Before you read the result
What NetBird documents about these signals
Each point below is taken from NetBird's own documentation. Knowing what the product is designed to do is what stops an unchanged reading from looking like a failure.
There is no centralized VPN server
NetBird documents itself as an open source zero trust networking platform, and states that there is no centralized VPN server with NetBird, because your computers, devices, machines and servers connect to each other directly over a fast encrypted tunnel. Carrying general internet traffic is an optional exit node configuration rather than something the client does on its own. An IP check taken with the client connected that returns your own address is therefore the documented outcome, not a sign the tunnel failed to come up.
Overlay addresses live in the CGNAT block
NetBird's management service assigns each peer a unique address from one of 64 possible /16 blocks within the carrier grade NAT range 100.64.0.0/10, with the block selected randomly per account and customisable, and gives every peer a name inside a private netbird.cloud space. That address is how your peers reach one another. It is not what a website sees, which is why the address shown in the NetBird client and the address reported on this page are expected to differ.
Exit nodes are the setting that moves the IP
An exit node in NetBird is a routing peer that carries a device's internet-bound traffic, and NetBird documents it as applying masquerading so that traffic appears to originate from the routing peer's public IP address. It has to be configured first, and an Auto Apply option, which requires client version 0.55.0 or later, lets a configured exit node activate automatically while still allowing a user to disable it on their own device. If your visible address did change, an exit node is the first thing to account for.
DNS is answered on the peer itself
NetBird runs a local resolver on each peer, documented as running on 100.x.255.254 port 53 in userspace mode, where x is the second octet of your account's /16 block. Managed Mode is the default and lets NetBird control DNS settings, while Unmanaged Mode leaves the peer's existing configuration untouched. Only macOS, Windows 10 and later, and Linux with systemd-resolved support nameservers with match domains, and NetBird notes that without a nameserver set to match domain ALL, devices keep sending DNS queries to their local resolver outside the tunnel.
IPv6 here is overlay addressing
NetBird's IPv6 overlay addressing requires client version 0.71.0 or later, and gives each account a unique IPv6 prefix from which peer addresses are allocated, with a /64 default and valid lengths from /48 through /120. New accounts have it enabled for the All group, while existing accounts enable it from the dashboard under Settings and then Network. That addressing applies between peers inside the overlay, so the public IPv6 reading on this page continues to follow your own connection rather than anything NetBird provides.