One line in Norton's documentation decides how to read almost any surprising result here: the Kill Switch functions only on the Mimic protocol. Norton offers five protocol choices, so a session left on Automatic may or may not have landed on the one that protection needs. Split tunnelling on two platforms and a second server hop account for most of the rest. The reading describes this browser on this connection, not Norton's network.
Norton documents the Kill Switch as functioning only on the Mimic protocol, so settle which protocol this session is using before you read anything below.
Take one reading before connecting and one after, and note the protocol in use both times, because on Norton that setting decides which other protections exist at all.
The points below are taken from Norton's own support pages for configuring and using the product.
The Kill Switch is tied to one protocol
Norton documents the Kill Switch as blocking your internet connection if the VPN connection drops, and then adds the condition that decides whether you have it at all: it functions only on the Mimic protocol. The protocol menu offers Automatic, WireGuard, Mimic, OpenVPN over TCP and OpenVPN over UDP, so a connection left on Automatic may have landed somewhere the switch does not apply.
Split tunnelling is per application, on two platforms
Norton documents split tunnelling as letting you exclude some of your applications from the VPN channel while others reach the internet directly, and lists it for Windows and Android. A browser on that exclusion list will report your own address, correctly. It is the first list to check before treating an unexpected reading here as a fault in the tunnel.
Double VPN changes what an address lookup returns
Norton describes Double VPN as routing your traffic through two VPN servers. The address a site sees is the second one, so a lookup on it can name a network that does not match the location you selected in the interface. That mismatch is the feature behaving as documented rather than evidence of a misrouted session.
Ad Tracker Blocking can stop a check loading
Norton documents Ad Tracker Blocking as helping to block advertisers' tracking technologies in order to reduce targeted ads. A resource that refuses to load partway through a check may have been blocked by that feature, which is a different finding from a network fault and worth separating before you draw a conclusion.
The gap between a restart and a connection
Norton documents a Reconnect after restarting option that reconnects the VPN automatically once the device has restarted, for continuous protection. That names the window these checks cannot see: the interval between the machine coming up and the tunnel being established. A reading taken inside that window describes your ordinary connection, and taking one deliberately is the only way to learn how long it lasts on your device.
Between the readings
Record a kill-switch drop on Norton VPN
Because the Kill Switch is documented as working only on Mimic, a recorded drop answers a question the settings screen cannot: whether anything of yours was reachable while the tunnel was down on the protocol you actually chose.
This does not test every server, app, device, or connection.
This does not prove anonymity.
This does not prove every security condition.
A clean result does not prove every leak is absent.
How to compare before and after on Norton VPN
Record the address, the resolver and any IPv6 result on your normal connection first.
Connect with the Norton VPN application and note the protocol, since the Kill Switch is documented as working only on Mimic.
Rerun the same checks in the same browser and the same profile.
Expect the address and the resolver to change. If they did not, check the split tunnelling list before anything else.
Safe Copy limits
Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.
FAQ
Norton VPN leak test FAQ
Does Norton VPN have a kill switch?
Norton documents a Kill Switch that blocks your internet connection if the VPN connection drops, and states that it functions only on the Mimic protocol. Which protocol you connected with therefore decides whether you have it.
Which protocols can I choose in Norton VPN?
Norton lists Automatic as the recommended option, along with WireGuard, Mimic, OpenVPN over TCP and OpenVPN over UDP. Automatic may select a protocol on which the Kill Switch does not apply.
My browser shows my own address while Norton VPN is connected.
Check split tunnelling first. Norton documents it as letting you exclude applications from the VPN channel while others access the internet directly, and lists the feature for Windows and Android.
Why does an address lookup name a location I did not pick?
Norton describes Double VPN as routing traffic through two VPN servers, and the address a site sees is the second one. A network that does not match your selection is consistent with that feature being on.
Does Norton VPN carry IPv6?
Norton's settings documentation covers the protocol menu, the Kill Switch, split tunnelling and reconnection, and does not describe IPv6 handling, so this page makes no claim about it. What the IPv6 check does tell you is whether an IPv6 address of your own is still visible from this browser.
Can this page confirm Norton's logging policy?
No. These checks read signals this browser exposes in one session. What a provider stores happens on its own servers and is outside anything a browser test can observe.
Other provider self-tests
The same current-session checks, walked through for another provider. Listed alphabetically; this is not a ranking or a comparison.