MyIPScan

Provider-neutral self-test pilot

AirVPN Leak Test

AirVPN is unusual in where it puts the resolver. Its published specifications give the VPN DNS addresses as 10.4.0.1 and fde6:7a:7d20:4::1, the same addresses as the tunnel gateway, and say every server runs a resolver that works down from the root servers rather than forwarding queries on. Network Lock, its leak protection, is described as strict firewall rules that hold even if the client stops running. What follows is a reading of this browser, not an assessment of AirVPN.

Read methodology

Live test

Run the test on AirVPN now

On AirVPN the resolver line is the one to read first: while connected it should be the tunnel gateway rather than a public service or your own network.

Open the full VPN Leak Test

Current-session checks

What this AirVPN self-test checks

Take one reading before connecting and one after. The pair that matters on AirVPN is the resolver and the exit address, because the specifications tie them to the same machine.

Before you read the result

What AirVPN documents about these signals

The points below are drawn from AirVPN's published technical specifications and from the Network Lock documentation for its Eddie client.

The resolver address is the tunnel gateway

AirVPN publishes its VPN DNS addresses as 10.4.0.1 and fde6:7a:7d20:4::1, the same addresses as the gateway, so while you are connected the resolver in use is the exit server itself. A DNS reading that names a public service or your own network is therefore saying something quite specific: that query left by a path the tunnel did not set.

Every server resolves from the root down

The specifications say each VPN server runs its own DNS server which finds out about root servers, top level domains and authoritative name servers directly, rather than passing queries to somebody else. The same daemon is documented as answering on port 53, on 443 for DNS over HTTPS and on 853 for DNS over TLS. This page can report which resolver replied, never how it resolved.

Network Lock is firewall rules, not a switch

AirVPN describes Network Lock as based on strict firewall rules, with the stated purpose of preventing leaks under any circumstance including an unexpected disconnection, and notes that protection persists even if the Eddie client stops working. An unexpected address in the result therefore points at a rule that was never installed more often than at a race during a drop.

Both address families are carried

The published specifications say servers support IPv4 and IPv6 tunnels and are reachable over both on their entry addresses. An IPv6 address here is not automatically wrong, then. The useful question is whether it belongs to the same network as the IPv4 exit or to the connection sitting underneath it.

Filtering is an account setting

AirVPN states that its resolvers are neutral and never inject or alter requests, while allowing an account or a single device to opt in to lists and custom answers. If a name fails to resolve while you are connected, that configuration is worth opening before the browser is. Nothing in this browser can read your account settings.

Between the readings

Record a kill-switch drop on AirVPN

AirVPN describes Network Lock as firewall rules strict enough to hold even if the Eddie client stops running. A recorded disconnect is how you see whether they held on your machine, and for how long they did not.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on AirVPN

  1. Write down the resolver, the IPv4 address and any IPv6 address on your ordinary connection.
  2. Turn Network Lock on first, then connect to an AirVPN server.
  3. Repeat the checks in the same browser, same profile, same extensions.
  4. Look for the resolver moving to the tunnel gateway rather than staying with a public service.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

AirVPN leak test FAQ

Which DNS server does AirVPN use while I am connected?

AirVPN publishes the VPN DNS addresses as 10.4.0.1 and fde6:7a:7d20:4::1, which are also the gateway addresses. Each server is documented as running its own resolver rather than forwarding queries elsewhere.

Does AirVPN carry IPv6?

The published specifications say servers support both IPv4 and IPv6 tunnels and are reachable over both. An IPv6 address in a reading here can be the tunnel working rather than a fault.

What exactly is Network Lock?

AirVPN describes it as strict firewall rules that stop IPv4 and IPv6 traffic whenever the system is not connected to one of its servers, and says the rules keep working even if the Eddie client stops.

Can AirVPN resolvers block a domain?

AirVPN says its DNS never injects or alters requests, but an account or a single device can opt in to lists and custom answers. That choice lives in your account, which a page in the browser cannot see.

Why might the resolver still look like my own network's?

A resolver can be pinned in the operating system, in the router, or by a browser secure DNS setting. This check reports which resolver answered; it cannot report why that one was picked.

Does a clean reading mean the whole device is covered?

No. What you see describes one browser in one session. Other applications, a second profile and any additional network adapter all sit outside what a page can observe.