Frequently Asked Questions About IP & Network Detection
Learn the difference between datacenter and residential IPs, risk scoring mechanisms, and DNS/WebRTC leak causes.
💡 Test your connection with our Proxy Anonymity Test to see where your TCP terminates.
💡 Use our Split Tunneling Test to identify routing leaks that might inflate your risk score.
💡 To check for hardware-level canvas, audio, and WebRTC leaks, visit the Browser Fingerprint Test.
⚠ We can only tell you whether your dual-family egresses terminate in different networks; we cannot judge how your proxy software should be configured. Conversely, IPv6 showing as unavailable does not equate to safety; it may simply mean your network lacks IPv6, or that your proxy disabled IPv6 entirely—the latter is often the intended behavior.
k3f9x2ab.leakv4.myipdns.com) for your browser to resolve. This hostname appears only once in history and will never exist in any cache, so your recursive resolution chain must query our authoritative server all the way back to the source; we record who actually made the query, and then return that address to your browser. Consequently, the "DNS Egress" column displays the actual outbound network address of your recursive resolver, not the upstream IP you entered in your system settings: if you set 8.8.8.8, the machine querying us will be a specific outbound node in that cluster, which may well reside in a different country; large public resolvers rely on anycast and clustering, so observing several different egress addresses in a single test is completely normal. The genuine criterion is not whether addresses match, but rather: if this egress falls within your own broadband ISP network while your IP egress terminates on a proxy—that signifies DNS queries failed to follow the tunnel.⚠ This methodology can only observe who queried our own authoritative server; we cannot and do not see any other domains you resolve. There is also a known blind spot: if your proxy also intercepts DNS queries, what we observe is the proxy provider's resolver—confirming no leak to your local ISP, yet your DNS query log remains visible to your proxy provider; that is a separate consideration beyond what this tool detects.
⚠ Honest clarification: we only distinguish between Cone and Symmetric NAT, and do not sub-classify into Full Cone, Restricted Cone, or Port-Restricted Cone. The RFC 3489 four-tier model requires actively controlling combinations of source ports and destination targets across repeated probes, and WebRTC in browsers provides no such low-level control; when web-based tools report one of the four categories, they are usually just relabeling these two outcomes.
⚠ The trade-off is connecting to multiple subdomains upon initial load, which ad blockers or strict privacy extensions occasionally intercept. In such cases, the corresponding indicator shows a gray dot and remains in an unknown state; we will never backfill values from other probes to forge an apparently complete result.