MyIPScan

Provider-neutral self-test pilot

Kaspersky VPN Leak Test

Two things Kaspersky documents change what these checks return. The application is launched automatically when the operating system starts, but the traffic encryption is not: Kaspersky states that encryption only starts with explicit user consent. And by default traffic goes through the quickest virtual server available at the time, which the same page notes could be located in another country, with a choice of region reserved for the paid version. Read what follows as a description of your own browser and this one session, not of Kaspersky's network.

Read methodology

Live test

Run the test on Kaspersky VPN now

Read the address line first. Kaspersky documents that the app launching and the encryption running are two separate events, so your own address here can mean protection was never switched on for this session.

Open the full VPN Leak Test

Current-session checks

What this Kaspersky VPN self-test checks

Take a reading before connecting, and a second one only once the app reports that protection is on rather than merely that it is running. On Kaspersky the address line and the resolver carry the most information, because both follow from choices its documentation spells out.

Before you read the result

What Kaspersky VPN documents about these signals

Each point below is drawn from Kaspersky's own knowledge base article on the product and its online help. Together they cover most of what the checks on this page can return.

The app starting is not the tunnel starting

Kaspersky documents that by default the application, and not the traffic encryption itself, is automatically launched when the operating system starts. The app then watches for situations where encryption could be useful and offers to switch it on. Traffic encryption only starts with explicit user consent. A check returning your own address is consistent with the app running while protection was never enabled, which is the first thing to rule out.

The exit servers belong to a partner

Kaspersky states that the servers used by the product sit in regions including the USA, Germany and Singapore, and that they are provided by its partner, the software company Pango. A lookup on the network behind your exit address will therefore name that infrastructure rather than Kaspersky itself. Knowing this beforehand stops an unfamiliar network name reading as evidence that something went wrong.

You can hand it your own resolver

The paid version carries a setting called Use custom DNS over HTTPS server, and Kaspersky notes that to set one up you need to turn off the VPN first. If you have ever used it, the resolver named on the DNS line is the one you configured rather than a default of the product. A name you do not recognise on that line may simply be an entry you made and forgot.

Kill Switch ships turned off

Kaspersky documents Kill Switch as blocking your Internet access if the secure connection is interrupted, and states plainly that by default the feature is turned off and the application does not block Internet access when that happens. It is reached through the application settings. Confirm its state before reading anything into a single result.

Split tunneling rules follow file paths

Kaspersky's split tunneling settings hold two lists, Do not use VPN and Use VPN, each populated through a Select button. Its documentation adds a caveat worth knowing: the settings for selected applications are applied to the specified paths only, so if a path changes because an application was updated, the settings will not be automatically applied to it. A browser that was excluded, or has quietly stopped being included, changes every reading below.

Between the readings

Record a kill-switch drop on Kaspersky VPN

Kaspersky's own limitations list says the secure connection may be briefly interrupted when the app changes virtual server region or when the computer changes network, and that data transmitted in that window is not protected. Kill Switch is documented as off by default, which makes the length of that window the thing worth recording rather than guessing.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Kaspersky VPN

  1. Record the visible address, the resolver and any IPv6 result on your ordinary connection before opening the app.
  2. Open Kaspersky VPN and switch protection on explicitly rather than assuming the running app has done it, then note which region the app reports.
  3. Rerun the same checks in the same browser, without changing profile or network in between.
  4. Expect the address to move to the region shown in the app. On the free version the server is chosen for you, so landing in a country you did not select is the documented outcome.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Kaspersky VPN leak test FAQ

Does Kaspersky VPN protect me as soon as the app starts?

No. Kaspersky documents that the application is automatically launched when the operating system starts but the traffic encryption is not. Encryption only starts with explicit user consent.

Whose network does my exit address belong to?

Kaspersky states that the servers it uses are provided by its partner, the software company Pango, in regions including the USA, Germany and Singapore. An unfamiliar network name on a lookup follows from that arrangement.

Why did I end up in a country I did not pick?

By default Kaspersky routes traffic through the quickest virtual server available at the time, which its documentation notes could be located in another country. Selecting a region is a feature of the paid version rather than the free one.

Is the Kill Switch on by default?

No. Kaspersky documents that by default the Kill Switch is turned off and the application does not block your Internet access if the secure connection is interrupted. It is switched on from the settings in the app.

Can I choose which resolver answers for me?

The paid version includes a setting named Use custom DNS over HTTPS server, and Kaspersky notes that to set one up you need to turn off the VPN. The DNS check on this page reports whichever resolver actually answered.

Why did my split tunneling rule stop applying?

Kaspersky documents that VPN settings for selected applications are applied to the specified paths only. If a path is changed, for example because an application from the list is updated, the settings will not be automatically applied to it.