MyIPScan

Provider-neutral self-test pilot

Tailscale Leak Test

Tailscale is the case on this list where an unchanged result is the right result. Its documentation describes an overlay network that routes traffic between devices running Tailscale and leaves your public internet traffic alone unless you deliberately select an exit node. Every device has to opt in to using one, and exit nodes need approval on the network first. So a reading that shows your ordinary address usually means Tailscale is behaving exactly as documented.

Read methodology

Live test

Run the test on Tailscale now

Unless you have selected an exit node, Tailscale leaves your public traffic alone, so this page reporting your usual address is the documented behaviour and not a leak.

Open the full VPN Leak Test

Current-session checks

What this Tailscale self-test checks

Read the signals before and after enabling Tailscale, and note whether an exit node is selected. Without one, the two readings should look the same.

Before you read the result

What Tailscale documents about these signals

The points below come from Tailscale's own documentation on exit nodes and on how names are resolved inside a tailnet.

Without an exit node nothing about your address changes

Tailscale describes itself as an overlay network that only routes traffic between devices running Tailscale, leaving public internet traffic untouched unless an exit node is configured. If you never selected one, this page will report the address your connection always had, and that is the product working rather than failing.

Exit nodes are opt-in at both ends

The documentation states that every device must explicitly opt in to using an exit node, and that a node has to be approved before it can act as one. Two separate decisions therefore stand between installing Tailscale and seeing a different address here, which is more than most people expect.

Name resolution inside the network is separate

MagicDNS resolves machine names within your own network to fully qualified names built from the machine name and your network's own DNS name, and Tailscale documents that the nameservers you configure receive the queries MagicDNS does not handle. Those are two different populations of query. Only the second reaches the public internet, and only the second is what a DNS check on this page can observe, so a reading here says nothing at all about how your own machines find each other.

An unchanged reading is the documented outcome

It is worth stating plainly because it is unusual: on Tailscale without an exit node, a check that shows your own address, your own resolver and your own country has not found a leak. It has confirmed the scope of the product, which is connectivity between your devices.

What changes the moment an exit node is selected

Once a device routes through an exit node, public traffic follows that path and the address here should become the exit node's. That is the point to rerun these checks, because it is the only configuration in which the page is measuring what most readers came to measure.

Between the readings

Record a kill-switch drop on Tailscale

Unless you have selected an exit node, Tailscale leaves your public address alone, so most readings here will show your own network by design. A recording is still the way to watch what changes when a connection drops.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on Tailscale

  1. Take a reading with Tailscale running and no exit node selected.
  2. Confirm in the client whether an exit node is available and approved.
  3. Select the exit node, then repeat the checks in the same browser.
  4. Expect the address to move only in the second reading, and not before.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

Tailscale leak test FAQ

Why has my address not changed?

Tailscale documents itself as an overlay network that routes traffic between your own devices and leaves public internet traffic untouched unless an exit node is selected. Without one, nothing about your public address should move.

How do I make traffic use an exit node?

The documentation describes exit nodes as requiring approval on the network, and every device as having to opt in explicitly. Both steps have to be done before public traffic follows that path.

Does MagicDNS change what a DNS check sees?

MagicDNS resolves machine names inside your own network. Queries it does not handle go to the nameservers you configured, and those are the only ones a public check on this page could observe.

Is an unchanged reading a leak?

Not on Tailscale without an exit node. It is the documented scope of the product. The reading only becomes evidence of a problem once an exit node is selected and the address still does not move.

Can this page tell whether an exit node is active?

Not directly. It can show you the address a website sees, which will match the exit node once one is in use. The client is the authority on which configuration is live.

What about the other devices on my network?

They are outside this reading entirely. A page in one browser describes that browser, and says nothing about how another machine on the same network is routing its traffic.