MyIPScan

Provider-neutral self-test pilot

Cloudflare WARP Leak Test

Cloudflare WARP is designed against a different goal from most of this list, and the documentation is unusually direct about it. Cloudflare says WARP replaces your original address with a Cloudflare address that consistently and accurately represents your approximate location. It also warns that granting a website microphone or camera access sends that traffic around WARP, making your original address visible. Both statements change what a reading below means before you have read a single line of it.

Read methodology

Live test

Run the test on Cloudflare WARP now

WARP is meant to give you an address that still matches your rough location, so a result placing you near home is the documented behaviour rather than a failure.

Open the full VPN Leak Test

Current-session checks

What this Cloudflare WARP self-test checks

Read the signals before and after enabling WARP. The line to watch is location: Cloudflare designs the replacement address to stay accurate about where you are.

Before you read the result

What Cloudflare WARP documents about these signals

The points below come from Cloudflare's own client documentation and its published notes on how WARP behaves.

The address is meant to describe your location

Cloudflare states that WARP replaces your original address with a Cloudflare address that consistently and accurately represents your approximate location. Read against that, a result that still places you in roughly the right city is the product working as documented. Providers built to move your apparent location behave differently, and comparing the two on that axis is a category error.

Camera and microphone access goes around it

Cloudflare's own FAQ warns that if you grant microphone or camera access to websites, that traffic will bypass WARP and your original address will be visible. This is the single most useful sentence on this page, because the browser machinery behind those permissions is the same machinery a WebRTC check exercises.

DNS is part of the product

Cloudflare describes WARP as powered in part by its 1.1.1.1 resolver, and its client documentation covers sending device queries to Cloudflare over an encrypted channel using DNS over HTTPS. A DNS reading naming Cloudflare is therefore the expected outcome here rather than a coincidence worth investigating. The exit address sits in Cloudflare's own network too, so a lookup on it lands in the same place: see AS13335 on MyIPScan for what that lookup returns and the address space Cloudflare announces for the ranges behind it.

IPv6 needs the platform to cooperate

Cloudflare documents IPv6 as an area where the client can conflict with the operating system, noting on Windows that the Teredo interface fights the client for control of IPv6 routing and has to be disabled for the client to provide IPv6 connectivity. Its known-limitations page also describes environments where IPv6 DNS servers need excluding from the tunnel by hand before things behave. An odd IPv6 line on Windows is worth reading against both of those before anything else is suspected.

Why this reads differently from a location-shifting tunnel

Everything above follows from a product that aims to encrypt the path without pretending you are somewhere else. If your reason for testing is whether a site can tell which country you are in, the honest answer from Cloudflare's own documentation is that WARP is not built to hide it, and a reading that reflects that is the product working. Comparing the result against a provider whose whole purpose is moving your apparent location will make a correctly working client look broken.

Between the readings

Record a kill-switch drop on Cloudflare WARP

This page makes no claim about how Cloudflare WARP behaves when it stops. What a recording gives you instead is the plain sequence for your own session: which address was visible, when it changed, and for how long.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Cloudflare WARP

  1. Take a reading with WARP off and note the address and the location shown.
  2. Turn WARP on and let the client report itself as connected.
  3. Repeat the checks in the same browser and compare the two locations.
  4. Expect the location to stay roughly right, and read the WebRTC line with camera and microphone permissions in mind.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Cloudflare WARP leak test FAQ

Does WARP hide my location?

Cloudflare says WARP replaces your original address with a Cloudflare address that consistently and accurately represents your approximate location. Staying in roughly the right place is the documented design.

Why would my original address still be visible?

Cloudflare's FAQ states that granting microphone or camera access to websites sends that traffic around WARP, at which point your original address becomes visible. It is worth reviewing those site permissions.

Which resolver answers while WARP is on?

Cloudflare describes WARP as powered in part by its 1.1.1.1 resolver, with device queries sent to Cloudflare over an encrypted channel. A DNS line naming Cloudflare is therefore expected.

Why is IPv6 behaving oddly on Windows?

Cloudflare documents the Windows Teredo interface as conflicting with its client over control of IPv6 routing, and says Teredo must be disabled for the client to provide IPv6 connectivity.

Is a reading that matches my city a leak?

Not on its own, given what Cloudflare documents. It is the stated behaviour of the product. Whether that suits you is a decision about which tool to use, not a fault to diagnose.

Does this page test Cloudflare's network?

No. It reports what your browser exposed in this session. Nothing here inspects Cloudflare's infrastructure or verifies any claim the company makes about it.