MyIPScan

Provider-neutral self-test pilot

Psiphon Leak Test

Psiphon is explicit about two things that matter before any reading is taken. Its documentation says that in VPN mode your entire computer's traffic passes through the Psiphon network, and that outside VPN mode only applications using the local HTTP and SOCKS proxies are proxied. It also states that it is designed as a censorship circumvention tool rather than specifically for anti-surveillance purposes, and points people who need anonymity to Tor instead.

Read methodology

Live test

Run the test on Psiphon now

On Psiphon the first question is which mode is running: outside VPN mode only applications pointed at the local proxies are covered, so a browser that is not may report your ordinary connection.

Open the full VPN Leak Test

Current-session checks

What this Psiphon self-test checks

Take a reading before and after connecting, and note whether VPN mode is on. Outside it, whether this browser uses the local proxy decides what the result can show.

Before you read the result

What Psiphon documents about these signals

The points below come from Psiphon's own frequently asked questions and its published description of how the client works.

VPN mode and proxy mode cover different things

Psiphon documents VPN mode as passing the entire computer's traffic through its network, and says that outside VPN mode only applications that use the local HTTP and SOCKS proxies are proxied. A browser that was never pointed at those local ports will therefore produce a perfectly ordinary reading while the client sits connected.

The stated purpose is circumvention

Psiphon says it is designed to be a censorship circumvention tool and is not specifically designed for anti-surveillance purposes, and that anyone who requires anonymity over the internet should use Tor instead. Reading a result here against the goal the tool actually states is more useful than reading it against the goal a leak test implies.

The iOS browser tunnels only itself

Psiphon describes its iOS browser as browser-only, tunnelling data loaded in the app itself and not other applications. If that is the client you are running, the only meaningful place to take a reading is inside that app, and a check from Safari would describe your ordinary connection.

Local proxy ports decide the boundary

Because coverage outside VPN mode is defined by which applications point at the local HTTP and SOCKS proxies, the boundary is one you configured rather than one the network drew. Two browsers on the same machine can therefore sit on opposite sides of it at the same moment, and a check run in the wrong one will look like a failure while describing a correctly configured system. Establishing which is which cannot be done from inside a web page, so it has to be done in the client and in the browser's own connection settings first.

What Psiphon does not claim about a session

Nothing in Psiphon's documentation offers a promise about what a browser exposes, and this page makes none either. It reports the address, the resolver, the WebRTC candidates and the IPv6 line as your browser presented them a moment ago. Read against a tool whose stated job is reaching blocked material, that is a narrower result than it first appears, and narrower is the honest reading rather than a disappointing one.

Between the readings

Record a kill-switch drop on Psiphon

An address change during a Psiphon session does not on its own mean anything leaked. A recording tells you whether the address that appeared was one of yours or simply another one of Psiphon's.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Psiphon

  1. Establish whether the client is running in VPN mode or as a local proxy.
  2. If it is a local proxy, confirm this browser is configured to use it.
  3. Take a reading before connecting and another after, in the same browser.
  4. Read an unchanged result against the mode first, because outside VPN mode it may be correct.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Psiphon leak test FAQ

What does VPN mode cover?

Psiphon documents VPN mode as passing your entire computer's traffic through its network. Outside VPN mode, only applications that use the local HTTP and SOCKS proxies are proxied.

Why is my address unchanged while Psiphon is connected?

Most often because the client is not in VPN mode and this browser is not pointed at the local proxy ports. In that arrangement an ordinary reading is the documented behaviour.

Is Psiphon built for privacy?

Psiphon states that it is designed as a censorship circumvention tool and not specifically for anti-surveillance purposes, and recommends Tor to anyone who requires anonymity over the internet.

What about the iOS browser?

Psiphon describes it as browser-only, tunnelling data loaded in the app itself rather than traffic from other applications. Readings taken outside that app describe your ordinary connection.

Can this page detect which mode is active?

No. It can show whether the address and resolver moved. Which mode produced that outcome has to be read in the client, and the two together are what make the result interpretable.

Does an ordinary reading mean something failed?

Not necessarily. Given how coverage is documented, an unchanged address can be the correct outcome for the mode you are running. The mode is the fact that settles it.