MyIPScan

Provider-neutral self-test pilot

Proton VPN Leak Test

Proton VPN is one of the few providers on this list that routes IPv6 rather than blocking it, which changes what an IPv6 leak test means here: an IPv6 address in the result may be the tunnel working, not a leak. It also runs its own DNS servers, adds an advanced kill switch on Windows and Linux, and announces exit addresses from its own autonomous system. The readings you get here belong to this browser and this connection, not to Proton VPN as a service.

Read methodology

Live test

Run the test on Proton VPN now

Proton VPN routes IPv6 rather than blocking it, so an IPv6 address below may be the tunnel working. Check that the network line names Proton.

Open the full VPN Leak Test

Current-session checks

What this Proton VPN self-test checks

Take a reading before you connect and another afterwards. On Proton VPN the line that needs the most care is IPv6, because unlike most providers here Proton carries it rather than switching it off.

Before you read the result

What Proton VPN documents about these signals

Proton VPN's support documentation states each of the points below. Read them first and the IPv6 line in particular stops being ambiguous.

IPv6 is routed, not blocked

Proton VPN says roughly 80 percent of its servers support IPv6 and that it is available on Windows, the Linux app and CLI, Android and the browser extension, while IPv6 is turned off on macOS and iOS to avoid exposing an address. So an IPv6 address in your result is not automatically a leak on Proton: compare it against the IPv4 exit and see whether both point at the same network.

Two kill switches, and one of them persists

Proton VPN documents a standard kill switch plus an advanced or permanent kill switch on Windows and Linux, which only allows internet access while you are connected to Proton VPN, with no exceptions. If a check returns your own address, which of the two you have enabled decides whether traffic was ever allowed out.

DNS answers come from Proton, and NetShield filters them

Proton VPN states that it runs its own DNS servers, and NetShield works at that DNS layer: it checks each domain against lists of ad, tracker and malware hosts and refuses to resolve matches. A DNS check while connected should therefore show Proton answering, and a page that fails to load may have been blocked at the resolver rather than failing to connect.

The exit sits in Proton's own network

Proton announces address space under AS62371, registered to Proton AG, so an ASN lookup on your exit address can name Proton directly - see AS62371 on MyIPScan, or the ranges Proton VPN announces. Proton also uses data-centre partners for regional coverage, so a different network is a prompt to check the server you picked, not proof of a fault.

Which platform you tested from matters

Proton documents its Linux app as carrying an always-on kill switch, port forwarding, NetShield, Secure Core, custom DNS, full IPv6 support and NAT type 2 together, where other platforms expose a smaller set. Two people running the same checks on the same account can therefore get different IPv6 and DNS readings purely because of the operating system they are on.

Between the readings

Record a kill-switch drop on Proton VPN

Proton VPN documents a standard kill switch and a permanent one on Windows and Linux. Which of them is in force is rarely obvious from the app, and a disconnect you record yourself is the plainest way to find out.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Proton VPN

  1. Note your starting address, resolver and IPv6 result before you open the app.
  2. Connect with Proton VPN and note which kill switch you have on - the standard one or the advanced kill switch on Windows and Linux.
  3. Rerun the checks in the same browser and read the IPv6 result carefully rather than assuming any IPv6 address is a leak.
  4. Both the IPv4 and any IPv6 address should point at Proton's network, and the resolver should be Proton's rather than your ISP's.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Proton VPN leak test FAQ

Is an IPv6 address a leak on Proton VPN?

Not necessarily. Proton VPN routes IPv6 on roughly 80 percent of its servers and supports it on Windows, Linux, Android and the browser extension. What matters is whether the IPv6 address belongs to Proton's network or to your own connection.

Why does the IPv6 check stay empty on my Mac or iPhone?

Proton VPN documents IPv6 as turned off on macOS and iOS or iPadOS, so that no IPv6 address is exposed on platforms where it does not yet carry the traffic. An empty result there is the documented behaviour.

What is the difference between the kill switch and the advanced kill switch?

Proton VPN describes the standard kill switch as protecting you when the connection drops, and the advanced or permanent kill switch, on Windows and Linux, as allowing internet access only while connected to Proton VPN.

Which DNS servers answer while I am connected?

Proton VPN states that it runs its own DNS servers, and NetShield filters ad, tracker and malware domains at that layer. The DNS check on this page reports which resolver actually answered for your session.

What ASN should my Proton VPN exit address belong to?

Proton announces address space under AS62371, registered to Proton AG. Proton also uses partner data centres, so a lookup returning a different operator is worth checking against the server you selected rather than treated as a leak.

Why did a friend on the same plan get a different result?

Feature coverage differs by platform. Proton lists its Linux app as carrying the always-on kill switch, custom DNS and full IPv6 support together, so the operating system you ran the checks from can change the IPv6 and DNS lines on its own.