Skip to content Skip to content
LunoVPN
Guides

Five tests that prove your VPN is actually working

A connected icon is not evidence. Five checks, ten minutes, and you will know whether your VPN is actually protecting you.

By the LunoVPN team
August 6, 2026 · 10 min read

TL;DR — A green icon in a VPN app means the client thinks it connected. It is not a measurement. These five checks take about ten minutes, need no technical background, and work with any provider — including whichever one you are using right now.

Every VPN app has a reassuring indicator. None of them are evidence. The indicator tells you the client software believes a tunnel was established; it says nothing about whether your DNS queries are still going to your ISP, whether a browser API is quietly announcing your real address, or what happens in the two seconds after the tunnel drops.

These five tests measure the things the icon does not. Run them once now, and again after any change to your setup — new router, OS update, new browser. Tick them off as you go; the list below remembers your progress in this browser.

Test 1 — Did your IP actually change?

The baseline check, and the only one most people ever run. Disconnect the VPN and note the address on what is my IP. Connect, reload, and look again.

A pass looks like a completely different address, in the country you selected, with the ISP name showing your VPN provider or a hosting company rather than your home ISP. A fail is the same address, or a different address that still resolves to your own ISP — which usually means the tunnel silently failed and the app has not noticed.

Test 2 — Are your DNS lookups leaking?

This is the one that catches most people, because everything appears to work perfectly while it is broken. Your traffic goes through the tunnel, but the lookups that translate every domain name you visit go straight to your ISP’s resolver — handing over a complete list of the sites you are visiting, in real time.

Run the DNS leak test while connected. A pass shows only resolvers belonging to your VPN provider. A fail shows your ISP’s name, your home country, or a public resolver you did not configure. A leak here defeats most of the reason you connected, and a surprising number of setups have one.

If you find one, the usual causes are: an operating system that ignores the tunnel’s DNS settings, a browser using its own secure DNS provider, or a router with hard-coded resolvers. Fixing it is usually a setting, not a rebuild.

Test 3 — Is WebRTC announcing your real address?

WebRTC is the browser technology behind video calls, and to make peer-to-peer connections work it will happily enumerate your local and public IP addresses — from inside the page, in JavaScript, regardless of what your VPN is doing at the network layer.

Check it with the WebRTC leak test. A pass shows only your VPN’s address, or nothing at all. A fail shows your real public address next to the VPN one — meaning any site you visit can read both, and pair them.

This is a browser-level problem with a browser-level fix, so it survives switching VPN providers. Worth re-checking after every browser update.

Test 4 — Does the kill switch actually cut traffic?

A kill switch is supposed to block all traffic the moment the tunnel drops, so a reconnection never happens in the clear. Most apps have the setting. Fewer people have ever watched it work.

Test it deliberately: turn the kill switch on, start something continuous — a video stream or a long download — then kill the VPN connection from the app or pull the network cable. A pass is the stream stopping dead and staying dead until you reconnect. A fail is the stream carrying on for a few seconds, or reconnecting on its own, which means those packets went out with your real address attached.

Do this on every device you rely on, not just the laptop. Phones are the common failure case: they switch between Wi-Fi and mobile data constantly, and each switch is a chance to leak.

Test 5 — What still identifies you anyway?

The honest one. Even with a perfect tunnel, no DNS leak and a working kill switch, your browser broadcasts a configuration profile — fonts, screen dimensions, timezone, graphics quirks — that is frequently unique enough to recognise you across sites and sessions without a single cookie.

Look at your own with the fingerprint test, then run the broader privacy check for the full picture. This is not a VPN failure and no VPN fixes it. It is the boundary of what the tool does, and knowing where that boundary sits is worth more than another feature you were told to trust.

What to do with a failure

  • A DNS leak Enable the provider’s own DNS in the app, turn off your browser’s independent secure-DNS setting, and re-test. If it persists, the router is usually the culprit.
  • A WebRTC leak Fix it in the browser — disable or restrict WebRTC, or use a browser that scopes it to the active interface. No VPN setting solves this one.
  • A kill switch that does not cut Check it is actually enabled for that network type, then re-test on mobile data as well as Wi-Fi. If it still fails, that is a serious defect worth raising with your provider.
  • Everything passes Re-run after your next OS or browser update. These leaks are usually introduced by a change somewhere else, not by the VPN.
Your progress

Tick them off as you go

Saved in this browser only — nothing is sent anywhere, which is rather the point.

0 of 5 done
LunoVPN

Run the tests on us

All five tools are free, take no signup, and work with any provider — ours or otherwise. If yours fails a test, we would rather you know.

Get LunoVPN See pricing
FAQ

Common questions

How do I know if my VPN is actually working?
Check five things rather than the app icon: that your public IP changed, that DNS queries resolve only through the VPN, that WebRTC is not exposing your real address, that the kill switch cuts traffic when the tunnel drops, and what your browser fingerprint still reveals. All five take about ten minutes.
What is a DNS leak?
Your traffic goes through the VPN tunnel but the lookups that convert domain names to addresses go to your ISP's resolver instead. Your ISP then has a live list of every site you visit, even though the connection itself is encrypted. It is the most common VPN misconfiguration and everything appears to work normally while it happens.
Can a VPN stop browser fingerprinting?
No. Fingerprinting reads your browser's configuration — fonts, screen size, timezone, graphics behaviour — from inside the page. A VPN changes the network path, not the browser. Reducing fingerprinting takes browser-level measures, and any provider claiming otherwise is overselling.
How often should I test my VPN?
Once when you set it up, and again after any change that could affect the network path: an OS update, a browser update, a new router, or a new device. Leaks are usually introduced by a change elsewhere rather than by the VPN itself.
Do these tests work with any VPN provider?
Yes. They measure your connection, not our product. Every tool linked here is free, requires no account, and gives the same answer regardless of which provider you use.
© 2026 LunoVPN — We don’t know who you are, and that’s by design.