Ir para o conteúdo
FortiSafe VPN

DNS, IPv6 and WebRTC leak test: what we measured

FortiSafe team ·

A leak is when part of your traffic leaves the VPN tunnel and reveals your internet provider. We tested the FortiSafe connection on 14 September 2026, on an iPhone, with and without the VPN: with the VPN on, the IP address, DNS servers and WebRTC didn't show the provider. IPv6 was inconclusive, because the network we used had no IPv6. The test covered a single device, and Mac wasn't tested.

What each leak is

DNS: the lookup that turns a website's name into an address. If it goes outside the tunnel to your provider's server, the provider can see which sites you look up, even with the VPN on. The test resolves dozens of random names and shows which DNS servers made the lookups.

IPv6: the newer version of the IP address. If a VPN only handles IPv4, IPv6 traffic can go straight out over your provider's network, with your real address.

WebRTC: the browser feature for video and audio calls. RFC 8828, from the IETF, explains that with a VPN that splits traffic between the tunnel and the regular network, WebRTC can reveal the provider's public address as well as the VPN's.

How we ran the test

  • Date and device: 14 September 2026, on an iPhone, in Safari, on a network from an internet provider in Paraguay.
  • Connection: the WireGuard app with a FortiSafe configuration, server br1.vpn.fortisafe.net in São Paulo, and DNS protection at the scams and malware level. The FortiSafe app is still in development.
  • Tool: the IP, DNS and WebRTC pages on BrowserLeaks, a testing site that doesn't sell VPNs.
  • Two rounds: without the VPN, to record who the internet provider is, and with the VPN. Without the no-VPN round, you can't tell whether the test would see the provider at all.
  • DNS filter: in both rounds, we opened a domain used to test whether DNS filters block malware.
  • A lesson learned: the first no-VPN round was thrown out. iCloud Private Relay was on and hid the provider behind an Apple address. We redid it with Private Relay off.

The results

TestWithout VPNWith VPN
IP address The internet provider's IP, in Paraguay. The VPN server's IP, in São Paulo. The provider doesn't appear.
DNS 6 servers, all from the internet provider. 8 servers, all from the DNS filter. None from the provider.
WebRTC The internet provider's IP. The VPN server's IP. The site showed "No Leak".
IPv6 No IPv6 address: the network had no IPv6. No IPv6 address. Inconclusive, because the network had no IPv6.
DNS filter (malware) The test domain opened. The test domain didn't open.

What the results mean — and what they don't

On that device, on that network and on that date, the VPN kept the IP address, DNS lookups and WebRTC inside the tunnel, and the DNS filter worked inside it.

IPv6 wasn't proven: since the network had no IPv6 even without the VPN, there was nothing to leak. The configuration sends IPv6 into the tunnel but doesn't give the device an IPv6 address, so anyone using the VPN has no IPv6.

This is one device's result. Mac, Windows and Android weren't tested, and each browser handles WebRTC in its own way. We'll repeat the test on those systems and update this page.

How to run the test yourself

  • Turn off any other VPN and, on iPhone or Mac, iCloud Private Relay. Otherwise the no-VPN round won't show your provider.
  • With the VPN off, open browserleaks.com/ip, browserleaks.com/dns (and run the DNS test) and browserleaks.com/webrtc. Note which provider appears.
  • Turn the VPN on and open the same three pages.
  • A leak is your provider showing up with the VPN on: in the IP address, in the list of DNS servers, in IPv6 or in the WebRTC public IP. A private IP such as 192.168.x.x in WebRTC isn't your public IP.
  • If IPv6 doesn't show up even without the VPN, the IPv6 test doesn't apply to your network.

What about FortiSafe?

FortiSafe uses WireGuard and sends all of the device's traffic through the tunnel, including IPv6.

DNS protection chosen per device, with no filter, scams and malware, or scams, malware and adult content, is in development in the FortiSafe apps.

The kill switch, which blocks the internet if the VPN drops, is also in development.

Sources

Pages checked and test run on 14 September 2026.