MyIPScan

Provider-neutral self-test pilot

Astrill Leak Test

Astrill splits protection along an axis most providers do not. App Guard on Windows blocks only the applications you list from reaching the internet if the VPN drops, while everything else keeps working, and Astrill says it runs even when the desktop application is not open and enables itself at system startup. Site Filter decides which sites enter the tunnel at all, defaulting to tunnelling everything. Whether your browser was on either list decides what this page can show.

Read methodology

Live test

Run the test on Astrill now

On Astrill the question behind a surprising reading is usually membership: whether this browser is in the App Guard list and whether Site Filter was tunnelling all sites.

Open the full VPN Leak Test

Current-session checks

What this Astrill self-test checks

Take a reading before and after connecting, then check the two lists. On Astrill the lists decide the result more often than the tunnel does.

Before you read the result

What Astrill documents about these signals

The points below come from Astrill's own feature pages for App Guard and the kill switch, Site Filter, and its StealthVPN protocol.

App Guard covers a list, not the machine

Astrill describes App Guard as an enhanced Windows feature that blocks only specific applications from reaching the internet if the VPN disconnects, while everything else carries on. It adds that App Guard works even when the desktop application is not running and enables itself automatically at system startup. Whether this browser is on that list changes what a dropped connection would have done.

The kill switch has two levels

Astrill documents its kill switch as operating at both system and application level, and says it can be configured to disable the entire internet connection when the VPN connection is disrupted. Those are different outcomes for the same event, so an unexpected address is worth reading against which level was configured rather than against the provider.

Site Filter decides what enters the tunnel

Site Filter is documented as a StealthVPN feature that lets you choose which sites go through the VPN, and Astrill states it is set to tunnel all sites by default. If it was changed, a site outside the selection will be reached over your ordinary connection, and a check run on that site will report exactly that.

StealthVPN changes appearance, not exposure

Astrill describes StealthVPN as a protocol of its own that adds obfuscation so traffic is not identifiable by automated firewall systems, using RSA-2048 certificates for authentication and AES-256 for encryption. Obfuscation is about how the traffic looks in transit. It does not alter which address a website ends up seeing.

Where a browser check sits in that arrangement

Because Astrill's controls are drawn around applications and sites, a single reading answers a narrow question: what this browser exposed for this request. It cannot enumerate which applications App Guard is covering, and it cannot see the Site Filter selection, so both need reading in the app.

Between the readings

Record a kill-switch drop on Astrill

Astrill documents App Guard and its kill switch as two different features, and its own FAQ says so in as many words. A recorded drop shows which of them was covering this browser, and whether there was an interval when neither was.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Astrill

  1. Check whether this browser appears in the App Guard list before you begin.
  2. Confirm Site Filter is still set to tunnel all sites, or note what it was changed to.
  3. Take a reading, connect with Astrill, then repeat the reading in the same browser.
  4. Read any difference against the two lists first, since they decide what the tunnel covered.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Astrill leak test FAQ

What does App Guard actually protect?

Astrill describes it as blocking only the applications you select from reaching the internet if the VPN disconnects, while other applications continue working. It also says it runs when the desktop app is closed.

Is App Guard the same as the kill switch?

No. Astrill documents a kill switch that works at system and application level and can disable the whole internet connection, and App Guard as the narrower Windows feature limited to a chosen list of applications.

Could Site Filter explain an unexpected address?

It could. Site Filter chooses which sites go through the VPN and is documented as tunnelling all sites by default. A site left outside the selection is reached over your ordinary connection.

Does StealthVPN change what a leak test can see?

Not directly. Astrill presents StealthVPN as obfuscation that makes traffic hard for firewall systems to identify. Which address a website observes is decided by routing, not by how the packets look.

Can this page tell me which applications are protected?

No. A page in the browser cannot read the configuration of a desktop application. The App Guard list has to be opened in Astrill itself before a reading here can be interpreted.

Why did the fingerprint values not move?

Screen metrics, fonts and language are reported by the browser rather than by the network, so a tunnel does not change them. That is expected here and is not a sign that anything failed.