MyIPScan

Provider-neutral self-test pilot

ZeroTier Leak Test

ZeroTier builds virtual networks rather than replacing your route to the internet, and its own documentation is blunt about the difference: it creates imaginary LANs. Three local settings decide whether any of your ordinary traffic moves at all, and the two that matter most are off until you turn them on. That is why a check run over ZeroTier usually returns the address you started with. What follows describes this browser on this connection, not ZeroTier's network.

Read methodology

Live test

Run the test on ZeroTier now

ZeroTier carries the virtual networks you join rather than your internet traffic, unless Allow Default is set and a route for everything exists. A familiar address below is normally correct.

Open the full VPN Leak Test

Current-session checks

What this ZeroTier self-test checks

Take a reading before joining a network and one after. On ZeroTier the useful question is whether anything moved at all, because the defaults are arranged so that nothing should.

Before you read the result

What ZeroTier documents about these signals

Each point below comes from ZeroTier's own documentation, which states what every local configuration flag defaults to.

Allow Default is off until you set it

ZeroTier documents four flags in a network's local configuration file. Allow Managed defaults to Yes and lets ZeroTier set IP addresses and routes. Allow Global defaults to No and covers public, non-private ranges. Allow Default defaults to No, and that is the one that lets ZeroTier set the default route on the system. Left alone, your internet traffic never enters the virtual network, and this page shows the address it always would.

An exit node is something you build

ZeroTier documents the exit-node setup as two deliberate steps: a managed route for all traffic pointing at the ZeroTier address of a router node you operate, added in Central under Network and then Settings and then Managed Routes, and Allow Default enabled on each member that should use it. Until both exist there is no exit node, and a check reporting your usual address is reporting the truth.

Allow DNS is off as well

Allow DNS also defaults to No, so ZeroTier will not set DNS servers on a member unless you allow it. On a default join the resolver answering for this browser is whatever your operating system was already using. A DNS check naming your own ISP is therefore not a leak out of anything; it is the absence of a change you never asked for.

The IPv6 addresses it hands out are private

ZeroTier's RFC4193 and 6PLANE modes assign addresses inside the unique local range, which the documentation describes as not globally routable, with 6PLANE giving each device a block of its own and embedding that member's ZeroTier device address. Those addresses exist to reach other members. An IPv6 check against a public site still reports whatever IPv6 your own connection has.

Where the DNS reading gets platform-specific

ZeroTier documents per-platform DNS quirks worth knowing before you read a resolver line. Most Linux distributions do not do per-interface DNS resolution out of the box, which is what its systemd helper exists for, and on macOS resolution goes through dns-sd, where the documentation records that nslookup, host and dig are broken while ping works. A command-line tool disagreeing with the browser can be that rather than the tunnel.

Between the readings

Record a kill-switch drop on ZeroTier

An exit node on ZeroTier is a machine you run yourself, so a drop here is your own router node going away rather than a provider outage. A recording shows how the local route behaved in the seconds after it did.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on ZeroTier

  1. Note the visible address, the resolver and any IPv6 result before you join a network.
  2. Join the network, then check the three flags that decide the outcome: Allow Managed, Allow Global and Allow Default.
  3. Rerun the same checks in the same browser so the comparison is like for like.
  4. Expect nothing to move unless you set Allow Default and a route covering all traffic. An unchanged address is the documented result.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

ZeroTier leak test FAQ

Does ZeroTier change my public IP address?

Not by default. ZeroTier documents Allow Default, the setting that lets it take over the system default route, as defaulting to No. Without it your internet traffic never enters the virtual network and this page reports your ordinary address.

How do I make ZeroTier carry all my traffic?

ZeroTier documents two steps: add a managed route covering all traffic that points at the ZeroTier address of a router node you run, then enable Allow Default on the members that should use it. Both are required before an exit node exists.

Why does the DNS check still name my own resolver?

Allow DNS defaults to No, so ZeroTier does not set DNS servers on a member unless you allow it. The resolver answering for this browser is the one your operating system was already using.

I have an IPv6 address from ZeroTier. Why does the IPv6 test not show it?

ZeroTier's RFC4193 and 6PLANE addresses sit in the unique local range and are documented as not globally routable. They reach other members of your network rather than public sites, so a public IPv6 check reports your own connection instead.

Is an unchanged address a leak on ZeroTier?

On a default join it is the documented behaviour rather than a fault. ZeroTier describes itself as creating imaginary LANs, and carrying your internet traffic is an option you switch on deliberately.

Can this page tell me anything about my ZeroTier network?

Only indirectly. It reads what this browser exposes to a public site. Traffic between members of a virtual network never reaches this page, so nothing here describes it.