Apple documents Private Relay in terms narrow enough to change what a leak test means. It covers web browsing in Safari, DNS resolution queries and insecure HTTP traffic, and sends requests through two separate relays run by different parties so that no single one of them, Apple included, holds the whole picture. The address presented is chosen to represent your city accurately by default. None of that describes a device-wide tunnel, and readings should be taken with that in mind.
Private Relay covers Safari browsing, DNS and insecure HTTP, so a check run in another browser measures your ordinary connection rather than telling you anything about the feature.
Take a reading in Safari with the feature off and another with it on. Anywhere else on the device the result describes your ordinary connection, because that is the documented scope.
What iCloud Private Relay documents about these signals
The points below come from Apple's own support and developer documentation describing what Private Relay covers and how it is built.
Safari, DNS and plain HTTP, and nothing else
Apple states that Private Relay protects web browsing in Safari, DNS resolution queries and insecure HTTP application traffic. Traffic from applications that use ordinary encrypted connections of their own is outside it. A reading taken in another browser is therefore an accurate description of your connection and no description at all of this feature.
Two relays, two different operators
Apple describes a multi-hop arrangement in which requests travel through two separate internet relays operated by different entities, so that no single party including Apple can view or collect the details of browsing activity. The first is documented as knowing your address but not the site you are visiting; the second as knowing the site but not your address. From the outside you meet only the second, which is why a lookup on the address you end up with does not obviously point at Apple, and why an unfamiliar network name in the result is the design rather than a symptom.
The address is chosen to match your city
Apple documents the relay address presented to networks and web servers as accurately representing the coarse city-level location of the client by default, so that location-dependent services still work. There is a broader region setting as an alternative. A result that places you near home is the default behaving as described.
This is not a device-wide tunnel
Everything Apple documents about the coverage points the same way: a defined set of traffic rather than everything a device sends. Comparing a reading here with one taken behind a full tunnel compares two different products, and the comparison will mislead in the direction of thinking something has failed.
What a browser check can still settle
Whether the address your browser presented changed between the two readings, which resolver answered, and what WebRTC produced. Those remain useful answers. They are just answers about Safari on this device, rather than about everything the device is doing.
Between the readings
Record a kill-switch drop on iCloud Private Relay
There may be no app to quit here, so force the change the way it happens to you: switch network, or turn the feature off in settings. The recording captures the moment the visible address changes back.
This does not test every server, app, device, or connection.
This does not prove anonymity.
This does not prove every security condition.
A clean result does not prove every leak is absent.
How to compare before and after on iCloud Private Relay
Take a reading in Safari with Private Relay switched off.
Switch it on and let the setting take effect before testing again.
Repeat the checks in Safari, not in another browser.
Expect the location to stay close to your city, since that is the documented default.
Safe Copy limits
Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.
FAQ
iCloud Private Relay leak test FAQ
What traffic does Private Relay cover?
Apple documents it as protecting web browsing in Safari, DNS resolution queries and insecure HTTP application traffic. Other application traffic is outside that scope.
Why does my location still look right?
Apple describes the relay address as accurately representing the coarse city-level location of the client by default, with a broader region setting available. A nearby location is the default working as documented.
Who can see my address?
Apple describes two relays run by different entities, arranged so no single party including Apple can view or collect the details of browsing activity. The first knows your address, the second knows the destination.
Should I test this from Chrome or Firefox?
No. The documented coverage is Safari browsing along with DNS and insecure HTTP. A reading from another browser will describe your ordinary connection and settle nothing about the feature.
Is this the same as a VPN?
Apple documents a defined set of traffic rather than a device-wide tunnel, so the two are not interchangeable. Reading a result here as if it came from a full tunnel is the usual source of confusion.
Can this page confirm which relay served me?
No. It reports what your browser exposed to this site. The internal arrangement between the two relays is not observable from a web page, and nothing here should be read as describing it.
Other provider self-tests
The same current-session checks, walked through for another provider. Listed alphabetically; this is not a ranking or a comparison.