl -4 https://api.ipify.org

See all endpoints at /api/tools/.

Frequently asked questions

When your VPN only routes IPv4 but your connection also has IPv6, sites can still see your real IPv6 address — a leak that bypasses the tunnel entirely.

If your VPN doesn't fully support IPv6, disabling it removes the leak. A better fix is a VPN that tunnels or blocks IPv6 properly.

The test tries to reach a server over IPv6 while your VPN is connected. If your real IPv6 address answers, traffic is escaping the tunnel; if nothing connects or only the exit address shows, you're covered.

Many VPNs were built IPv4-first and silently ignore IPv6. If your ISP hands out IPv6 and the VPN doesn't route it, every IPv6-capable site sees your real address while you assume you're hidden.

Run this test with the VPN off. If it returns an IPv6 address, your network is dual-stack and IPv6 is something your VPN must handle. If it returns nothing, you're IPv4-only and not exposed this way.

Rarely for everyday browsing — sites fall back to IPv4. Some local network features or IPv6-only services can be affected, so the cleaner long-term fix is a VPN that tunnels IPv6 rather than disabling it.

Support may be off by default, your app version may be stale, or the OS is preferring an IPv6 route the VPN didn't capture. Update the app, enable IPv6 in its settings, and reconnect before retesting.

Blocking drops all IPv6 so it can't leak — safe but you lose IPv6. Tunneling carries your IPv6 traffic through the VPN with an exit IPv6 address — you keep IPv6 and stay covered. Either prevents a leak.

Yes, and it's common. The two are routed separately, so your IPv4 can show the exit hole while your real IPv6 leaks straight past it. That's why IPv6 needs its own test.

It can. A device may send DNS over IPv6 to your ISP's resolver even when IPv4 DNS is tunneled, producing a DNS leak driven entirely by IPv6. Test both if you're on a dual-stack network.

No. It checks your live connection for an exposed IPv6 address and reports the result. vpn.golf keeps no logs, so nothing about the test is recorded or linked to you.

Each hole handles IPv6 inside the tunnel rather than ignoring it, so your real IPv6 address never reaches the sites you visit — the same no-leak posture applied to both address families.
Want to hide your IP for real?

vpn.golf is a no-logs WireGuard VPN. Pick a hole, take the shot.

Step up to the tee — free