MyIPScan

Provider-neutral self-test pilot

Norton VPN Leak Test

One line in Norton's documentation decides how to read almost any surprising result here: the Kill Switch functions only on the Mimic protocol. Norton offers five protocol choices, so a session left on Automatic may or may not have landed on the one that protection needs. Split tunnelling on two platforms and a second server hop account for most of the rest. The reading describes this browser on this connection, not Norton's network.

Read methodology

Live test

Run the test on Norton VPN now

Norton documents the Kill Switch as functioning only on the Mimic protocol, so settle which protocol this session is using before you read anything below.

Open the full VPN Leak Test

Current-session checks

What this Norton VPN self-test checks

Take one reading before connecting and one after, and note the protocol in use both times, because on Norton that setting decides which other protections exist at all.

Before you read the result

What Norton VPN documents about these signals

The points below are taken from Norton's own support pages for configuring and using the product.

The Kill Switch is tied to one protocol

Norton documents the Kill Switch as blocking your internet connection if the VPN connection drops, and then adds the condition that decides whether you have it at all: it functions only on the Mimic protocol. The protocol menu offers Automatic, WireGuard, Mimic, OpenVPN over TCP and OpenVPN over UDP, so a connection left on Automatic may have landed somewhere the switch does not apply.

Split tunnelling is per application, on two platforms

Norton documents split tunnelling as letting you exclude some of your applications from the VPN channel while others reach the internet directly, and lists it for Windows and Android. A browser on that exclusion list will report your own address, correctly. It is the first list to check before treating an unexpected reading here as a fault in the tunnel.

Double VPN changes what an address lookup returns

Norton describes Double VPN as routing your traffic through two VPN servers. The address a site sees is the second one, so a lookup on it can name a network that does not match the location you selected in the interface. That mismatch is the feature behaving as documented rather than evidence of a misrouted session.

Ad Tracker Blocking can stop a check loading

Norton documents Ad Tracker Blocking as helping to block advertisers' tracking technologies in order to reduce targeted ads. A resource that refuses to load partway through a check may have been blocked by that feature, which is a different finding from a network fault and worth separating before you draw a conclusion.

The gap between a restart and a connection

Norton documents a Reconnect after restarting option that reconnects the VPN automatically once the device has restarted, for continuous protection. That names the window these checks cannot see: the interval between the machine coming up and the tunnel being established. A reading taken inside that window describes your ordinary connection, and taking one deliberately is the only way to learn how long it lasts on your device.

Between the readings

Record a kill-switch drop on Norton VPN

Because the Kill Switch is documented as working only on Mimic, a recorded drop answers a question the settings screen cannot: whether anything of yours was reachable while the tunnel was down on the protocol you actually chose.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Norton VPN

  1. Record the address, the resolver and any IPv6 result on your normal connection first.
  2. Connect with the Norton VPN application and note the protocol, since the Kill Switch is documented as working only on Mimic.
  3. Rerun the same checks in the same browser and the same profile.
  4. Expect the address and the resolver to change. If they did not, check the split tunnelling list before anything else.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Norton VPN leak test FAQ

Does Norton VPN have a kill switch?

Norton documents a Kill Switch that blocks your internet connection if the VPN connection drops, and states that it functions only on the Mimic protocol. Which protocol you connected with therefore decides whether you have it.

Which protocols can I choose in Norton VPN?

Norton lists Automatic as the recommended option, along with WireGuard, Mimic, OpenVPN over TCP and OpenVPN over UDP. Automatic may select a protocol on which the Kill Switch does not apply.

My browser shows my own address while Norton VPN is connected.

Check split tunnelling first. Norton documents it as letting you exclude applications from the VPN channel while others access the internet directly, and lists the feature for Windows and Android.

Why does an address lookup name a location I did not pick?

Norton describes Double VPN as routing traffic through two VPN servers, and the address a site sees is the second one. A network that does not match your selection is consistent with that feature being on.

Does Norton VPN carry IPv6?

Norton's settings documentation covers the protocol menu, the Kill Switch, split tunnelling and reconnection, and does not describe IPv6 handling, so this page makes no claim about it. What the IPv6 check does tell you is whether an IPv6 address of your own is still visible from this browser.

Can this page confirm Norton's logging policy?

No. These checks read signals this browser exposes in one session. What a provider stores happens on its own servers and is outside anything a browser test can observe.