Research Question: can a single real connection's IPv4 and IPv6 exit addresses disagree on country while agreeing on network operator? Yes — here's an actual instance of it, captured during this session's own testing.
| Test date | August 13, 2026 |
| Environment | Windows 11, single real network connection (hosting/VPN-classified) |
| Tool | NetRiskScan WebRTC Leak Test, which independently measures both HTTP exit addresses per protocol |
The result
| HTTP exit IPv4 | HTTP exit IPv6 | |
|---|---|---|
| Address | 191.222.208.203 | 2403:18c0:1001:5f8:438:1aff:fef9:93ea |
| Reported country | Brazil | Japan |
| ASN / network owner | AS906, DMIT Cloud Services | AS906, DMIT Cloud Services |
| Classification | VPN, Hosting | VPN, Hosting |
Both addresses trace back to the exact same operator — AS906, DMIT Cloud Services — and both are classified as VPN/hosting infrastructure. The country field is where they diverge: Brazil for the IPv4 address, Japan for the IPv6 address, measured within the same page load.
Reading this against NetRiskScan's own documented patterns
Our How to Run an IPv6 Leak Test guide defines exactly this pattern in advance, before this specific result existed: "Location Mismatch — the country differs but the network owner is the same on both. Often a multi-region VPN or CDN routing quirk rather than a genuine leak, since one provider still controls both addresses." This live result matches that description precisely — a single hosting operator evidently serves IPv4 traffic from a Brazil-registered range and IPv6 traffic from a Japan-registered range within the same infrastructure, most likely because the operator's IPv4 and IPv6 address blocks were allocated to, or are routed through, different regional points of presence.
Why this isn't flagged as a privacy leak
A genuine IPv6 leak (see IPv6 Leaks Explained) describes a VPN protecting IPv4 while a device's separate, unprotected native IPv6 address exposes the user's real ISP directly. That's not what happened here: both addresses belong to the same VPN/hosting operator, meaning both are still "inside" the same protected environment — the discrepancy is about which of that operator's regional address blocks answered, not about the tunnel being bypassed.
Limitations
This is one measurement from one session on one provider's infrastructure — it demonstrates that the Location Mismatch pattern is real and does occur, not how common it is across VPN or hosting providers generally. We did not test this repeatedly over time, so we can't say whether this specific connection's IPv6 country is stable or itself variable.
Conclusion
If your own IPv4 and IPv6 results disagree on country but agree on network owner, this case study is a real example of that exact outcome being a routing quirk rather than a leak — though it's still worth running the IPv6 Leak Test yourself to confirm which pattern you're actually looking at, since a genuine leak (different owner, not just different country) looks meaningfully different.