What is an IP leak test?
An IP leak test checks whether your real IP address is exposed while you use a VPN or proxy. Sentry inspects WebRTC ICE candidates and your browser fingerprint to show what a website could learn about you.
Sentry checks your browser for WebRTC leaks, reveals your browser fingerprint, and audits your connection security. The analysis runs in your browser — Sentry has no server and no database of its own.
Stored in this browser only, and only the time, score and verdict — no IP address, no ISP.
An IP leak test checks whether your real IP address is exposed while you use a VPN or proxy. Sentry inspects WebRTC ICE candidates and your browser fingerprint to show what a website could learn about you.
WebRTC can reveal addresses that your VPN tunnel was supposed to hide. Sentry reports three things: local network addresses, public addresses, and whether the public address WebRTC reveals differs from the one the IP lookup saw — that mismatch is what a real VPN bypass looks like. Modern browsers replace local addresses with a random .local mDNS name; when that happens Sentry says so, because it means your browser is already protecting you.
Detecting relayed candidates requires a TURN server with credentials, which would mean running a backend. Sentry deliberately has none, so that row reports "Not tested" rather than implying a clean result.
The analysis runs entirely in your browser and there is no Sentry server to send it to. Two things do leave your device: your IP address reaches the public lookup APIs listed in "What This Page Contacts" above (that is unavoidable — an IP lookup is a request from your IP), and one anonymous, cookieless pageview goes to PostHog. Scan history stays in your browser's local storage and holds only the time, score and verdict.
Fingerprinting identifies your device from characteristics like screen resolution, installed fonts, WebGL renderer, audio processing and hardware specs. The hashes on this page are computed locally and shown to you; they are not stored or transmitted.
The score starts at 100 and subtracts: WebRTC IP leak −25, connection not HTTPS −20, no content blocker −15, not a secure context −10, mixed content −10, no confirmed VPN or proxy −20, cookies enabled −5. A check that could not run is listed as "not assessed" and never costs points. A VPN is weighted heavily because it is the single biggest change most people can make to how much a website learns about them; a careful browser without one still reaches the "Good" band.
It is a heuristic, not a verdict, and it reports three states. "Likely" means your IP itself belongs to a VPN, proxy or hosting provider — the only signal that actually shows traffic is tunnelled. "Inconclusive" means the only hint is that your browser timezone disagrees with your IP location, which happens with a VPN but equally when travelling or when an extension spoofs your timezone. Because your browser controls that value, it does not earn the VPN points — the score credits a VPN only when your IP proves it. "Not detected" means neither signal is present, and scores the same as inconclusive. A self-hosted VPN on an unlisted provider can still evade detection.
A plain-text file containing everything on this page: addresses, network provider, location, device and hardware details, fingerprint hashes, security status and the score breakdown. It is generated in your browser and downloaded directly — it is never uploaded. It identifies you, so treat it accordingly.
Everything Sentry loads and every request it makes, in full. Open your browser's network panel and check — this list should match exactly.
Not contacted: no CDN (fonts, styles, scripts and the map are all served from this domain), no advertising network, no map tile server. Sentry has no backend, so your results are never sent anywhere for processing.