Before you read the result
What CyberGhost documents about these signals
CyberGhost's support centre and feature pages are the source for each point below. They explain most of the readings this page can produce.
IPv6 is not carried
CyberGhost does not support the IPv6 protocol, and its support centre publishes separate instructions for disabling IPv6 on Windows, on macOS, and on Linux via Network Manager. An IPv6 check that returns nothing while you are connected matches that. An IPv6 address tied to your own network is the case where those instructions are the documented fix.
Smart DNS is not the VPN
CyberGhost sells Smart DNS as a separate product that changes only your DNS servers, pointing them at CyberGhost resolvers, and states that it does not change your IP address or encrypt the connection. If you configured Smart DNS on a device rather than running the VPN app, an IP check showing your own address is that product working as described, not a leak.
The kill switch is what stands between a drop and a leak
CyberGhost describes an automatic kill switch that cuts internet traffic when the VPN connection drops, and restores it once the tunnel is back. If a check shows your own address, the question is whether the tunnel was up at that moment, and the kill switch setting in the app is where to start.
Some servers are CyberGhost's own hardware
CyberGhost operates what it calls NoSpy servers in a data centre it runs itself, with only its own staff having physical access. Which server you picked therefore changes what an ASN lookup on your exit address returns, so compare the network behind the address against the location you actually selected in the app.
Published audits cover the policy, not your session
CyberGhost has commissioned independent reviews of its no-logs policy from Deloitte, first in 2022 and again in 2024. Those reports speak to what CyberGhost stores. They say nothing about the WebRTC and fingerprint values your browser produces locally, which are what the checks on this page read.