Guides ·
IPv6 leaks: why your IPv6 exit is in a different region
If your home connection gives your devices both an IPv4 and an IPv6 address, you are on a dual-stack network. When a site also has both kinds of address, your device picks one path for every connection. If your proxy only takes over IPv4 and the system follows its default of preferring IPv6, those connections never touch the proxy: they leave through your home line, and the site sees your ISP’s IPv6 address. That is an IPv6 leak, and IP Judge reports it as an IPv6 exit in a different region from your IPv4 exit. As of 1 October 2026, the domains of ChatGPT, Claude, Gemini and Muse all have IPv6 addresses, so this is not an edge case.
Why IPv6 goes around the proxy
Three defaults stack up:
- Devices get IPv6 on their own. Routers send Router Advertisements carrying the network prefix (RFC 4861). Devices build a global IPv6 address from it (RFC 4862) and add the advertising router as an IPv6 default router, with no setup on your part. The same advertisements can also hand out IPv6 DNS servers (RFC 8106).
- IPv6 is preferred. In the default policy table of RFC 6724, IPv6 has precedence 40 and IPv4 35; the standard says applications will use IPv6 in preference to IPv4 when the two are equally suitable. Microsoft’s documentation states that Windows favors global IPv6 addresses over IPv4 by default.
- IPv6 gets a head start. RFC 8305 (Happy Eyeballs v2) sends the AAAA query first and, if the IPv4 answer arrives first, recommends waiting 50 ms for the IPv6 one. It then tries IPv6 first and recommends starting the IPv4 attempt about 250 ms later. If your home IPv6 connects within that window, IPv6 wins.
The proxy is where it goes wrong. RFC 7359 describes exactly this for VPNs: many only support IPv4, so they install an IPv4 default route that sends all IPv4 traffic into the tunnel, while packets to IPv6 addresses still go out through the local IPv6 router and the VPN does nothing about them. A proxy app’s TUN mode works the same way, with a virtual adapter and routes that pull traffic in; in the TUN documentation of the open-source proxy core mihomo, for example, IPv4 and IPv6 routes are configured separately. Take over only IPv4 and you get the same leak.
System proxy mode is different. The browser hands the proxy a “host:port” with the CONNECT method and the proxy makes the connection (RFC 9110), so your device’s IPv6 preference doesn’t apply to those requests. Programs that ignore the system proxy, and requests your rules send direct, are still connected by your device itself and prefer IPv6 like anything else.
There is one more case: IPv6 really does go through the proxy, but the proxy side’s IPv6 exit sits in a different region from its IPv4 exit. The check only sees the result and flags both; the region and network type of the IPv6 exit tell you whether it is your home line or another route.
Which AI sites have IPv6 addresses
A site is reachable over IPv6 if its domain has an AAAA record. We queried Cloudflare’s and Google’s public DNS on 1 October 2026 (Beijing time), and both agreed on which names have one:
- ChatGPT / OpenAI:
chatgpt.com,chat.openai.com,auth.openai.comandapi.openai.comhave AAAA records. The bareopenai.comis IPv4-only;www.openai.comhas IPv6. - Claude / Anthropic:
claude.ai,claude.com,platform.claude.com,api.anthropic.comandanthropic.comall do. - Gemini:
gemini.google.com,aistudio.google.comand the sign-in domainaccounts.google.comall do. - Muse:
muse.aidoes.
Every one of these also has IPv4 addresses, so the choice is made on your side. Cloudflare’s documentation says it generates AAAA records for proxied domains by default, that only Enterprise customers can turn this off, and that client software decides between IPv4 and IPv6 when both exist. ipjudge.org has AAAA records too, so the IP that opened this site can also be an IPv6 address. DNS records change, so trust what you see when you look. One catch: with a proxy running, a local AAAA lookup may be answered by the proxy app; mihomo’s DNS documentation says that with ipv6 set to false in its DNS section, AAAA queries get empty answers.
How IP Judge tests for it
The check runs on the home page and on the Claude, ChatGPT, Gemini and Muse pages, in the “IPv4 exit” and “IPv6 exit” rows of “Browser and connection checks”:
- Your browser fetches
https://1.1.1.1/cdn-cgi/traceandhttps://[2606:4700:4700::1111]/cdn-cgi/trace. Both are official addresses of Cloudflare’s public resolver; the first can only be reached over IPv4 and the second only over IPv6, so the browser has no choice to make. /cdn-cgi/traceis a troubleshooting endpoint Cloudflare lists. It returns plain text in whichip=is the visitor IP it saw andloc=the matching country or region code. Each request gets up to 8 seconds.- The two
locvalues are compared. It compares regions, not IPs, since an IPv4 and an IPv6 address are never the same.
What you’ll see:
- Different regions: the IPv6 row turns amber with “Different route” and notes that it is in a different region from your IPv4 exit. The issue is added to “How to fix”.
- Same region: both rows say “Consistent”. No IPv6 answer within 8 seconds: “Not detected”. Either there is no IPv6, or the probe was blocked; neither is a problem by itself.
- The IPv6 exit gets its own card under “Who sees which of your IPs”: red “Region not supported” if it is in mainland China, Hong Kong or Macau, amber “Different exit” elsewhere. The WebRTC check compares against it as well.
