Before you read the result
What ExpressVPN documents about these signals
Everything below is drawn from ExpressVPN's own feature and support pages. Knowing the intended behaviour first is what lets you tell a normal reading from one worth chasing.
Private DNS on every server
ExpressVPN states that it runs private, encrypted DNS on every VPN server rather than passing queries to an outside resolver. A DNS check while connected should therefore show ExpressVPN infrastructure answering, not your ISP and not a public resolver. Your ISP's resolver appearing in the result is the reading that deserves a closer look.
The kill switch covers IPv6 too
ExpressVPN describes the Internet Kill Switch as blocking IPv4, IPv6 and DNS traffic outside the encrypted tunnel rather than letting IPv6 fall back to the local interface. In practice that means an IPv6 check normally returns nothing while you are connected, and an IPv6 address matching your home network is worth investigating.
Where to find the setting
If a check shows an address you did not expect, the first setting to confirm is Network Lock, which ExpressVPN says is enabled by default. It lives in the app's preferences, not in your browser, and the app labels it Internet Kill Switch rather than Network Lock.
Routers change what you are testing
ExpressVPN lists the kill switch as available on Windows, Mac, Linux, routers, Android and iOS. That last one matters here: when the tunnel is established by a router, a browser check run on a device behind it is measuring the router's connection, and nothing you change in a desktop app will move the result.
What the app cannot reach
WebRTC runs inside the browser. With the whole system routed through the app, WebRTC candidates should carry the tunnel address, but a browser extension, a second adapter or a split-tunnel rule can change that. ExpressVPN's TrustedServer claim that its servers run in RAM only is a statement about the server, not about your session; only the checks here speak for your browser.