A regular IP check shows you one address — whichever protocol your browser happened to use for that request. Catching an IPv6 leak requires forcing both protocols to answer independently and comparing them side by side.

Why a normal IP check misses this

When both IPv4 and IPv6 are available, your browser picks one automatically for a given request, usually preferring IPv6 when it's present. A single "what's my IP" lookup only ever shows you that one choice — so it's entirely possible to see a clean, VPN-protected IPv4 address on one check and never realize an unprotected IPv6 address was reachable the whole time.

Step by step

  1. Connect your VPN.
  2. Force an IPv4-only request. This means hitting an endpoint that only resolves over IPv4, so there's no ambiguity about which protocol answered.
  3. Force an IPv6-only request, separately. Same idea, pinned to IPv6 only.
  4. Compare the two results — country, network owner (ASN), and privacy classification (VPN/proxy/hosting vs. residential/mobile) for each.
  5. Repeat with the VPN off to confirm your baseline and that the test itself is behaving correctly.

NetRiskScan's IPv6 Leak Test automates exactly this: it runs both pinned requests and looks up full IP intelligence on each result.

Reading the four outcomes

  • No IPv6 Detected — no IPv6 endpoint responded. Neutral: either your network doesn't support IPv6, or your VPN disables it. Either way there's no unprotected path.
  • IPv6 Only — no IPv4 endpoint responded on your connection. Informational, not itself a leak indicator.
  • Consistent — both protocols point to the same country and/or network owner. Your VPN is handling both address families the same way.
  • Suspected Leak — your IPv4 identity looks protected (VPN/proxy/hosting) while your IPv6 identity looks like a direct residential or mobile connection in a different location. This is the pattern that matters.
  • Location Mismatch — the country differs but the network owner is the same on both. Often a multi-region VPN or CDN routing quirk rather than a genuine leak, since one provider still controls both addresses.

Fixing a confirmed leak

Look for an IPv6 protection or "disable IPv6" setting in your VPN client first — many now include one specifically because this pattern is common. If your client doesn't support IPv6 at all, disabling IPv6 at the operating-system network adapter level closes the same gap, at the cost of losing IPv6 connectivity generally.

FAQ

Is a "Location Mismatch" as serious as a "Suspected Leak"?

No — it's flagged separately because the same organization controlling both addresses is a much weaker signal of a real problem. It's still worth a second look, but it's common with large multi-region providers and not automatically a privacy failure.

Should I test on Wi-Fi and mobile data separately?

Yes. IPv6 availability and your VPN's behavior can both differ meaningfully between a home router and a mobile carrier connection.