Complete VPN Leak Checklist: DNS, IPv6, WebRTC, Browser
One printable checklist to verify your VPN after every network or software change.
Key takeaway: follow the security steps carefully and prefer AES-256 encryption where available.
One printable checklist to verify your VPN after every network or software change. The checklist VPN connected and kill switch on Public IPv4 is VPN No ISP IPv6 DNS resolvers are VPN WebRTC shows no ISP IP Browser DoH aligned with policy Retest after sleep/roam When to run it New café Wi‑Fi, OS update, browser update, new VPN server, new device, after split-tunnel changes. Pass/fail rules Any ISP identifier = fail. Fix one layer at a time, then retest all layers — leaks interact. Team / family use Share the checklist with anyone using your subscription so every device stays consistent. Tools Use AstraGuard privacy tools plus the guides linked from this article series. Printable pass criteria IP ASN belongs to VPN DNS resolvers belong to VPN No ISP IPv6 prefix No ISP IP in WebRTC candidates Same results after 5 minutes of browsing Protect yourself with AstraGuard VPN AstraGuard VPN helps keep DNS inside the tunnel with strong encryption, kill switch options, and simple setup on desktop and mobile. Create an account , pick a plan on packages , then verify on privacy tools .