"Is my VPN actually working?" is really four smaller, checkable questions bundled together. Running through them takes about five minutes and replaces a vague worry with a specific answer.
The checklist
- Public IP. Check your address before connecting, then again after. It should change to the VPN's exit address. Use NetRiskScan's IP Risk Check for this.
- DNS. Run a DNS Leak Test while connected — the resolver handling your queries should be consistent with your VPN's exit, not your ISP's default.
- WebRTC. Run a WebRTC Leak Test — your browser's real-time connection feature shouldn't reveal an address outside what your VPN shows.
- IPv6. Run an IPv6 Leak Test — if your connection has a working IPv6 path, it needs to be protected too, not just your IPv4 traffic.
What "working" actually means
A fully working VPN passes all four checks consistently: exit IP changed, DNS routes through the tunnel, WebRTC doesn't leak a separate address, and IPv6 is either tunneled or cleanly disabled rather than silently bypassing the tunnel. Passing only the first check (a changed public IP) is the most common false sense of security — it's necessary but not sufficient.
What to do if something fails
Each individual leak type has its own common causes and fixes — see the dedicated guides linked above for DNS, WebRTC and IPv6 specifically, since the right fix depends on which check actually failed.
FAQ
How often should I re-run this check?
After any VPN client update, operating system update, or network change — any of these can silently reset settings that were previously configured correctly.