Skip to content
IPOK

What do proxy, VPN, and Tor change — and how can you review leak clues?

A proxy commonly changes the exit for selected apps or protocols; a VPN commonly creates a system tunnel; Tor provides another kind of multi-hop exit. Actual coverage depends on client, routing, DNS, and application configuration, and the network type alone does not guarantee anonymity.

You can separately inspect public WebRTC candidates, resolver country codes seen by a DNS test, and whether IPv4/IPv6 use the expected exits. Differences are possible configuration clues, while unknown or matching results do not rule out a leak.

IPOK's WebRTC test contacts public STUN on click and parses candidates locally; DNS contacts bash.ws test endpoints; dual stack contacts IPOK's own single-stack endpoints. The application does not build a visitor profile from these results.

Your public IP
Up to 8 sources cross-verifiedOpen methodologyFree · no loginNo account profile · retention disclosed

FAQ

Which method is best?

That depends on your authorized use, threat model, and compliance requirements. IPOK only shows network paths and leak clues; it does not recommend policy evasion or guarantee anonymity.

Can a VPN or proxy still expose extra network information?

Yes. Whether WebRTC, DNS, or the other IP stack uses the expected path depends on configuration. Each test must be run separately and remains diagnostic evidence only.

Does incognito mode hide my IP?

No. Incognito mainly changes local history and cookie behavior, not network routing; a site still sees the current connection exit, which may be direct, proxy, or VPN.

How do I reduce IP-leak risk?

Review WebRTC, DNS, and IPv4/IPv6 handling for your authorized network setup, then re-test each item here. An unknown result means the test lacked enough evidence and is not proof of safety.

Related checks