Start with a clean baseline
Before connecting, record the public IP, network owner, approximate country or region, network timezone, and any available DNS or WebRTC result. A baseline turns the test into a comparison instead of a guess.
Keep the baseline short-lived. MyIPCheckup stores its comparison baseline only in this browser and expires it after 24 hours.
Confirm the public route changed
After connecting, the observed public IP and often the ASN or organization should change. City-level geolocation is weaker evidence because databases can disagree or lag behind network changes.
A changed IP confirms that this web request used a different visible route. It does not audit every application or prove that the VPN software is free of implementation defects.
Review DNS, WebRTC, and IPv6 separately
DNS requests, WebRTC candidate gathering, and IPv6 connectivity can reveal additional paths. Complete the tests your setup supports and treat a blocked or unavailable test as missing evidence.
Do not call an unavailable check safe. A responsible report distinguishes a completed negative result from an inconclusive result.
Interpret timezone carefully
A browser timezone that differs from the network location can be expected while traveling, using a remote desktop, keeping manual settings, or connecting through a distant VPN exit.
Timezone mismatch is supporting context, not proof of a VPN or a privacy failure.
Know what a browser test cannot certify
A website cannot inspect the VPN client source code, encryption implementation, kill switch, routing for every application, or operating-system policy.
Use browser results as observable evidence, then combine them with provider documentation, device settings, and independent security reviews.