MyIPScan

Provider-neutral self-test pilot

NordVPN Leak Test

NordVPN handles IPv6 by shutting it down rather than carrying it: its own documentation describes blocking the IPv6 interface and rerouting IPv4 only. That single decision explains most of what an IPv6 leak test shows here. It also runs its own DNS servers, and it ships two different kill switches that behave differently. Treat the output as a description of your own session rather than an assessment of NordVPN.

Read methodology

Live test

Run the test on NordVPN now

NordVPN blocks the IPv6 interface rather than carrying it, and answers DNS from its own resolvers, so those are the two lines to read first.

Open the full VPN Leak Test

Current-session checks

What this NordVPN self-test checks

Take one reading on your normal connection and one connected. On NordVPN the IPv6 result should go quiet by design, so the lines worth studying are the resolver that answered and what WebRTC exposed.

Before you read the result

What NordVPN documents about these signals

Each point below is taken from NordVPN's own blog and support articles. They set out what a normal reading is supposed to look like.

IPv6 is blocked, not tunnelled

NordVPN describes IPv6 leak protection as blocking the IPv6 interface so that only IPv4 traffic is rerouted and encrypted. An IPv6 check that returns nothing while you are connected is therefore the documented outcome. An IPv6 address that still resolves to your own connection is the reading that needs investigating.

Two kill switches that are not the same thing

NordVPN separates an internet kill switch from an App Kill Switch, which closes named applications when the connection drops. NordVPN's support pages state that the App Kill Switch is off by default on desktop, while on mobile the kill switch is enabled by default and is not exposed as its own setting. Knowing which one you have on changes how you read a failed check.

DNS answers come from NordVPN's resolvers

NordVPN operates its own DNS servers, and Threat Protection filters domains at that layer against reputation databases and phishing detection. NordVPN also notes that Threat Protection overrides a custom DNS setting, so if you pointed the app at a resolver of your own and the DNS check does not show it, that feature is the first thing to look at.

There is a published address to compare against

NordVPN documents its own DNS server addresses, 103.86.96.100 and 103.86.99.100, in its support material. That gives the DNS check on this page something concrete to be measured against: a resolver answering from those addresses is NordVPN's, and one answering from your ISP's range is not, without any need to infer it from the result.

What the app does not decide

WebRTC candidates and fingerprint values are produced by the browser. With the whole system routed through the app they should carry the tunnel address, but an extension, a virtual adapter or split tunnelling can change that. Nothing on this page inspects NordVPN's servers - only what your browser reveals in this session.

Between the readings

Record a kill-switch drop on NordVPN

NordVPN separates an internet kill switch from an App Kill Switch, and its support pages put the App Kill Switch off by default on desktop. Which of them was covering this browser shows up in the seconds after the tunnel address disappears.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on NordVPN

  1. Before connecting, record the address, the resolver and whether IPv6 answers at all on your normal connection.
  2. Connect with the NordVPN app and check which kill switch is enabled, since the App Kill Switch and the internet kill switch are separate settings.
  3. Rerun the same checks in the same browser without changing profile or extensions.
  4. IPv4 and the resolver should change, and IPv6 should stop answering because the interface is blocked rather than tunnelled.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

NordVPN leak test FAQ

Does NordVPN support IPv6?

NordVPN documents IPv6 leak protection as blocking the IPv6 interface and rerouting IPv4 only. An empty IPv6 result on this page is therefore the expected reading rather than a sign the test failed.

Which kill switch does NordVPN turn on by default?

NordVPN's support pages state that the App Kill Switch is off by default on desktop, while on mobile the kill switch is enabled by default and is not shown as a separate option in settings.

Which DNS addresses belong to NordVPN?

NordVPN publishes 103.86.96.100 and 103.86.99.100 as its own DNS servers in its support material, which gives you a fixed reference to compare the resolver in your result against.

Why does the DNS check not show the custom resolver I set?

NordVPN notes that Threat Protection overrides a custom DNS setting because the filtering happens on NordVPN's own DNS servers. Turning that feature off is the usual reason a custom resolver reappears.

Can this page tell me whether NordVPN keeps logs?

No. These checks read what your browser exposes in one session. Logging happens on the provider's side and cannot be observed from a browser test, whatever the result looks like.

A check still shows my own address. What should I look at?

Confirm the app is connected and the kill switch you rely on is the one that is enabled, restart the browser to drop cached connections, then rerun the focused DNS, WebRTC and IPv6 tools.