stun:stun.l.google.com:19302
- Public IP
- Checking…
- Local IP
- Checking…
- mDNS hostname
- Checking…
Check whether WebRTC reveals an IP address different from the one websites see. STUN requests often travel outside a proxy tunnel and expose your real public IP or your local network address.
Gathering ICE candidates from each STUN server.
0/9 STUN servers finished
Each server is asked in its own WebRTC connection. The public IP is the address that STUN server saw your browser connect from.
stun:stun.l.google.com:19302
stun:stun2.l.google.com:19302
stun:stun.cloudflare.com:3478
stun:global.stun.twilio.com:3478
stun:stun.nextcloud.com:443
stun:stunserver.stunprotocol.org:3478
stun:stun.syncthing.net:3478
stun:stun.miwifi.com:3478
stun:stun.qq.com:3478
WebRTC lets browsers make real-time audio, video and data connections. To find a route between peers it asks STUN servers which address you connect from. Those requests often bypass the proxy or VPN, so any website can read your real public IP with a few lines of JavaScript.
We open a WebRTC connection to each of nine public STUN servers and collect the ICE candidates your browser produces. Server-reflexive addresses are compared with the IP this page arrived from — exactly for IPv4, and by /64 network for IPv6, because IPv6 privacy addresses rotate within the same network.
A private address such as 192.168.x.x does not locate you, but it narrows down your device and network. Modern browsers replace it with a random .local mDNS hostname; seeing a real local address means that protection is off.
Use a VPN that tunnels UDP and IPv6, or set WebRTC to use the proxy IP in your anti-detect browser. In Firefox you can turn off media.peerconnection.enabled; in Chromium browsers an extension or the WebRtcIPHandling policy can restrict WebRTC to the proxied interface.