MyIPScan

Provider-neutral self-test pilot

NetBird Leak Test

NetBird is not a consumer VPN subscription, and that changes almost every reading on this page. Its documentation describes an open source zero trust networking platform that builds a point-to-point WireGuard overlay between machines you control, and states plainly that there is no centralized VPN server with NetBird. Routing internet-bound traffic through it is an optional exit node configuration rather than a default, so an IP check normally returns the same address it returned before the client connected. The address NetBird hands your device comes from the carrier grade NAT block 100.64.0.0/10 and is meaningful only inside the overlay. Read what follows as an explanation of your own session rather than a verdict on NetBird.

Read methodology

Live test

Run the test on NetBird now

NetBird does not route general internet traffic by default, so the IP line below is expected to show your own address unless an exit node is in use. Read that line first, then the resolver.

Open the full VPN Leak Test

Current-session checks

What this NetBird self-test checks

Take a reading before the client is running and one after the peer joins the network. On NetBird the interesting comparison is often that nothing changed, which is what the documented default produces.

Before you read the result

What NetBird documents about these signals

Each point below is taken from NetBird's own documentation. Knowing what the product is designed to do is what stops an unchanged reading from looking like a failure.

There is no centralized VPN server

NetBird documents itself as an open source zero trust networking platform, and states that there is no centralized VPN server with NetBird, because your computers, devices, machines and servers connect to each other directly over a fast encrypted tunnel. Carrying general internet traffic is an optional exit node configuration rather than something the client does on its own. An IP check taken with the client connected that returns your own address is therefore the documented outcome, not a sign the tunnel failed to come up.

Overlay addresses live in the CGNAT block

NetBird's management service assigns each peer a unique address from one of 64 possible /16 blocks within the carrier grade NAT range 100.64.0.0/10, with the block selected randomly per account and customisable, and gives every peer a name inside a private netbird.cloud space. That address is how your peers reach one another. It is not what a website sees, which is why the address shown in the NetBird client and the address reported on this page are expected to differ.

Exit nodes are the setting that moves the IP

An exit node in NetBird is a routing peer that carries a device's internet-bound traffic, and NetBird documents it as applying masquerading so that traffic appears to originate from the routing peer's public IP address. It has to be configured first, and an Auto Apply option, which requires client version 0.55.0 or later, lets a configured exit node activate automatically while still allowing a user to disable it on their own device. If your visible address did change, an exit node is the first thing to account for.

DNS is answered on the peer itself

NetBird runs a local resolver on each peer, documented as running on 100.x.255.254 port 53 in userspace mode, where x is the second octet of your account's /16 block. Managed Mode is the default and lets NetBird control DNS settings, while Unmanaged Mode leaves the peer's existing configuration untouched. Only macOS, Windows 10 and later, and Linux with systemd-resolved support nameservers with match domains, and NetBird notes that without a nameserver set to match domain ALL, devices keep sending DNS queries to their local resolver outside the tunnel.

IPv6 here is overlay addressing

NetBird's IPv6 overlay addressing requires client version 0.71.0 or later, and gives each account a unique IPv6 prefix from which peer addresses are allocated, with a /64 default and valid lengths from /48 through /120. New accounts have it enabled for the All group, while existing accounts enable it from the dashboard under Settings and then Network. That addressing applies between peers inside the overlay, so the public IPv6 reading on this page continues to follow your own connection rather than anything NetBird provides.

Between the readings

Record a kill-switch drop on NetBird

By default NetBird is not the path your general internet traffic takes, so a dropped peer connection changes what you can reach inside the overlay rather than what the outside world sees. If an exit node is carrying your traffic, the seconds while that peer connection renegotiates are the ones worth recording.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on NetBird

  1. Note your visible address, the resolver that answered and the IPv6 result before the NetBird client is connected.
  2. Start the client and let the peer join the network, noting whether an exit node is configured for this device.
  3. Rerun the checks in the same browser, without changing profile or network.
  4. With no exit node, expect the readings to be unchanged, which is the documented default. With an exit node, expect the address to become the routing peer's public address.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

NetBird leak test FAQ

Why has my IP address not changed after connecting NetBird?

NetBird does not carry general internet traffic unless an exit node is configured. Its documentation describes a private WireGuard overlay with no centralized VPN server, so an unchanged public address is the designed behaviour rather than a failure.

What is the 100.64 address NetBird gave my device?

NetBird assigns peers addresses from the carrier grade NAT range 100.64.0.0/10, drawing on one of 64 possible /16 blocks selected per account. It is an overlay address used between your own peers and is not the address a website sees.

How do I make NetBird change my visible address?

That is what an exit node does. NetBird documents an exit node as a routing peer carrying internet-bound traffic and applying masquerading, so traffic appears to originate from the routing peer's public IP address. It has to be configured before it applies.

Which resolver answers DNS on NetBird?

NetBird runs a local resolver on each peer, documented at 100.x.255.254 on port 53 in userspace mode, with Managed Mode as the default. It also notes that without a nameserver set to match domain ALL, devices keep sending queries to their local resolver outside the tunnel.

Does NetBird give me an IPv6 address on the public internet?

NetBird's IPv6 support, which requires client version 0.71.0 or later, is overlay addressing between peers, with each account allocated its own prefix and a /64 default. The public IPv6 reading on this page still follows your own connection.

Can this page tell me anything about NetBird's own infrastructure?

No. NetBird is open source and can be self-hosted, and its Signal service is documented as storing no data, with no traffic passing through it. None of that is observable from a browser, which reports only on your own session.