Mozilla VPN is the clearest case on this list of a product whose exit belongs to somebody else. Mozilla states that Mozilla VPN is built on top of Mullvad VPN infrastructure and uses the same servers, and that the connection runs on WireGuard. So the network name attached to your address after connecting will often read Mullvad rather than Mozilla, and that is the documented arrangement rather than a mismatch worth worrying about.
Read the signals before and after connecting. On Mozilla VPN the line that surprises people is the network name, because the servers are Mullvad's and are documented as such.
The points below come from Mozilla's own product pages and support articles for Mozilla VPN.
The exit belongs to Mullvad's network
Mozilla says plainly that Mozilla VPN is built on top of Mullvad VPN infrastructure and uses the same servers. A lookup on your address after connecting can therefore name Mullvad, or the hosting company behind a Mullvad site, and still be exactly right. Reading that as evidence of a misconfigured tunnel is the common mistake here.
WireGuard is the protocol
Mozilla describes the service as running on WireGuard, which it calls one of the most performant VPN protocols. For a reading on this page the protocol matters only indirectly: it decides how the tunnel is built, not which address is presented. What you can check is whether the address changed at all.
One subscription, up to five devices
Mozilla documents a limit of five simultaneous devices on a subscription. If a device silently fails to connect because the limit was reached, the checks here will report an ordinary connection with no error attached. That is one of the few cases where a plain reading is the first hint that a subscription rather than a setting is in the way.
Two products that share a server list
Because the infrastructure is shared, the network characteristics you can observe from a browser are largely Mullvad's. MyIPScan keeps a separate walkthrough for that provider at the Mullvad self-test, and the two pages describe different products over a common set of exits rather than one product written up twice. Where they differ is in what each company publishes about its own client, and it is the client rather than the server that decides most of what a check like this one can see.
What Mozilla does not document here
Mozilla's own help pages for the product do not set out IPv6 handling or resolver addresses in the way some providers on this list do, so this page states neither. That gap is worth naming rather than papering over: if your IPv6 line has content, treat it as a question to put to the provider rather than as something settled by anything published here or inferred from the shared infrastructure. A page that guessed would be easier to read and worse to rely on.
Between the readings
Record a kill-switch drop on Mozilla VPN
The checks on this page sample a Mozilla VPN session once. What happens between a dropped tunnel and a restored one is a sequence, and a sequence needs more than one reading to describe.
This does not test every server, app, device, or connection.
This does not prove anonymity.
This does not prove every security condition.
A clean result does not prove every leak is absent.
How to compare before and after on Mozilla VPN
Note the address and the network name it resolves to before connecting.
Connect with Mozilla VPN and let the client settle before testing again.
Rerun the checks in the same browser and read the network name carefully.
Treat a name pointing at Mullvad as consistent with what Mozilla documents.
Safe Copy limits
Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.
FAQ
Mozilla VPN leak test FAQ
Why does my address look like Mullvad?
Because Mozilla states that Mozilla VPN is built on top of Mullvad VPN infrastructure and uses the same servers. A lookup naming Mullvad is the documented arrangement rather than an error.
Which protocol does Mozilla VPN use?
Mozilla describes the service as running on WireGuard. The protocol decides how the tunnel is negotiated; it does not by itself change which address a website records for you.
How many devices can connect at once?
Mozilla documents up to five devices on an active subscription. A device that quietly fails to connect at the limit will produce a reading that simply looks like no VPN at all.
Does Mozilla publish its IPv6 behaviour?
Its own help pages for the product do not set out IPv6 handling the way some providers do, so nothing is claimed about it here. Ask the provider before drawing a conclusion from the IPv6 line.
Is this page the same as the Mullvad one?
No. They cover two products that share a server list. The Mullvad walkthrough describes that provider's own documented behaviour, which is not automatically what Mozilla publishes for its product.
What can this check settle on its own?
Whether the address, resolver and WebRTC candidates your browser presented changed between the two readings. Anything about the servers behind them is outside what a browser can observe.
Other provider self-tests
The same current-session checks, walked through for another provider. Listed alphabetically; this is not a ranking or a comparison.