- The “IP used for Claude” and “IP used for ChatGPT” rows are read by requesting claude.ai and chatgpt.com directly, and the browser picks IPv4 or IPv6 on its own. An address with colons there means your browser reached that site over IPv6, and that is the address the site sees. Gemini offers no way to read the IP it sees, so rely on the IPv6 row for it.
In the Claude environment score, IPv4 and IPv6 in the same region is worth 4 of the 15 points under Consistency; the Muse sign-up score doesn’t use it. These are IP Judge’s own weights, not published platform rules — see the Method page.
How to fix it
The goal is for IPv6 connections to leave through the same exit as IPv4, or not to use IPv6 at all. RFC 7359 puts it in that order too: if the software handles IPv6, send IPv6 traffic into the tunnel as well; if it can’t, disable IPv6 on all interfaces, which it calls a temporary workaround.
1. Have the proxy take over IPv6 (preferred)
- Use TUN mode and turn on the app’s IPv6 options. In mihomo, the top-level
ipv6setting controls whether IPv6 traffic is accepted and defaults to true (general settings). The TUN optioninet6-addressgives the virtual adapter an IPv6 address; it needs top-levelipv6set to true, and the program checks the other interfaces for IPv6 at startup and disables the feature if there is none (TUN documentation). After moving from an IPv4-only network to a dual-stack one, restart the proxy app before you test. - Once the proxy takes IPv6, the line still has to forward it. If it can’t, make sure IPv6 connections are dropped rather than sent direct; a dropped attempt makes the browser fall back to IPv4 under Happy Eyeballs, just a little slower.
2. Stop the proxy’s DNS from returning IPv6 addresses
That is what the mihomo DNS option above does: with no IPv6 address to connect to, programs use IPv4. It only covers lookups that go through the proxy’s DNS. Connections to literal IPv6 addresses (including IP Judge’s IPv6 probe) are unaffected, and IPv6 DNS servers from your router or the browser’s own secure DNS can still return AAAA records if they bypass the proxy. The DNS side is covered in DNS leaks.
3. Turn IPv6 off on the device, or prefer IPv4
Mac: per Apple’s support guide, choose Apple menu > System Settings, click Network in the sidebar, click a network service, click Details, then click TCP/IP, and set Configure IPv6 to Link-local only, which Apple describes as limiting IPv6 traffic to the local network. Change it for every network service you use, such as Wi-Fi and Ethernet.
Windows: Microsoft’s guidance advises against disabling IPv6 or unbinding it from adapters, since some Windows components might not function, and recommends “Prefer IPv4 over IPv6” instead. In an administrator Command Prompt, set the DisabledComponents registry value to 32 (hex 0x20), then restart:
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 32 /f
Preferring IPv4 only changes the order; the IPv6 path is still there. If IPv4 is slow to connect, Happy Eyeballs can still switch to IPv6, and addresses that are IPv6-only still use it. Afterwards, check that the “IP used for Claude” and “IP used for ChatGPT” rows show your proxy exit.
Phones: we found no Apple documentation of a way to turn IPv6 off on iPhone. On Wi-Fi you can deal with it at the router or enable IPv6 in your proxy app; on mobile data the router setting doesn’t apply.
4. Turn IPv6 off on the router
If the router stops advertising a prefix, devices on your network can’t form a global IPv6 address (RFC 4862). That covers devices you can’t configure individually, such as TVs and phones, and also means every device is affected. Where the setting lives depends on the router, so check its manual.
Then re-run the check on the home page: the IPv6 row should read “Consistent” or “Not detected”, and the Claude and ChatGPT rows should show your proxy exit. Page traffic, DNS and WebRTC should agree as well; see WebRTC leaks.
FAQ
My IPv6 exit is in the same country as my IPv4 exit. Am I fine?
The check will say “Consistent”, but the same region doesn’t prove the traffic went through the proxy. If you live in the US and your proxy exits in the US, IPv6 going around the proxy still looks consistent. Open the type link after the IPv6 address to see which network it belongs to: if it is your home ISP, IPv6 is still going out locally.
The IPv6 row says “Not detected”. Do I need to do anything?
No. The IPv6-only probe got no answer within 8 seconds, either because the network has no IPv6 or because the proxy blocked it. Either way, this run didn’t see a second exit.
I set Windows to prefer IPv4. Why is the IPv6 row still amber?
The probe goes to an IPv6 address directly, so there is no IPv4 option to prefer. As long as your local IPv6 works, it shows your local exit. Preferring IPv4 matters for sites that have both kinds of address; judge it by the Claude and ChatGPT rows.
Will turning IPv6 off break anything?
The AI sites listed above all have IPv4 addresses today, so they keep working. On Windows, Microsoft recommends preferring IPv4 over disabling IPv6, and RFC 7359 treats disabling it as a stopgap. Having the proxy handle IPv6 properly is the better long-term fix.
Will ChatGPT or Claude ban me for a mismatched IPv6 exit?
No public source answers that. What is certain: when your browser reaches claude.ai over IPv6, that IPv6 address is what Claude sees, not your proxy exit. For which IP each platform sees and where it is, read Which IP do ChatGPT and Claude actually see?
Which kind of IP do you have?
Check my IP for free