Short answer

A candidate is not automatically a leak. A private IPv4 address or an mDNS .local name is local-network information. A public candidate can matter when it reveals a route you did not intend to expose, especially when it differs from the VPN or proxy route websites normally see.

Run the local-only WebRTC candidate test →

How to read an ICE candidate

This synthetic documentation address shows the standard candidate shape:

candidate:842163049 1 UDP 1677734911 203.0.113.7 61764 typ srflx raddr 192.168.1.14 rport 61764
842163049Foundation used to group similar candidates
1Component, usually RTP/data transport
UDPTransport protocol
1677734911ICE priority, not a privacy score
203.0.113.7:61764Example address and port; 203.0.113.0/24 is reserved for documentation
typ srflxServer-reflexive candidate learned with STUN
raddr / rportRelated local address and port reported by the candidate

Candidate types: host, srflx, prflx, and relay

Host describes a route from a local interface. Modern browsers may replace a local IP with an mDNS name. Server-reflexive (srflx) describes a NAT mapping learned through STUN. Peer-reflexive (prflx) is learned during connectivity checks. Relay is an address allocated by a TURN server.

Candidate priority helps ICE choose a route; a larger number is not evidence that an address is safer or more private.

When a candidate deserves review

First record the public route visible to an ordinary HTTPS request. Then inspect WebRTC candidates. If a public-looking candidate shows a different address from the route you meant to expose, investigate the browser, VPN split-tunneling policy, and the exact STUN/TURN configuration used by the test.

A private address, carrier-grade NAT address, loopback address, link-local address, or mDNS name is not by itself evidence that a public IP escaped a VPN. Conversely, an empty candidate list can mean the browser withheld details; it does not prove that every WebRTC configuration is safe.

What the MyIPCheckup test covers

The current test uses RTCPeerConnection({iceServers: []}). It requests no media permission and sends no candidate inventory to MyIPCheckup. It also contacts no third-party STUN or TURN server. That makes the data path narrow and explicit, but it means the test cannot rule out a public srflx candidate that a STUN-enabled site could gather.

Primary references

MDN: RTCIceCandidate type defines the browser-facing candidate types. RFC 8445: Interactive Connectivity Establishment specifies ICE terminology and processing. The example above uses an address reserved for documentation by RFC 5737.