Short answer
A candidate is not automatically a leak. A private IPv4 address or an mDNS .local name is local-network information. A public candidate can matter when it reveals a route you did not intend to expose, especially when it differs from the VPN or proxy route websites normally see.
How to read an ICE candidate
This synthetic documentation address shows the standard candidate shape:
candidate:842163049 1 UDP 1677734911 203.0.113.7 61764 typ srflx raddr 192.168.1.14 rport 61764
842163049Foundation used to group similar candidates1Component, usually RTP/data transportUDPTransport protocol1677734911ICE priority, not a privacy score203.0.113.7:61764Example address and port; 203.0.113.0/24 is reserved for documentationtyp srflxServer-reflexive candidate learned with STUNraddr / rportRelated local address and port reported by the candidateCandidate types: host, srflx, prflx, and relay
Host describes a route from a local interface. Modern browsers may replace a local IP with an mDNS name. Server-reflexive (srflx) describes a NAT mapping learned through STUN. Peer-reflexive (prflx) is learned during connectivity checks. Relay is an address allocated by a TURN server.
Candidate priority helps ICE choose a route; a larger number is not evidence that an address is safer or more private.
When a candidate deserves review
First record the public route visible to an ordinary HTTPS request. Then inspect WebRTC candidates. If a public-looking candidate shows a different address from the route you meant to expose, investigate the browser, VPN split-tunneling policy, and the exact STUN/TURN configuration used by the test.
A private address, carrier-grade NAT address, loopback address, link-local address, or mDNS name is not by itself evidence that a public IP escaped a VPN. Conversely, an empty candidate list can mean the browser withheld details; it does not prove that every WebRTC configuration is safe.
What the MyIPCheckup test covers
The current test uses RTCPeerConnection({iceServers: []}). It requests no media permission and sends no candidate inventory to MyIPCheckup. It also contacts no third-party STUN or TURN server. That makes the data path narrow and explicit, but it means the test cannot rule out a public srflx candidate that a STUN-enabled site could gather.
Primary references
MDN: RTCIceCandidate type defines the browser-facing candidate types. RFC 8445: Interactive Connectivity Establishment specifies ICE terminology and processing. The example above uses an address reserved for documentation by RFC 5737.