Not every VPN handles IPv6 the same way, and the difference between the three common approaches is exactly what determines whether your connection has an IPv6 leak at all.
Design 1: native IPv6 tunneling
The VPN client tunnels both IPv4 and IPv6 traffic consistently — this is the ideal design, providing uniform protection regardless of which protocol a given connection happens to use. If your VPN does this correctly, an IPv6 Leak Test should show consistent, VPN-matching results for both address families.
Design 2: deliberate IPv6 blocking
Rather than tunneling IPv6, the VPN client disables it on your device entirely while connected — a simpler, safer-by-default approach for VPN providers that haven't built full IPv6 tunnel support. This is a legitimate, intentional design, not a bug: with no IPv6 path available, there's nothing to leak through. A leak test should show "No IPv6 Detected" in this case, which is the expected, safe outcome.
Design 3: accidental bypass
The VPN tunnels IPv4 but does neither of the above for IPv6 — leaving a working IPv6 path active and completely unprotected while the client operates under the assumption that IPv4 tunneling was sufficient. This is the actual leak scenario, and the one worth actively checking for.
How to tell which design your VPN uses
The only reliable way is direct testing — run the IPv6 Leak Test with your VPN connected. "No IPv6 Detected" or fully consistent results across both protocols both indicate a safe design; a mismatch where IPv6 shows your real, unprotected identity indicates Design 3.
FAQ
Can I tell which design a VPN uses before subscribing?
Some providers document this explicitly in their feature lists or support documentation; when it's unclear, testing directly after subscribing (many services offer trial periods or refund windows) is the reliable way to confirm.