Astrill splits protection along an axis most providers do not. App Guard on Windows blocks only the applications you list from reaching the internet if the VPN drops, while everything else keeps working, and Astrill says it runs even when the desktop application is not open and enables itself at system startup. Site Filter decides which sites enter the tunnel at all, defaulting to tunnelling everything. Whether your browser was on either list decides what this page can show.
On Astrill the question behind a surprising reading is usually membership: whether this browser is in the App Guard list and whether Site Filter was tunnelling all sites.
The points below come from Astrill's own feature pages for App Guard and the kill switch, Site Filter, and its StealthVPN protocol.
App Guard covers a list, not the machine
Astrill describes App Guard as an enhanced Windows feature that blocks only specific applications from reaching the internet if the VPN disconnects, while everything else carries on. It adds that App Guard works even when the desktop application is not running and enables itself automatically at system startup. Whether this browser is on that list changes what a dropped connection would have done.
The kill switch has two levels
Astrill documents its kill switch as operating at both system and application level, and says it can be configured to disable the entire internet connection when the VPN connection is disrupted. Those are different outcomes for the same event, so an unexpected address is worth reading against which level was configured rather than against the provider.
Site Filter decides what enters the tunnel
Site Filter is documented as a StealthVPN feature that lets you choose which sites go through the VPN, and Astrill states it is set to tunnel all sites by default. If it was changed, a site outside the selection will be reached over your ordinary connection, and a check run on that site will report exactly that.
StealthVPN changes appearance, not exposure
Astrill describes StealthVPN as a protocol of its own that adds obfuscation so traffic is not identifiable by automated firewall systems, using RSA-2048 certificates for authentication and AES-256 for encryption. Obfuscation is about how the traffic looks in transit. It does not alter which address a website ends up seeing.
Where a browser check sits in that arrangement
Because Astrill's controls are drawn around applications and sites, a single reading answers a narrow question: what this browser exposed for this request. It cannot enumerate which applications App Guard is covering, and it cannot see the Site Filter selection, so both need reading in the app.
Between the readings
Record a kill-switch drop on Astrill
Astrill documents App Guard and its kill switch as two different features, and its own FAQ says so in as many words. A recorded drop shows which of them was covering this browser, and whether there was an interval when neither was.
This does not test every server, app, device, or connection.
This does not prove anonymity.
This does not prove every security condition.
A clean result does not prove every leak is absent.
How to compare before and after on Astrill
Check whether this browser appears in the App Guard list before you begin.
Confirm Site Filter is still set to tunnel all sites, or note what it was changed to.
Take a reading, connect with Astrill, then repeat the reading in the same browser.
Read any difference against the two lists first, since they decide what the tunnel covered.
Safe Copy limits
Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.
FAQ
Astrill leak test FAQ
What does App Guard actually protect?
Astrill describes it as blocking only the applications you select from reaching the internet if the VPN disconnects, while other applications continue working. It also says it runs when the desktop app is closed.
Is App Guard the same as the kill switch?
No. Astrill documents a kill switch that works at system and application level and can disable the whole internet connection, and App Guard as the narrower Windows feature limited to a chosen list of applications.
Could Site Filter explain an unexpected address?
It could. Site Filter chooses which sites go through the VPN and is documented as tunnelling all sites by default. A site left outside the selection is reached over your ordinary connection.
Does StealthVPN change what a leak test can see?
Not directly. Astrill presents StealthVPN as obfuscation that makes traffic hard for firewall systems to identify. Which address a website observes is decided by routing, not by how the packets look.
Can this page tell me which applications are protected?
No. A page in the browser cannot read the configuration of a desktop application. The App Guard list has to be opened in Astrill itself before a reading here can be interpreted.
Why did the fingerprint values not move?
Screen metrics, fonts and language are reported by the browser rather than by the network, so a tunnel does not change them. That is expected here and is not a sign that anything failed.
Other provider self-tests
The same current-session checks, walked through for another provider. Listed alphabetically; this is not a ranking or a comparison.