Free network diagnostic
WebRTC Leak Test for Your Browser
See the addresses or hostnames your browser exposes while gathering WebRTC connection candidates. Compare the observed route with the proxy or VPN connection you intended to use.
Inspect this browserโs WebRTC candidates
Starting the check contacts Googleโs public STUN server, which sees the connectionโs source address. The tool creates a data channel to gather candidates; it does not request camera or microphone access, send media, or connect to another user.
What this WebRTC test measures
WebRTC uses ICE candidates to describe possible connection paths. This test creates a local peer connection and data channel, then displays the candidates the browser exposes. It uses one public STUN server to help discover the address seen outside your network.
The check ends when gathering completes or after 15 seconds. It does not place a call, connect to another user or test every interface. No camera or microphone permission is requested. Browser policy and permission state can affect which candidates are visible.
Read host, srflx and relay candidates
A host candidate describes a local interface candidate; the browser may expose a hostname ending in .local instead of a numeric address. That hostname is not a public ISP address. A server-reflexive candidate, shown as srflx, is an address observed through STUN.
A relay candidate describes a TURN relay path. This test configures STUN only, so it does not claim to verify a TURN service or a complete media connection. The official Trickle ICE sample provides a separate diagnostic interface when you need to test your own STUN or TURN configuration.
How to investigate an unexpected public address
Record the intended proxy or VPN exit address before running the check. What is my IP shows this browserโs HTTP IPv4 path; compare IPv4 with IPv4 and keep IPv6 observations separate. A public WebRTC address outside the intended route is a reason to examine routing, not proof that an account has been banned.
The IETFโs WebRTC IP handling guidance explains how direct STUN traffic can take a different path from an application proxy when direct access is permitted. Check browser and network policy for your actual configuration. The browser proxy guide explains why a proxy setting does not cover every protocol automatically.
Why an empty result is inconclusive
A browser may restrict address exposure, block WebRTC, or fail to reach STUN. A timeout reports incomplete gathering. STUN errors can also coexist with useful candidates from another path, so this tool preserves both the candidates and warnings.
If no public address appears, the result only describes this attempt. It does not certify DNS routing, other applications, future calls or a hosted AI browser. Run the check inside the browser session you actually use; a test on your laptop cannot establish the route of a remote agent.
Data handling during the check
The check begins only when you press the button. Googleโs STUN service receives the discovery traffic and can observe its source address. Candidate results stay in this pageโs state; the tool has no result-upload or account-storage feature. Avoid sharing screenshots that expose addresses you want to keep private.
If your browser belongs to a managed workplace, coordinate routing changes with its administrator. Disabling WebRTC entirely can affect calling and collaboration apps. Test the affected workflow after a configuration change instead of treating one checkbox as a universal fix.
Method and sources
Documentation reviewed October 11, 2026. The result panel identifies the source and time of each check. A failed or incomplete check is not a clean result.
Frequently asked questions
Continue the diagnosis
Compare the HTTP route with the candidates from this test.
Understand protocol support and application coverage.
Identify the network announcing an observed address.
Inspect the TLS connection observed at our hosting edge.