MyIPScan

Provider-neutral self-test pilot

Edge Secure Network Leak Test

Microsoft documents Edge Secure Network as a service run in partnership with Cloudflare, and it differs from a VPN application in three ways that change how a leak test should be read. It comes with a monthly data allowance. It deliberately gives you an address geographically similar to the one you already had. And on its recommended setting most of your browsing is not routed through it at all. What you see below describes this browser in this session.

Read methodology

Live test

Run the test on Edge Secure Network now

Edge Secure Network is documented as giving you an address in a similar region, and on its default setting only unsecure traffic is routed, so a familiar-looking result is often the design.

Open the full VPN Leak Test

Current-session checks

What this Edge Secure Network self-test checks

Take one reading with the feature off and one with it on, and settle which of the three modes you are in first, because that decides whether this page was routed at all.

Before you read the result

What Edge Secure Network documents about these signals

Every point below is stated in Microsoft's own support material for the feature rather than inferred from how it behaves.

Three modes, and the default routes very little

Microsoft lists three settings. Optimized, the recommended one, routes only unsecure traffic, such as when you are on public Wi-Fi or visiting a site without a valid certificate, and excludes streaming and video content. Select sites lets you mark individual sites as always using it. All sites routes everything you browse. On Optimized an ordinary secure page is not routed, so a check showing your own address is that mode working.

The address is meant to look like home

Microsoft describes the service as replacing your geolocation with a similar regional address, so that websites and services see a location geographically similar to yours and local results still work. It also states that you cannot select a specific region or location for your traffic. A result that places you near where you actually are is the documented outcome, not a failure to connect.

There is a monthly allowance

Microsoft documents 5 GB of data every month when you are signed in to Edge with a personal Microsoft account, and says the browser tells you how much is left and when the allowance resets. That is a limit a VPN application does not impose, and it matters here: two readings taken days apart can differ for no reason other than the allowance having run out in between.

Cloudflare operates it, and Microsoft says what is kept

Microsoft names Cloudflare as the provider, acting as its data subprocessor, and states that the diagnostic and support data collected is stored briefly in temporary logs and then permanently deleted within 25 hours. It also states that your Microsoft account identity is never shared with the service provider. Those are claims about the operators and their retention, not about what your browser exposed.

It lives inside one browser

The setting sits in Edge's own privacy and security settings, and the traffic it covers is Edge's traffic. Everything else on the machine keeps its ordinary path. A check run in a different browser therefore measures your normal connection and settles nothing at all about this feature, however clean or alarming the result looks.

Between the readings

Record a kill-switch drop on Edge Secure Network

No kill switch is documented for this feature, and the monthly allowance is a second way protection can end mid-session. Recording the moment your address changes back is how you tell which of the two happened.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Edge Secure Network

  1. Note the address, the resolver and any IPv6 result with the feature switched off.
  2. Switch it on in Edge and note which of the three modes is selected, because Optimized routes very little.
  3. Rerun the same checks in Edge itself rather than in another browser.
  4. Expect a location that still looks close to yours, and on Optimized expect an ordinary secure page not to be routed at all.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Edge Secure Network leak test FAQ

Who actually runs Edge Secure Network?

Microsoft documents it as a service provided in partnership with Cloudflare, with Cloudflare acting as its data subprocessor. Microsoft also states that your Microsoft account identity is never shared with that provider.

Why does my location still look correct?

Microsoft describes the service as replacing your geolocation with a similar regional address so that local results keep working, and states that you cannot select a specific region. A nearby location is the documented behaviour.

Why was this page not routed through it?

On the recommended Optimized setting, Microsoft documents only unsecure traffic as being routed, with streaming and video content excluded. An ordinary secure page is left alone, so the check reports your own address.

How much data do I get each month?

Microsoft documents 5 GB of data every month when you are signed in to Edge with a personal Microsoft account, and says the browser tells you how much remains and when it resets.

Does it protect anything outside Edge?

The setting lives in Edge and covers Edge's browsing. Other applications on the machine keep their ordinary path, so a check in another browser describes your normal connection rather than this feature.

How long does Cloudflare keep data about my session?

Microsoft states that diagnostic and support data is stored briefly in temporary logs and permanently deleted within 25 hours. That is a statement about the operator's retention, which no browser check can verify.