Is your VPN secure? How to check for leaks

A trusted virtual private network is a great tool for security and privacy, but if it's not configured correctly it may not be so private.

A trustworthy virtual private network (VPN) is a good way to keep your internet usage secure and private whether at home or on public Wi-Fi. But just how private is your activity over a VPN? In other words, how do you know if the VPN is doing its job or if you’re unwittingly leaking information to prying eyes?

To find out, you first need to know what your computer looks like to the internet without a VPN running. Start by searching for what is my IP on Google. At the top of the search results, Google will report back your current public Internet Protocol (IP) address. That’s a good place to start, but there is more to your internet connection and its potential for leaks.

Diving deeper

ipleaknet

An example analysis from IPLeak.net.

Your public IP address is one way private information can leak over a VPN, but you can also leak information via Domain Name System (DNS) queries, WebRTC, torrents, and geolocation. To see what you look like in your default state, visit IPLeak.net. This website checks all the previously mentioned methods for leaking data. Take note of all the data you see on this page so you can compare it to your VPN’s.

Now close this site, connect to your VPN, and navigate back to IPLeak once again to see what you look like over your VPN of choice.

Not all of these tests happen automatically. The torrent test, for example, requires a small torrent file (available via magnet link) to run before it can detect any potential leakage.

The geolocation test is helpful, but keeping your location secure is pretty straightforward. Just don’t allow any website to use your location while on a VPN. One way to do that is to specify a browser, Firefox for example, as your VPN-only browser. Then disallow location requests on that browser. Alternatively, you could use a browser extension that provides a fake location to websites that request it.

The most likely culprit for leaked information, however, is DNS. To navigate the web your machine requires contact with DNS servers to help translate website addresses from names to numeric IP addresses. Typically your PC automatically uses the DNS servers of your internet service provider. The problem is that if you’re using a VPN and leaking DNS through a local service provider, you can reveal enough information to point anyone spying on you in the right direction. That’s why VPN services often funnel their customers’ queries through DNS servers that aren’t connected to your ISP.

Diving even deeper

dnsleak IDG

The landing page for DNSLeakTest.com.

IPLeak is great, but there’s nothing like a little redundancy to ensure you’re really private over a VPN. As a second check against DNS leaks go to DNSLeakTest.com, and from the landing page choose the Extended test. This typically takes some time to complete, but it’s worth it as I have seen leaky results on this site that IPLeak didn’t catch.

If you are still seeing DNS servers from your VPN provider, and not your ISP, then you can be reasonably sure you aren’t leaking data.

Some top VPN choices

Many VPN services these days do a good job of preventing the various data leaks that could reveal your identity, and our top-rated VPN services should all work well. Still, if you’d like some specific advice, here are four VPNs that do a good job of protecting against data leaks on both Windows and Android. In most cases, you shouldn’t have to make any settings adjustments to the VPN, but if there are any notable settings to be aware of we will note them here.

hotspotshieldrunning IDG

HotSpot Shield Elite.

First up is HotSpot Shield Elite. A recent addition to our best VPN roundup. HSS does a great job of stopping leaks, and unlike many of the other services here it uses multiple DNS servers on mobile. HSS Elite costs $72 for a full year’s subscription, or you can pay $120 for a lifetime of use. In the Windows app under Settings > General Settings there’s an option called Prevent IP leak that is turned on by default.

nordvpnstart NordVPN

NordVPN

NordVPN also does a good job of keeping leaks away and its app is easy-to-use as well. This service costs $69 for a year’s subscription. NordVPN doesn’t have any DNS or IP leak settings to worry about, but it does have a new setting called CyberSec that blocks ads, and protects against various malware threats and botnet control. This is turned off by default, but it’s a good option to turn on since even on a VPN cookies set by advertisers make it possible to track you online.

windflix IDG

Windscribe Pro

Windscribe Pro is a great option that is also simple to use and costs $49 per year. It does not have any settings you need to worry about, but you can get enhanced privacy protections, such as ad blocking, if you install the service’s browser extension in addition to the desktop app. If you’re not willing to pay for a VPN, Windscribe offers a free version with up to 10GB per month.

tunnelbear 1 TunnelBear

TunnelBear

Finally, TunnelBear is another fantastic option for preventing VPN and IP leaks. TunnelBear costs $50 per year. It doesn’t have any leak protection settings you need to worry about. There is a “GhostBear” setting that is supposed to make your VPN traffic look closer to unencrypted traffic though it can make your browsing speeds slower.

 

What to do if you’re leaking DNS

As we’ve just discussed, many set-it-and-forget-it type VPNs funnel your DNS requests through their own providers, though some require an explicit settings change to do this. Check your VPN provider’s help pages if you are leaking DNS for advice on how to fix it.

Another way to address this issue is to permanently switch your PC to an alternative DNS provider such as Google, OpenDNS, or Comodo Secure DNS. That way if your VPN provider’s DNS fails, you won’t be using DNS tied to your ISP.

Once you’ve fixed your DNS problems, return to DNSLeakTest to see what it reports. If it shows DNS servers that aren’t related to your ISP or general location then you’re all set to enjoy added privacy over your VPN connection.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ian Paul

PC World (US online)
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?