MyIPScan

Provider-neutral self-test pilot

Mullvad Leak Test

Mullvad is unusual on three of the axes these checks measure. Its kill switch is always on and cannot be disabled in settings. IPv6 is a setting you turn on rather than one that is on already, on Windows and Linux. And Mullvad announces its exit addresses from its own autonomous system, so an ASN lookup names Mullvad rather than a hosting company. Everything below describes one browser on one connection; it settles nothing about Mullvad's fleet as a whole.

Read methodology

Live test

Run the test on Mullvad now

Mullvad cannot have its kill switch turned off and IPv6 is opt-in, so an empty IPv6 line is expected here. The network line should name Mullvad rather than your ISP.

Open the full VPN Leak Test

Current-session checks

What this Mullvad self-test checks

Work through the tools once before you connect and once after. On Mullvad the interesting comparison is the ASN behind your exit address and whether IPv6 answers at all, because both follow from choices Mullvad has made and documented.

Before you read the result

What Mullvad documents about these signals

These points come from Mullvad's help pages and its published audit posts, and they set the baseline your own result should be compared against.

A kill switch you cannot turn off

Mullvad's help pages describe the kill switch as always on and impossible to disable in settings: it is active from the moment you press Connect until you disconnect. Separately, an optional Lockdown mode keeps blocking the internet even after you press Disconnect or Quit. So on Mullvad there is no kill-switch toggle to blame for an unexpected reading - look at Lockdown mode and at what was running outside the app instead.

IPv6 is opt-in, not automatic

Mullvad states that on Windows and Linux IPv6 is normally not needed and is something you enable if you have a reason to, while on a Mac it should normally be enabled or some sites will not load. That means an empty IPv6 result on Windows usually reflects the default rather than a fault, and an IPv6 address appearing after you enabled the setting is expected.

The exit sits in Mullvad's own network

Mullvad announces address space from its own autonomous system, AS39351, rather than only reselling hosting capacity. That makes the ASN behind your exit address a usable confirmation: see AS39351 on MyIPScan for what a lookup returns, and the ranges Mullvad announces for the prefixes involved. Mullvad also documents using colocated hardware, so not every server is guaranteed to land in that ASN.

Custom DNS overrides the content blockers

Mullvad supports setting your own DNS server in the app's advanced settings, and documents that doing so overrides its DNS content blockers. It also notes that a public DNS server can only be used on WireGuard, while a local one works with OpenVPN. If a DNS check names something other than Mullvad, that setting is the first place to look.

Browser signals and published audits

WebRTC and fingerprint readings come from the browser, which the VPN app does not rewrite. Mullvad ships Mullvad Browser, built with the Tor Project as a Tor Browser without the Tor network, precisely because those signals live outside the tunnel. Mullvad also publishes audit reports: X41 D-Sec audited the app over 30 person-days in late 2024 and Cure53 completed a fourth infrastructure audit in June 2024.

Between the readings

Record a kill-switch drop on Mullvad

Mullvad's help pages describe a kill switch that is always on and cannot be disabled in settings. That makes a recorded drop a check of the outcome rather than of the checkbox: nothing to switch off, so watch what actually got out.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Mullvad

  1. Before connecting, note the visible address, the ASN it belongs to, and whether IPv6 answers.
  2. Connect with the Mullvad app. There is no kill switch to enable; if you use Lockdown mode, note that it keeps blocking after you quit.
  3. Rerun the checks in the same browser and look at the ASN on the new address.
  4. The ASN should move to Mullvad's own AS39351, and IPv6 should follow whatever you set the IPv6 option to.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Mullvad leak test FAQ

Does Mullvad have a kill switch I need to switch on?

No. Mullvad documents the kill switch as always on and not disableable in settings, active from the moment you press Connect. Lockdown mode is a separate optional setting that also blocks the internet after you disconnect or quit.

Why does the IPv6 check return nothing on Mullvad?

On Windows and Linux, Mullvad treats IPv6 as an option you enable when you need it rather than a default. An empty IPv6 reading on those platforms usually reflects that setting. Mullvad advises Mac users to leave IPv6 enabled.

Should my exit address belong to AS39351?

Mullvad announces address space under its own AS39351, so a lookup on your exit address naming Mullvad is a strong confirmation the tunnel is carrying your traffic. Mullvad also uses colocation, so treat a different network as a question to investigate rather than proof of a leak.

Why is my DNS check not naming Mullvad?

A custom DNS server set in the app's advanced settings takes precedence and also overrides Mullvad's content blockers. Mullvad additionally documents that a public DNS server only works over WireGuard, so protocol choice can change the result.

Does Mullvad publish independent audits?

Yes. Mullvad publishes the reports on its own blog: X41 D-Sec audited the apps across platforms in late 2024, and Cure53 completed a fourth infrastructure audit in June 2024. Those are claims about Mullvad's code and servers, not about your browser session.

Why does my browser fingerprint look the same as before?

A VPN moves your network path; it does not rewrite the browser. Fingerprint and WebRTC signals are produced locally, which is the reason Mullvad ships a separate hardened browser rather than trying to fix them from the VPN app.