Full Browser Privacy Scan
YOUR PUBLIC IP ADDRESS
Detecting...

A complete 12-point scan of your browser's privacy exposure — IP leaks , WebRTC , fingerprint uniqueness, DNS routing , canvas tracking, timezone mismatch, and more. Results in under 15 seconds.

100% client-side  ·  No data stored  ·  Free forever

Verified Testing Engine

All checks run entirely inside your browser. Zero data leaves your device.

Zero packet inspection No tracking logs 100% passive scan

How to read your composite score

A single number out of 100 is convenient, but it can hide what actually matters. This scan averages 12 checks that don't carry equal real-world risk — treat the score as a starting point, then open the individual result cards above to see which specific signal is driving it.

One red flag can outweigh nine green checks

A confirmed WebRTC or DNS leak that exposes your real IP is a categorically more serious exposure than a mediocre fingerprint uniqueness score, even though both only move the headline number by a similar amount. If your IP or WebRTC card shows red, treat it as the priority fix regardless of what the overall score reads — run the dedicated WebRTC leak test for the full ICE candidate breakdown.

Fingerprint scoring isn't pass/fail like leak checks

IP and DNS checks are binary — either your real address leaked or it didn't. The fingerprint component is inherently probabilistic: it estimates how rare your signal combination is, not whether something is broken. A high fingerprint score describes your exposure if a tracker chose to use it, not a confirmed problem the way a red WebRTC badge is.

Test with your VPN on AND off

A single scan only tells you your exposure under the conditions you happened to be in. The more useful comparison is running the scan once with your VPN disconnected as a baseline, then again with it active — that delta shows you exactly what your VPN is and isn't protecting, which a one-time score can't show on its own.

A "blocked" storage check isn't always bad

Safari's Private Browsing mode restricts or blocks IndexedDB and persistent storage by design — a "blocked" result there is the browser's own privacy feature working, not a misconfiguration. The same check run in a normal window, or in a different browser's private mode, can legitimately show a different result without either being "wrong."

Frequently asked questions

“Is one combined score better than running each individual test?”
They answer different questions, and we'd recommend both. The combined scan is fastest for a general health check and for catching a signal you weren't thinking to test — like a timezone mismatch you didn't know was a leak vector. The dedicated single-purpose tests (WebRTC, DNS, IP) go deeper on that one signal — for example, the standalone WebRTC test shows every individual ICE candidate with type and IP, which the summary card here condenses into a single pass/fail badge. Use the full scan to find where to look, then the specific test to see exactly what's happening.
“My WebRTC leak test showed clean, but the full scan flagged an issue — why?”
This usually means the two tests ran under different conditions, most often because a VPN connection state changed between the two tests, or because the WebRTC leak test was run in a different browser tab or profile than the full scan. Both tools use the same underlying detection logic, so if conditions are identical, results should match — re-run both within the same tab, back to back, to confirm.
“What counts as a "good" privacy score?”
There's no universal passing number, because the checks aren't weighted equally in real-world risk — see our published scoring methodology for exactly how each signal is weighted. A single WebRTC or DNS leak that exposes your real IP is a more serious exposure than a middling fingerprint uniqueness score, even if the leak only costs you a few summary points. Read the individual card badges, not just the headline number — a 90/100 with one red "IP leak detected" card is a worse security posture than an 80/100 with only medium-severity fingerprint findings.
“Does this scan send or store my results anywhere?”
No. Every check — IP lookup aside, which necessarily contacts an external API to resolve your address — runs and scores entirely inside your browser. Your composite score, badges, and attribute values are computed in JavaScript on your device and are not transmitted to or stored on PrivacyTestLab's servers. You can verify this yourself by opening your browser's Network tab during a scan, or read our transparency page and privacy policy for the full data-handling policy.
“Why does the scan flag my storage checks as "blocked" in Safari Private Browsing — is that a problem?”
No — that's expected behavior, not a leak. Safari's Private Browsing mode restricts or fully blocks IndexedDB and persistent localStorage by design as a privacy feature, so a "blocked" result there reflects Safari doing its job, not a misconfiguration on your end. The same check in a normal (non-private) Safari window, or in Chrome/Firefox private modes, which handle storage restrictions differently, may show a different result — this is one area where "worse-looking" isn't actually worse.
“How often should I re-run this scan?”
Re-run it any time you change something that could affect your exposure — connecting or disconnecting a VPN, switching browsers, installing or removing an extension, or updating your OS or browser version (which can change fingerprint signals like the WebGL renderer string). Outside of specific changes, a monthly check is reasonable for most people; daily re-scanning won't surface new information unless your setup has actually changed.
“Does a high fingerprint score mean someone is tracking me right now?”
No — it measures exposure, not an active event. The fingerprint component estimates how rare your specific combination of signals is, which determines how easily a tracker *could* re-identify you if they tried. It doesn't mean any particular site is currently doing so. Run our dedicated Browser Fingerprint Test for the full 14-signal breakdown behind this card's score.
“Can I fix everything this scan flags?”
Most, but not all. WebRTC and DNS leaks are directly fixable with browser settings or extensions we link to on the dedicated test pages. Fingerprint-related signals (screen resolution, installed fonts, CPU thread count) are harder to fully eliminate without switching to a hardened browser like Brave or Tor, since some of those values are inherent to your actual hardware. The realistic goal for most people is reducing exposure meaningfully, not reaching a perfect, untraceable score.

Community

Get the next leak test before it's news

Tool releases and research notes, sent when there's something worth reading. Nothing else.

At least 10 characters.