Most home and mobile networks today run IPv4 and IPv6 side by side. If your VPN only tunnels one of them, the other can carry your real identity in plain sight — and because IPv4 usually looks fine on its own, this kind of leak is easy to miss entirely.

Why dual-stack changes the picture

"Dual-stack" means your connection has a working address on both protocols at once, not one or the other. Historically, VPN software was built almost entirely around IPv4 — tunneling IPv4 traffic, replacing your IPv4 DNS settings, and stopping there. IPv6 support came later, and not every client added it fully. The result is a specific, common failure mode: your device still has a live, publicly routable IPv6 address, and nothing is stopping traffic from using it directly instead of the VPN.

What "leak" means here specifically

An IPv6 leak isn't about IPv6 being unsafe by nature — it's about inconsistency. If a VPN tunnels IPv4 completely and either also tunnels IPv6 or disables it outright, there's no leak either way: one consistent, protected path. The leak happens in the middle state — IPv4 protected, IPv6 quietly untouched — because some apps, sites and background services will use whichever address family responds, and an unprotected IPv6 address answers directly from your real network.

What it exposes

Anything reachable over IPv6 sees your real public address, your real ISP, and your real approximate location — the exact information a VPN's IPv4 tunnel was supposed to hide. Because your IPv4 traffic still looks perfectly protected, there's no obvious symptom; you have to check both address families directly to notice anything's wrong.

How to check your own connection

The only way to know is to measure your IPv4 and IPv6 identities independently and compare them — not just look at "my IP address," which only shows whichever protocol your browser happened to prefer for that one request. NetRiskScan's IPv6 Leak Test forces separate IPv4-only and IPv6-only requests and compares the country, network owner and privacy classification of each. See How to Run an IPv6 Leak Test for the full walkthrough.

FAQ

If my VPN shows "No IPv6 Detected," do I have a problem?

No — that's a safe, intended outcome for VPNs that handle this by disabling IPv6 on the client rather than tunneling it. With no IPv6 path at all, there's nothing for a leak to travel through.

Does this affect mobile connections too?

Yes, and mobile carriers are often more likely to assign a working IPv6 address by default than home ISPs are, which can make this specific leak more common on cellular data than on a typical home Wi-Fi connection.

Is turning off IPv6 entirely a good fix?

It's a reasonable stopgap if your VPN doesn't support IPv6 properly, but it's a workaround, not a long-term solution — check whether your VPN client has a native "protect IPv6" or "block IPv6" setting first, since that keeps IPv6 available for anything else that might need it.