All systems operationalโ€ขIP pool status
Coronium Mobile Proxies

Free network diagnostic

WebRTC Leak Test for Your Browser

See the addresses or hostnames your browser exposes while gathering WebRTC connection candidates. Compare the observed route with the proxy or VPN connection you intended to use.

Inspect this browserโ€™s WebRTC candidates

Starting the check contacts Googleโ€™s public STUN server, which sees the connectionโ€™s source address. The tool creates a data channel to gather candidates; it does not request camera or microphone access, send media, or connect to another user.

What this WebRTC test measures

WebRTC uses ICE candidates to describe possible connection paths. This test creates a local peer connection and data channel, then displays the candidates the browser exposes. It uses one public STUN server to help discover the address seen outside your network.

The check ends when gathering completes or after 15 seconds. It does not place a call, connect to another user or test every interface. No camera or microphone permission is requested. Browser policy and permission state can affect which candidates are visible.

Read host, srflx and relay candidates

A host candidate describes a local interface candidate; the browser may expose a hostname ending in .local instead of a numeric address. That hostname is not a public ISP address. A server-reflexive candidate, shown as srflx, is an address observed through STUN.

A relay candidate describes a TURN relay path. This test configures STUN only, so it does not claim to verify a TURN service or a complete media connection. The official Trickle ICE sample provides a separate diagnostic interface when you need to test your own STUN or TURN configuration.

How to investigate an unexpected public address

Record the intended proxy or VPN exit address before running the check. What is my IP shows this browserโ€™s HTTP IPv4 path; compare IPv4 with IPv4 and keep IPv6 observations separate. A public WebRTC address outside the intended route is a reason to examine routing, not proof that an account has been banned.

The IETFโ€™s WebRTC IP handling guidance explains how direct STUN traffic can take a different path from an application proxy when direct access is permitted. Check browser and network policy for your actual configuration. The browser proxy guide explains why a proxy setting does not cover every protocol automatically.

Why an empty result is inconclusive

A browser may restrict address exposure, block WebRTC, or fail to reach STUN. A timeout reports incomplete gathering. STUN errors can also coexist with useful candidates from another path, so this tool preserves both the candidates and warnings.

If no public address appears, the result only describes this attempt. It does not certify DNS routing, other applications, future calls or a hosted AI browser. Run the check inside the browser session you actually use; a test on your laptop cannot establish the route of a remote agent.

Data handling during the check

The check begins only when you press the button. Googleโ€™s STUN service receives the discovery traffic and can observe its source address. Candidate results stay in this pageโ€™s state; the tool has no result-upload or account-storage feature. Avoid sharing screenshots that expose addresses you want to keep private.

If your browser belongs to a managed workplace, coordinate routing changes with its administrator. Disabling WebRTC entirely can affect calling and collaboration apps. Test the affected workflow after a configuration change instead of treating one checkbox as a universal fix.

Method and sources

Documentation reviewed October 11, 2026. The result panel identifies the source and time of each check. A failed or incomplete check is not a clean result.

Frequently asked questions

Continue the diagnosis

Check the browserโ€™s public IPv4

Compare the HTTP route with the candidates from this test.

Browser proxy setup

Understand protocol support and application coverage.

ASN lookup

Identify the network announcing an observed address.

JA4 fingerprint checker

Inspect the TLS connection observed at our hosting edge.