What Is a WebRTC Leak?
what is a webrtc leak: clear guide, checks, and next steps.
Quick answer
WebRTC is a browser-networking signal. Run the WebRTC Leak Test, compare public, local/private, and masked candidates, then use the VPN and IPv6 checks for the full route picture.
Article to tool flow
Browser candidates can differ from the normal page request route.
A Privacy Receipt is a reduced, share-safe diagnostic summary. It removes raw IP addresses, exact city, full User-Agent, resolver IPs, and WebRTC candidates. It is not proof of anonymity, a VPN provider audit, or a security certificate.
Summary FAQ
What should I do after reading this article?
Run the linked WebRTC Leak Test first, then compare one related tool if the result does not match what you expected.
What should I save or share?
Use the Privacy Receipt when you need a safe summary. Avoid posting raw IPs, exact location, full User-Agent, resolver IPs, or WebRTC candidate strings publicly.
Does a clean-looking result mean everything is private?
No. MyIPScan checks visible browser/session signals in this context. It helps you find review items, but it does not certify a VPN, device, provider, account, or network.
WebRTC checks separate browser candidates from the public IP route so the result is easier to interpret.
| Candidate | What it may mean | Best next check |
|---|---|---|
| Public candidate | A browser-level route may expose a public address | Reconnect the VPN and rerun the same browser check. |
| Private or mDNS candidate | The browser may be masking local network details | Confirm whether local exposure matters for your use case. |
| No candidates | WebRTC may be blocked, limited, or unavailable | Check calls or real-time apps if you depend on WebRTC. |
What a WebRTC Leak Means
WebRTC is a browser technology used for real-time communication features. To support those features, a browser may gather network candidates that describe possible connection paths.
A leak concern appears when candidate behavior surfaces a public address or route context that conflicts with the user’s expected privacy setup. Local or private candidates are different from public exposure and should not be described as the same risk.
WebRTC results are browser-specific. A setting or extension that changes behavior in one browser may not apply the same way in another browser profile or device.
This is related to browser privacy, but it is not the same intent as browser fingerprinting. WebRTC focuses on candidate behavior; fingerprinting covers broader browser surfaces.
What MyIPScan Checks
Use the WebRTC Leak Test to inspect visible WebRTC candidate behavior in the current browser session.
If you are checking a VPN setup, pair it with the VPN Leak Test. Browser identity and capability signals may also matter, so review the Browser Fingerprint Test and User-Agent Checker when context is needed.
The methodology explains why WebRTC public, local, limited, masked, and unknown categories should be interpreted separately.
How to Interpret the Result
If a public candidate is visible, the result deserves review because the browser surfaced a network signal that may be outside your expected route. If only local or limited candidates appear, that is not the same as public IP exposure.
Unknown or unsupported WebRTC behavior lowers confidence. It may mean the browser blocks the feature, the test could not gather a useful signal, or the environment behaves differently.
What the Result Cannot Prove
The WebRTC test cannot prove every WebRTC risk is absent. It checks candidate behavior available to the current browser session.
It does not certify a VPN provider or inspect every browser permission, extension, operating-system setting, app, or device.
What to Do Next
If review is needed, check browser WebRTC settings, privacy extensions, VPN leak-protection settings, and browser permissions. Retest after one change at a time.
A Privacy Receipt can summarize the WebRTC category safely. It should not copy or export raw candidate strings.
Next Step: Run the Related MyIPScan Checks
Check it on MyIPScan: run the primary diagnostic for the current browser session.
- Primary check: WebRTC Leak Test
- Related check: VPN Leak Test
- Related check: Browser Fingerprint Test
- Related check: User-Agent Checker
- Methodology: read MyIPScan Methodology v1.1
FAQ
What is a WebRTC leak?
It is a browser candidate signal that may expose network context you did not expect, especially when a public candidate is visible.
Does a WebRTC test prove all browser leak risk is gone?
No. It checks candidate behavior available to the current browser session and has limits.
How can I verify WebRTC behavior?
Run the WebRTC Leak Test in the browser profile you actually use, then compare after changing settings.
Is a local WebRTC candidate the same as public IP exposure?
No. Local or limited candidates are different from public candidates and should be interpreted separately.
What should I do if a public candidate appears?
Review browser settings, extensions, VPN leak-protection options, and retest after each change.