WebRTC Leak Test: Inspect ICE Candidates
See which ICE candidates this browser exposes in a local-only WebRTC check, what each candidate type means, and what this limited test cannot prove.
Run the local-only test
The test creates a data-only peer connection after your click. It requests neither camera nor microphone and contacts no third-party STUN or TURN server.
Inspect copied ICE candidate lines
Paste only candidate: or SDP
a=candidate: lines you chose to copy. Parsing stays
in this browser: nothing is sent, saved, or used for a VPN or
public-route verdict.
How to interpret the candidates
Candidate type and address scope matter more than the mere presence of a candidate.
host: a local interface route
A host candidate may contain a private address, an mDNS-masked local name, or a publicly routable address. Private and mDNS values are not automatically leaks. A public-looking value deserves review against the route you intended to expose.
srflx, prflx, and relay
A server-reflexive candidate is a NAT mapping learned through STUN; a peer-reflexive candidate is learned during connectivity checks; a relay candidate uses TURN. This local-only test does not configure STUN or TURN, so those types normally will not appear.
What a result can prove
It can show candidate strings exposed by this browser with this exact configuration at this time. It cannot certify anonymity, every browser mode, every application route, or behavior with another site's STUN/TURN configuration.