WebRTC IP Leak Detection Tool
Detect local and public IP candidate addresses exposed by browser WebRTC via STUN, and identify VPN or proxy leak risks.
Browser execution mode: Your data is processed in your browser and is not uploaded to the server.
Speed and Stability: Processing speed depends on your device and browser. For large batch work, the desktop version may be more stable.
Loading tool, please wait...
Loading tool, please wait...
If the online tool fails to load or run, try the desktop tool.https://tools.yikeaigc.com/
Tool Usage
Return to old version
Analyzing…
Local / Private IP
—
Public (srflx) IP
—
mDNS masking (.local)
—
Candidate Address Stats
Session & Browser Info
Raw ICE Candidates
Selected0servers. Custom can be added:
Detection progress0/0
Comparison results
| STUN Server | Local IP | Public IP (srflx) | mDNS | Total Candidates | Conclusion |
|---|
The first 20 are shown in the table. If more servers are selected, all results are included in the ZIP archive.
Instructions
Software Usage Instructions
- Select a detection mode: Use the top tabs to switch between "Single Check" and "Batch Comparison". Single Check is suitable for quick verification; Batch Comparison can use multiple STUN servers at the same time for cross-comparison.
- Configure the STUN server:
- Single Check: Choose a preset from the drop-down list, such as Google, Cloudflare, Twilio, Nextcloud, or Tencent QQ, or select "Custom STUN URL" and enter an address starting with
stun:/stuns:. - Batch Comparison: Select multiple servers to include in the comparison, or enter a custom STUN URL in the input box and click "Add" to add it to the list.
- Single Check: Choose a preset from the drop-down list, such as Google, Cloudflare, Twilio, Nextcloud, or Tencent QQ, or select "Custom STUN URL" and enter an address starting with
- Set detection options:
- Enable IPv6: Decide whether to collect IPv6 candidates based on whether your local network supports dual stack.
- Filter link-local noise: Ignore auto-configured addresses such as 169.254/fe80:: to keep the results more focused.
- Collection timeout: In milliseconds, default 4000; if the network is slow, you can increase it to 6000 or higher.
- Start detection: Click "Check for IP Leaks" or "Start Batch Comparison", and wait for ICE candidate collection to complete.
- View results:
- The top conclusion area indicates in plain language whether a public IP is exposed.
- Three summary cards show the local IP, public srflx IP, and mDNS hostname respectively.
- The statistics table lists the number of host / srflx / prflx / relay and IPv4 / IPv6 candidates.
- The "Raw ICE Candidate Addresses" area at the bottom displays the complete strings provided by the browser to JavaScript.
- Export and download: For a single check, you can copy or download JSON; after a batch comparison is complete, click "Download All Results (ZIP)", which contains the JSON file for each server and a summary.csv summary table.
FAQ
A: WebRTC is a real-time communication interface built into modern browsers. It uses the ICE framework to collect local LAN IP addresses and the public IP addresses visible to STUN servers as candidate addresses. When using a VPN or proxy, these candidates may bypass the tunnel and directly expose your real IP to JavaScript, causing a "leak".
A: host comes from the device's local network adapter and is usually a private IP; srflx (server reflexive) is the NAT external address observed by the STUN server, i.e., your public IP; prflx (peer reflexive) is observed by the remote peer; relay requires a TURN relay to be generated. To determine whether the "public IP is exposed," mainly check whether srflx contains a real public IP.
A: This is mDNS hostname masking. Chrome, Firefox, and others replace the original private IP with a random identifier like
xxxx-xxxx-xxxx.local, so JavaScript cannot obtain the real LAN IP. The detection tool will list it separately in the "mDNS Masking" card.A: Common causes include: WebRTC is disabled by an extension or policy, the selected STUN server is unreachable, UDP is blocked by a firewall, or the collection timeout is too short. You can switch to another STUN server, increase the timeout to more than 6000 milliseconds, or disable plugins that block WebRTC and try again.
A: You need to compare it with your real IP. If the public IP in the result matches the exit IP provided by the VPN, it means the traffic is correctly going through the tunnel; if it matches the IP originally assigned by your ISP, then WebRTC is bypassing the VPN. You should disable or restrict WebRTC in the browser, for example by using WebRTC Network Limiter or the corresponding about:config switch.
A: Different STUN servers may be deployed by different carriers or in different regions, so NAT paths and visible addresses can vary; some enterprise environments only allow specific STUN ports. Batch comparison mode is designed to cross-verify results across multiple servers—the higher the consistency, the more reliable the results.
A: In the downloaded ZIP, each STUN server corresponds to one JSON file, recording the candidate list, classification statistics, elapsed time, error information, and more. A summary.csv summary table is also included, which can be opened directly in Excel or WPS for side-by-side comparison. If duplicate names occur, a number is automatically appended to the file name to distinguish them.
Related Tools
Contact Information Anti-Deletion Tool
Convert sensitive text such as WeChat IDs and phone numbe...
Complete List of Special Symbols
Provides thousands of special symbols, emojis, arrows, ma...
Browser Fingerprint Detection Tool
Detect multidimensional fingerprints such as Canvas, WebG...
Network Traffic Consumption Tool
Professional network traffic consumption testing tool, su...
Project Progress (Gantt Chart) Drawing Tool
A professional project schedule management tool that supp...