MyIPScan

Provider-neutral self-test pilot

CyberGhost Leak Test

CyberGhost does not support IPv6, and its support site carries per-platform guides for turning IPv6 off on Windows, macOS, Linux and Android. That is the context an IPv6 leak test needs here: an empty IPv6 line is the documented behaviour, and an IPv6 address that still belongs to your own connection is the reading to act on. Read the output as a statement about this browser, not about CyberGhost's servers.

Read methodology

Live test

Run the test on CyberGhost now

CyberGhost does not carry IPv6, so an empty IPv6 line below is the documented behaviour. An address that still belongs to your own connection is the one worth chasing.

Open the full VPN Leak Test

Current-session checks

What this CyberGhost self-test checks

Open each tool once before connecting and once after. On CyberGhost the IPv6 line and the resolver tell you most, because both follow from choices CyberGhost has published.

Before you read the result

What CyberGhost documents about these signals

CyberGhost's support centre and feature pages are the source for each point below. They explain most of the readings this page can produce.

IPv6 is not carried

CyberGhost does not support the IPv6 protocol, and its support centre publishes separate instructions for disabling IPv6 on Windows, on macOS, and on Linux via Network Manager. An IPv6 check that returns nothing while you are connected matches that. An IPv6 address tied to your own network is the case where those instructions are the documented fix.

Smart DNS is not the VPN

CyberGhost sells Smart DNS as a separate product that changes only your DNS servers, pointing them at CyberGhost resolvers, and states that it does not change your IP address or encrypt the connection. If you configured Smart DNS on a device rather than running the VPN app, an IP check showing your own address is that product working as described, not a leak.

The kill switch is what stands between a drop and a leak

CyberGhost describes an automatic kill switch that cuts internet traffic when the VPN connection drops, and restores it once the tunnel is back. If a check shows your own address, the question is whether the tunnel was up at that moment, and the kill switch setting in the app is where to start.

Some servers are CyberGhost's own hardware

CyberGhost operates what it calls NoSpy servers in a data centre it runs itself, with only its own staff having physical access. Which server you picked therefore changes what an ASN lookup on your exit address returns, so compare the network behind the address against the location you actually selected in the app.

Published audits cover the policy, not your session

CyberGhost has commissioned independent reviews of its no-logs policy from Deloitte, first in 2022 and again in 2024. Those reports speak to what CyberGhost stores. They say nothing about the WebRTC and fingerprint values your browser produces locally, which are what the checks on this page read.

Between the readings

Record a kill-switch drop on CyberGhost

CyberGhost describes a kill switch that cuts internet traffic when the connection drops and restores it once the tunnel is back. Whether that happened on your machine, and how many seconds passed before it did, is not something a single reading can answer.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on CyberGhost

  1. Note the visible address, the resolver and the IPv6 result on your normal connection first.
  2. Connect with the CyberGhost app, confirming the kill switch is enabled and noting which server location you chose.
  3. Rerun the checks in the same browser so the comparison is like for like.
  4. Expect the address and resolver to change and the IPv6 line to stay empty. If only Smart DNS is configured, the address is meant not to change.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

CyberGhost leak test FAQ

Does CyberGhost support IPv6?

No. CyberGhost does not support the IPv6 protocol and publishes per-platform guides for disabling it. An empty IPv6 result while connected is consistent with that design.

The IPv6 check still returns an address. What is CyberGhost's answer?

CyberGhost's own documented answer is to disable IPv6 on the device, and its support centre has separate articles for Windows, macOS and Linux. Check the IPv6 tool again after applying the change for your platform.

I set up Smart DNS and my IP has not changed. Is that a leak?

No. CyberGhost describes Smart DNS as changing only your DNS servers, without changing your IP address or encrypting the connection. An unchanged address is how that product is documented to behave.

What does CyberGhost's kill switch actually do?

CyberGhost describes it as automatically cutting internet traffic if the VPN connection drops, and restoring it when the tunnel returns. It is the setting to confirm when a check reports an address you did not expect.

What are NoSpy servers, and do they change my result?

CyberGhost describes NoSpy servers as machines in a data centre it operates itself. Which location you connect to changes the network behind your exit address, so an ASN lookup is worth comparing against the server you selected.

Has anyone checked CyberGhost's no-logs claim?

CyberGhost has published independent reviews of its no-logs policy carried out by Deloitte, in 2022 and again in 2024. Those cover what the provider stores, which is not something a browser check can observe.