Start with a baseline
Before connecting, note the public IP address, address version, approximate location, and network provider visible to websites. This baseline gives you something concrete to compare after the tunnel starts.
Avoid sharing the full address in screenshots or support posts unless necessary. Treat it as network information that can be sensitive when combined with other details.
Connect and reload
Connect to the chosen VPN server, wait for the application to report a stable connection, and reload the IP checker. The public address should normally change to an address operated by the VPN service.
The approximate country or region should align with the selected exit, allowing for ordinary IP-location inaccuracies. If both the address and location remain unchanged, the traffic may not be using the tunnel.
Check IPv4, IPv6, and DNS
A VPN can route IPv4 correctly while allowing IPv6 to use the normal connection. Verify both protocols when your network supports them. Some VPNs intentionally disable IPv6 rather than tunnel it.
DNS requests should use the resolver expected by the VPN configuration. A DNS result that names your usual provider is not always proof of a leak, but it deserves investigation alongside the provider's documentation.
Test failure behavior
If the VPN offers a kill switch, test it carefully by interrupting the tunnel and checking whether internet access stops. Do this without active downloads or sensitive sessions. The goal is to confirm that applications do not silently fall back to the normal route.
Review split-tunneling rules too. Excluded applications are expected to retain the ordinary public IP, while included applications should use the VPN exit.
Disconnect and compare again
Disconnect the VPN and reload the checker. The baseline network address or another address from the same provider should return. A dynamic connection may not reproduce the exact original value, so compare provider and region as well.
If results are inconsistent, restart the VPN application, inspect its route and DNS settings, update it, or contact the provider. A single green status indicator is less reliable than a repeatable before-and-after test.