MyIPScan

Provider-neutral self-test pilot

Hotspot Shield Leak Test

Hotspot Shield's own settings guide documents split tunnelling, which it also calls Smart VPN, in two opposite modes: Bypass VPN sends the apps and websites you list around the tunnel, and Route via VPN sends only the ones you list through it. The Windows app carries an Advanced section with four entries, kill switch, Prevent IP leak, local network and auto-protect, and the Mac section of the same guide lists no equivalent to Prevent IP leak. Its protocol menu offers Automatic, its own Hydra, IKEv2 and WireGuard, with Automatic described as choosing one for your network. Those settings decide most of what the checks return, so read the output as a description of this browser rather than of Hotspot Shield's network.

Read methodology

Live test

Run the test on Hotspot Shield now

Read the address line first. Hotspot Shield documents a Route via VPN mode in which only the websites you listed go through the tunnel, and everything else keeps using your normal connection.

Open the full VPN Leak Test

Current-session checks

What this Hotspot Shield self-test checks

Take each reading once before connecting and once after. On Hotspot Shield, open your split tunnelling lists first, because a site sitting in the wrong list changes the address line before any other setting gets a chance to.

Before you read the result

What Hotspot Shield documents about these signals

The points below come from Hotspot Shield's own app features and settings guide and its support centre articles. Knowing which setting sits on which platform is what separates an expected reading from one worth chasing.

Smart VPN decides what is tunnelled at all

Hotspot Shield documents split tunnelling under the second name Smart VPN, and it works in two opposite directions. Bypass VPN sends the apps and websites you add around the tunnel while everything else uses it. Route via VPN inverts that: only the entries you added go through, and the rest use your normal internet connection. On Route via VPN, an address check against a site you never listed is documented to show your own address.

Prevent IP leak is a Windows entry

The Advanced section of the Windows app carries four settings: kill switch, Prevent IP leak, local network and auto-protect. Hotspot Shield describes Prevent IP leak as stopping sites, cache or cookies from revealing your IP, and adds that your public IP has already changed the moment you connect. The Mac section of the same guide lists start on launch, auto-connect, always-on, notify on public WiFi, appearance, restore purchase and split tunnelling, with no equivalent entry, so which machine you are testing from decides whether that setting exists to check.

The switch has a different name on each platform

Hotspot Shield files the kill switch under Advanced on Windows, calls it Internet Killswitch on Android and Kill Switch on iOS, and describes each as blocking internet traffic while you are disconnected from the VPN. iOS additionally carries an Always-on VPN setting the guide says cannot be disabled, and which reconnects on its own. If a reading surprises you, the platform you are on decides which of those you are looking for.

Automatic picks the protocol for you

The protocol menu lists Automatic, Hydra, IKEv2 and WireGuard, and Hotspot Shield describes Hydra as its own proprietary protocol. Automatic is documented as picking a protocol for your network rather than leaving the choice with you. The transport carrying this session is therefore not necessarily the one that carried the last, which is worth noting when two readings taken days apart disagree.

A virtual location is an assignment

Hotspot Shield calls its servers virtual locations, and its support centre defines one as a way to change your location to a specified country by assigning you an address there. That is a statement about the address you are handed, not about a building you are routed to. Compare the country a geolocation lookup reports against the virtual location you selected in the app, rather than against where you happen to be sitting.

Between the readings

Record a kill-switch drop on Hotspot Shield

Hotspot Shield documents a switch that stops the data flow if the VPN suddenly disconnects, filed under Advanced on Windows, named Internet Killswitch on Android and Kill Switch on iOS. Whether it caught a real drop on your device, and how many seconds passed first, is what a recording adds to a single reading.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Hotspot Shield

  1. Note the visible address, which resolver answered and whether IPv6 answered at all on your normal connection.
  2. Open Hotspot Shield, check the split tunnelling lists so you know whether this browser is meant to be tunnelled, pick a virtual location and connect.
  3. Rerun the same checks in the same browser and the same profile, without switching either.
  4. Expect the address to move to the virtual location you chose. If Route via VPN is on and the site you tested was never added to the list, an unchanged address is the documented behaviour.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Hotspot Shield leak test FAQ

What is Smart VPN on Hotspot Shield?

Smart VPN is Hotspot Shield's other name for split tunnelling. Bypass VPN sends the apps and websites you list around the tunnel; Route via VPN sends only the ones you list through it, and everything else uses your normal connection.

My address has not changed. Where does Hotspot Shield say to look?

Its own settings guide points at the split tunnelling lists. Under Route via VPN only the entries you added travel through the tunnel, so an unchanged address on any other site matches how that mode is documented to work.

What does the Prevent IP leak setting do?

Hotspot Shield documents it in the Advanced section of the Windows app and describes it as preventing sites, cache or cookies from revealing your IP while you are connected. The Mac section of the same guide does not list an equivalent setting.

Which protocol is actually carrying my session?

Hotspot Shield offers Automatic, Hydra, IKEv2 and WireGuard, and documents Automatic as picking a protocol for your network. Hydra is described as its own proprietary protocol. The choice lives in the app, not in the browser.

Does Hotspot Shield answer my DNS queries?

Its support centre states that Hotspot Shield encrypts the DNS request and that this is what prevents DNS leaks. The same article notes the request may not travel through the tunnel itself, so a checker that looks only at the route can read the same session differently.

The app says one country and a lookup says another. What now?

Hotspot Shield defines a virtual location as assigning you an address for a specified country. Geolocation databases map addresses independently and are not complete, so compare the reading against the location you selected in the app.