MyIPScan

Provider-neutral self-test pilot

AdGuard VPN Leak Test

AdGuard VPN is the provider on this list where a reading showing your own address can be exactly right. It documents two modes: general, where every domain except the exclusions is tunnelled, and selective, where only the domains on the list are. If this site is not on that list in selective mode, the checks below will report your ordinary connection and nothing is broken. Its protocol is its own, built over TLS with HTTP/2 as transport.

Read methodology

Live test

Run the test on AdGuard VPN now

Before reading anything else on AdGuard VPN, check which mode you are in: in selective mode only listed domains are tunnelled, so a familiar address here may be the setting working.

Open the full VPN Leak Test

Current-session checks

What this AdGuard VPN self-test checks

Run the checks before and after connecting, and note the mode and the exclusion list alongside them. On AdGuard VPN those two settings decide what the result can possibly show.

Before you read the result

What AdGuard VPN documents about these signals

The points below come from AdGuard's own knowledge base on VPN modes and exclusions and from its description of the AdGuard VPN protocol.

Selective mode can make a familiar address correct

AdGuard documents two modes with separate lists. In general mode the tunnel covers everything except the domains you exclude. In selective mode only the domains on the list are routed through the VPN. Run this check in selective mode without adding this site, and the reading describes your ordinary connection because that is what the setting asked for.

Exclusions are written per domain

Because the lists are keyed on domains rather than on applications, two tabs open at the same time can be on different sides of the tunnel. That is worth knowing before a result is read as a leak: the answer may be one line in a list you set months ago and have not looked at since.

A protocol built to resemble HTTPS

AdGuard describes its own protocol as using TLS encryption with HTTP/2 as transport, working with data streams rather than individual packets and opening a separate tunnel per connection. The design goal it states is being hard to distinguish from ordinary HTTPS traffic while staying fast. Nothing about that changes which address a website sees.

IPv6 is a switch with its own exclusions

The knowledge base describes enabling IPv6 so that you have an IPv6 address while traffic goes through the VPN, and a separate section listing IPv6 ranges for which tunnelling is disabled. So on AdGuard VPN the IPv6 line depends on two settings, not one, and an empty line is not by itself evidence of anything.

The resolver is a setting you chose

AdGuard lets you select which DNS server is used while connected and recommends its own. Whatever you picked is what the DNS line above will name. Reading that line as a verdict on the provider therefore skips a step, because the value was configured rather than discovered.

Between the readings

Record a kill-switch drop on AdGuard VPN

Reading an AdGuard VPN session once tells you where you stood at that moment. It says nothing about the seconds after the tunnel goes and before it returns, which is where an exposure would fall if there was one.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on AdGuard VPN

  1. Open the app and note whether you are in general or selective mode.
  2. Read the exclusion list for that mode and check whether this site appears on it.
  3. Take a reading before connecting, connect, then repeat it in the same browser.
  4. Interpret any difference against the mode first, because the mode decides what should change.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

AdGuard VPN leak test FAQ

Why does this page show my ordinary address while AdGuard VPN is on?

In selective mode only the domains on the exclusion list are routed through the VPN. If this site is not on that list, your ordinary connection is what the check will see and the setting is doing its job.

What is the difference between general and selective mode?

AdGuard documents general mode as tunnelling every domain except the ones you exclude, and selective mode as tunnelling only the domains you list. Each mode keeps its own separate list.

Does AdGuard VPN handle IPv6?

Its knowledge base describes an IPv6 setting that gives you an IPv6 address over the VPN, plus a list of IPv6 ranges excluded from tunnelling. Both settings affect what the IPv6 line can show.

What protocol does it use?

AdGuard describes a protocol of its own built on TLS with HTTP/2 as transport, opening a tunnel per connection and working with streams rather than packets, with the stated aim of resembling ordinary HTTPS.

Which DNS server answers while I am connected?

The one selected in the app's settings, which AdGuard suggests should be its own resolver. The DNS line above reports which resolver replied for this browser, not which one you intended.

Can this page see my exclusion list?

No. Nothing in a web page can read the configuration of an application on your device. The list has to be checked in the app, and this reading only makes sense once you have.