MyIPScan

Provider-neutral self-test pilot

Surfshark Leak Test

Surfshark's support pages say plainly that the service does not support the IPv6 protocol, and they recommend disabling IPv6 on the device. That is the single most useful thing to know before reading an IPv6 leak test here, because an empty IPv6 result is the design rather than a fault. The result describes the device in front of you, not Surfshark's network.

Read methodology

Live test

Run the test on Surfshark now

Surfshark does not support IPv6 and recommends disabling it, so an empty IPv6 line is the design. The visible address also rotates by default.

Open the full VPN Leak Test

Current-session checks

What this Surfshark self-test checks

Read each signal once unconnected and once connected. On Surfshark the IPv6 line is the one people misread most often, so start there and then compare the resolver and the WebRTC result.

Before you read the result

What Surfshark documents about these signals

Surfshark states each of the points below on its own support and feature pages, and together they explain most of what you will see.

IPv6 is unsupported by design

Surfshark's support pages state that at the moment Surfshark does not support the IPv6 protocol, and they publish instructions for turning IPv6 off on Windows, macOS, Linux and Android. If your IPv6 check comes back empty while connected, that matches what Surfshark documents. An IPv6 address that still resolves to your home connection is the case to act on.

Rotating IP changes the address under you

Surfshark's Rotating IP changes your address roughly every five minutes within the location you chose, without dropping the connection, and it does not apply to Dedicated IP, Static IP or MultiHop servers. If two runs a few minutes apart report different addresses, that feature is the likely explanation rather than an unstable tunnel.

DNS requests travel inside the tunnel

Surfshark describes routing DNS requests through its own encrypted tunnels so that a Wi-Fi operator or ISP cannot read them. A DNS check while connected should therefore stop showing your ISP's resolver. CleanWeb adds ad, tracker and malware blocking on top of that, which can also explain a page that refuses to load.

The kill switch is the setting behind a failed check

Surfshark describes its kill switch as cutting the internet automatically if the VPN connection drops. When a check returns your own address, the sequence worth reconstructing is whether the tunnel dropped and whether the kill switch was enabled at that moment, rather than whether the test itself misfired.

Audits cover the provider, not your browser

Surfshark publishes independent assurance work on its no-logs claim: Deloitte produced assurance reports in 2023 and again in 2025, and Cure53 has reviewed its server infrastructure. Those are statements about Surfshark's systems. The WebRTC and fingerprint readings on this page are produced by your browser and are unaffected by them.

Between the readings

Record a kill-switch drop on Surfshark

Surfshark describes a kill switch that cuts the internet automatically if the VPN connection drops. The interesting quantity sits between “drops” and “cuts”, and it is counted in seconds rather than settings.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Surfshark

  1. On your normal connection, note the address, the resolver, and whether IPv6 answers at all.
  2. Connect with the Surfshark app and confirm the kill switch is enabled before you retest.
  3. Rerun the same checks in the same browser, with the same extensions loaded.
  4. Expect the address and resolver to change and IPv6 to stay quiet. If you have Rotating IP on, expect the address itself to keep moving.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Surfshark leak test FAQ

Does Surfshark support IPv6?

Surfshark's support pages state that at the moment it does not support the IPv6 protocol, and they recommend disabling IPv6 on your device. An empty IPv6 result on this page is consistent with that.

My IPv6 test shows an address from my own ISP. What does that mean?

Because Surfshark does not carry IPv6, an IPv6 address belonging to your own connection is the reading worth acting on. Surfshark publishes per-platform instructions for turning IPv6 off, which is its documented answer to this.

Why did my address change between two runs?

Surfshark's Rotating IP changes your address roughly every five minutes within the location you selected, without disconnecting. It does not apply on Dedicated IP, Static IP or MultiHop servers.

Does Surfshark run the DNS that answers my queries?

Surfshark describes routing DNS requests through its own encrypted tunnels rather than leaving them with your ISP. The DNS check here reports which resolver actually answered for your browser session.

Has Surfshark's no-logs claim been checked by anyone?

Surfshark publishes independent assurance reports from Deloitte covering its no-logs policy, in 2023 and again in 2025, and Cure53 has reviewed its server infrastructure. Those reports concern Surfshark's systems, not your session.

Why has my browser fingerprint not changed?

A VPN changes the network path, not the browser. Fonts, screen metrics, language and similar values are reported by the browser itself, so they usually look the same before and after connecting.