How Our Privacy Checks Work
Reviewed October 8, 2026. Each result describes what this browser or a data provider reported during a particular check. A successful request is not proof of anonymity. An unavailable service is not evidence of protection.
Public IP, location and VPN detection
The Cloudflare-hosted connection endpoint reads the public source address and network metadata of the request. Location is approximate network information, not GPS. VPN and proxy signals come from proxycheck.io when the hosted detector is configured. A hosting classification can also represent a server or business network. “Not detected” means no supported signal was returned, not that no VPN exists.
If that endpoint fails, a direct request to ipwho.is may provide approximate IP and location information. The fallback does not establish VPN status. Lookup data can be outdated or wrong.
DNS resolver check
The browser requests unique hostnames supplied by dnsleak.dev through the site’s Worker. The service returns observed resolver information. The result is interpreted cautiously: an operator difference alone is not proof of a leak. Service failure, missing resolver details or incomplete results remain inconclusive.
Limited WebRTC candidate check
The current implementation uses a local RTCPeerConnection with an empty ICE-server list. It examines local candidates but does not run a remote STUN or TURN test. Private addresses and masked .local candidates are not classified as public leaks. An additional public address is reported for investigation. The absence of one does not rule out exposure in another WebRTC application.
IPv6 reachability
The browser requests api6.ipify.org. A returned IPv6 address means the endpoint was reached. A failed request does not distinguish missing IPv6 from an endpoint outage, timeout or block. The test does not identify which tunnel carried the request. Reachability is displayed separately and earns no privacy points.
The checklist score
This is a site-defined heuristic, not a probability, industry standard or audited security rating. VPN/anonymizer database detection can contribute up to 35 points; the limited local WebRTC observation up to 30; a completed DNS resolver observation with resolver details up to 25. The components total 90 raw points. The displayed checklist score is rounded to a scale of 100: earned points ÷ 90 × 100. For example, 55 raw points display as 61/100, and 90 raw points display as 100/100. A full score does not guarantee privacy or anonymity. Unavailable or inconclusive checks contribute no points and remain marked not run or inconclusive. The 25 DNS points record test completion, not a clean leak verdict. Resolver details must be compared with your intended configuration; network differences alone do not establish a leak. Low scores can reflect missing evidence rather than poor privacy; high scores do not establish anonymity.
Browser information and photos
Browser Check reads local browser properties without building a unique fingerprint. Photo Privacy parses supported metadata in your browser. A cleaned image can still show identifying details in its pixels; inspect the picture itself before sharing. Files are not uploaded by the photo tool.
Compare results fairly
- Use the same device and browser before and after a setting change.
- Reconnect, reload and start a fresh scan rather than comparing stale results.
- Change one variable at a time and record any service errors.
- Confirm unexpected behavior against the provider’s documented configuration.
Technical references
- MDN: RTCPeerConnection configuration
- MDN: Do Not Track limitations
- IPWhois: geolocation API documentation
Contact the maintainer if an explanation does not match the result you see. No source listed here certifies or endorses this site.