Skip to content
LunoVPN
Free privacy scanner

Scan yourself. We won’t see the results.

Every site you open reads a surprising amount about your device before you click anything. This hybrid scan combines the three checks that usually live on separate pages — DNS leak, WebRTC leak and browser fingerprint — and shows you exactly what a tracking company would get, including the things our own product cannot fix.

DNS leak check WebRTC leak check Browser fingerprint check
privacy-check · hybrid scan RESULTS: LOCAL-ONLY

Nothing you see below is uploaded, stored or logged. The fingerprint and signal probes make no network requests at all; the two leak probes (DNS and WebRTC) are the only ones that touch the network, and they carry nothing but random tokens — never your results. Open your browser’s developer tools and watch the Network tab; that’s rather the point of this page.

0exposure score

composite fingerprint of this browser:

The exposure score is an indicative summary of the signals found on this page, not a scientific measurement of how identifiable you are. Real uniqueness depends on how rare your particular combination is across the whole population of browsers, which no single site can determine on its own.

The uncomfortable part

Fingerprinting is the tracking that survives everything

Most people picture tracking as cookies, and picture the solution as deleting them. That model is about a decade out of date. The dominant technique now identifies you by how your device is configured rather than by anything stored on it, which means there is nothing to delete.

The scan above shows the raw material: your timezone, language, screen geometry, graphics hardware, available fonts, processor count and a dozen smaller details. Individually none of them identifies anybody — plenty of people have a 1920×1080 screen. Combined, they form a pattern that is frequently unique, and crucially it is stable. Clearing cookies does not change it. Private browsing does not change it. Connecting through a VPN does not change it, because none of it travels over the network in a way a tunnel could hide; it is read directly by the page you are visiting.

Cookies are a name tag you can take off. A fingerprint is your handwriting.

Canvas and WebGL: the sharpest signals

Two of the checks deserve special mention because they are unusually revealing. A canvas fingerprint asks your browser to draw an invisible image and then hashes the result. Because rendering depends on your graphics driver, fonts and operating system, the same instruction produces subtly different pixels on different machines, and that difference is remarkably consistent on yours. WebGL goes further and can often report your actual graphics card model, which narrows the field considerably.

Neither exists to track you — they are legitimate graphics features that tracking simply repurposed. That is the awkward pattern across this whole area: the most effective identifiers are side effects of useful things.

Why we are showing you what we cannot fix

We sell a VPN, and a VPN does nothing about most of what the scan finds. We could have built a tool that only tested the things our product solves, presented you with an alarming red result, and sold you the fix. Plenty of sites do exactly that.

It seemed more useful to show the whole picture, including the large part of it where the answer is “change your browser, not your VPN”. A tool that exaggerates the problem it happens to solve is advertising wearing a lab coat, and you can generally tell.

Matching problem to tool

What actually fixes what

Privacy is layered, and each layer has one job. Here is which tool addresses which exposure — including the rows where the answer is not us.

ExposureFixed byHow
Your IP addressA VPNHidden by connecting through a VPN server — the site sees the server, not you.
Your ISP seeing your browsingA VPNEncrypted between you and the VPN server, so the network sees a tunnel rather than destinations.
Browser fingerprintYour browserA VPN cannot help. Use a browser that resists fingerprinting, and avoid exotic configurations.
Canvas & WebGL signaturesYour browserBlocked or randomised by fingerprint-resistant browsers and some extensions.
Cookies & cross-site trackingYour browserThird-party cookie blocking and separate profiles or containers do the work here.
Accounts you log intoNothing, technicallyIf you sign in, you are identified. Compartmentalise instead: separate accounts, separate profiles.
Timezone & language mismatchYour browserA VPN changes your apparent country but not your clock, which is why the two can disagree.
Payment identityPrivate paymentCards identify the buyer regardless of connection privacy. Monero does not.

Three of these eight rows are solved by a VPN, and we would rather tell you that than imply otherwise. If you want to work out which layers matter for your situation specifically, the threat model assessment is a better starting point than any product page.

FAQ

Privacy check questions

Does this privacy check send my data anywhere?
No result is ever transmitted, logged or stored, and you can prove it rather than trust it. The fingerprint and signal probes run entirely in your browser and make no network requests at all. The two leak probes are the exception by nature — the DNS check issues lookups for random one-time subdomains and the WebRTC check contacts a STUN server — but those requests carry nothing except random tokens. Open your browser’s developer tools, switch to the Network tab and run the scan again: you will see no request carrying your results, because there isn’t one.
What does the hybrid scan combine?
Three checks that usually live on separate pages: a DNS leak check (are your lookups answered inside the VPN tunnel or by your internet provider?), a WebRTC leak check (does the browser technology behind video calls reveal your network addresses to the page?) and a browser fingerprint check (canvas, WebGL, fonts, hardware and display signals). Each category gets its own verdict, and each links to the dedicated deep-dive test if you want the full picture: the DNS leak test, the WebRTC leak test and the browser fingerprint test.
What is browser fingerprinting?
It is identification by configuration rather than by cookie. Your timezone, language, screen size, fonts, graphics hardware and dozens of other details combine into a pattern that is often unique or near-unique, and that pattern stays recognisable when you clear cookies, open a private window or connect through a VPN. It is the tracking method that survives almost everything people do to avoid tracking.
Does a VPN stop fingerprinting?
No. A VPN changes your IP address and encrypts the connection, which defeats IP-based tracking and hides your browsing from your network. Fingerprinting works entirely inside the browser, so it carries on regardless. Anyone claiming their VPN makes you unfingerprintable is describing a browser, not a VPN.
What is a WebRTC leak?
WebRTC is the browser technology behind video calls, and it can reveal network addresses directly to a website, in some configurations bypassing a VPN tunnel entirely. Modern browsers obscure local addresses by default, but the risk is real enough that it is worth checking rather than assuming.
Why does my timezone matter?
Because it is a location signal that a VPN does not change. If your IP address says one country while your browser clock says another, that mismatch is itself informative — it suggests a VPN is in use and hints at where you actually are.
What is Do Not Track, and why is it usually useless?
Do Not Track is a request your browser sends asking sites not to track you. It carries no legal weight in most places and the overwhelming majority of sites simply ignore it. Global Privacy Control is a newer signal with actual legal standing under some privacy laws, which makes it worth enabling even though coverage is still uneven.
My score is bad. What should I fix first?
Work down from the biggest exposure rather than trying to fix everything. In practice that usually means using a browser that resists fingerprinting by default, adding a content blocker, and keeping accounts separated so that logging into one service does not connect your whole session together. A VPN belongs on that list, but it is rarely the first item.
Is a perfect score even possible?
Not really, and chasing one can backfire. A browser configured with unusual anti-fingerprinting settings can end up more identifiable than a normal one, because the unusual configuration is itself a distinguishing signal. Blending in is often stronger than locking down.

We can fix the network half. Honestly, that’s the half we do.

No email at signup, no logs to search, and an independently audited claim behind it.

Get LunoVPN Do I even need one?