What does "My IP" show once you're connected to a VPN?
Summary
An IP checker shows the address the internet sees your traffic coming from, and with a VPN on, that becomes the VPN server's address instead of your home or mobile connection's. The 192.168-style address in your Wi-Fi settings is a separate, local address and doesn't change. A new address on the checker doesn't prove you're hidden, though, because DNS lookups, a browser feature called WebRTC, and IPv6 can still give away your real details.
Three addresses, three different screens
The IP checker. This is your public address, the one websites see. Turn the VPN on and it switches to the VPN server's address.
Your device's Wi-Fi settings. Addresses beginning 10., 172.16 to 172.31, or 192.168 come from ranges reserved for private networks under RFC 1918. They have no meaning outside your home or office network and aren't routed across the internet, so a VPN leaves them alone.
Your router's WAN address. If it starts anywhere from 100.64 to 100.127, your internet provider is using carrier-grade NAT, and that address comes from the shared space set aside for it in RFC 6598. It isn't routable on the public internet either, which is why it won't match what the IP checker says, with or without a VPN.
Leaks that the IP checker won't catch
DNS is the first thing your browser contacts when you open a site. Proton VPN explains that if your VPN hides your IP but your ISP's DNS server is still exposed, that mismatch lets websites tell you're trying to mask who you are. Proton runs its own DNS servers to avoid it.
WebRTC lets browsers handle video and audio calls without plugins, and Mullvad warns that it can expose your real IP. On Android, Mullvad says Chrome and Firefox both leak your local IP address; Firefox can be set to stop it, Chrome can't.
IPv6 is the third route. Proton VPN, while it moves to full IPv6 support, turns IPv6 off in some of its apps so your IPv6 address can't be exposed by accident.
Mullvad's Connection check page is built for this, checking whether you're on the VPN and whether DNS or WebRTC is leaking.
When different apps show different addresses
Split tunneling sends some apps or destinations outside the VPN on purpose. Those apps go out through your home connection, so their address won't match the one your browser reports.
Apple's iCloud Private Relay works on a similar boundary. It covers browsing in Safari, sending requests through two relays, and the second relay assigns a temporary IP address. Apple describes it only in terms of Safari browsing.
A changing exit address becomes a problem when a company system only lets in specific IP addresses. A fixed address can come as a separate charge on top of the per-user price, and the dedicated IP cost page breaks that down.
Sources
- https://www.rfc-editor.org/rfc/rfc1918
- https://www.rfc-editor.org/rfc/rfc6598
- https://protonvpn.com/support/dns-leaks-privacy
- https://protonvpn.com/support/prevent-ipv6-vpn-leaks
- https://mullvad.net/en/help/webrtc
- https://mullvad.net/en/check
- https://protonvpn.com/support/protonvpn-split-tunneling
- https://support.apple.com/en-us/102602
Related on this site
- Does a VPN hide what you do online from everyone?
- What is a VPN tunnel, and does all of your traffic have to go through it?
- What does a VPN kill switch actually stop when the connection drops?
- Business VPN dedicated IP cost: what the fixed charge adds per person
- Business VPN pricing: what teams actually pay per user
Written by Kaz (pen name). Published September 28, 2026. The facts above come from the vendor and standards pages listed under Sources. We have not used these products. Corrections: contact form.