IP Judge ipjudge.org

Guides ·

IPv6 leaks: why your IPv6 exit is in a different region

If your home connection gives your devices both an IPv4 and an IPv6 address, you are on a dual-stack network. When a site also has both kinds of address, your device picks one path for every connection. If your proxy only takes over IPv4 and the system follows its default of preferring IPv6, those connections never touch the proxy: they leave through your home line, and the site sees your ISP’s IPv6 address. That is an IPv6 leak, and IP Judge reports it as an IPv6 exit in a different region from your IPv4 exit. As of 1 October 2026, the domains of ChatGPT, Claude, Gemini and Muse all have IPv6 addresses, so this is not an edge case.

At a glance: how IPv6 skips the proxyWhen the proxy only handles IPv4, IPv4 connections go through it and sites see the proxy exit. If a site also has an IPv6 address, the system tries IPv6 first, and that connection leaves through your home connection without touching the proxy. At a glance: how IPv6 skips the proxy IPv4 connections Proxied Browser Proxy app Proxy IPv4 Sites see the proxy exit IPv6 connections Skip the proxy Browser No proxy Home IPv6 Tried first when the site has an IPv6 address Typical when the proxy handles only IPv4.
One browser, two ways out. If the proxy only takes IPv4, IPv6 connections leave straight through your home line and sites see a different address.

Why IPv6 goes around the proxy

Three defaults stack up:

  1. Devices get IPv6 on their own. Routers send Router Advertisements carrying the network prefix (RFC 4861). Devices build a global IPv6 address from it (RFC 4862) and add the advertising router as an IPv6 default router, with no setup on your part. The same advertisements can also hand out IPv6 DNS servers (RFC 8106).
  2. IPv6 is preferred. In the default policy table of RFC 6724, IPv6 has precedence 40 and IPv4 35; the standard says applications will use IPv6 in preference to IPv4 when the two are equally suitable. Microsoft’s documentation states that Windows favors global IPv6 addresses over IPv4 by default.
  3. IPv6 gets a head start. RFC 8305 (Happy Eyeballs v2) sends the AAAA query first and, if the IPv4 answer arrives first, recommends waiting 50 ms for the IPv6 one. It then tries IPv6 first and recommends starting the IPv4 attempt about 250 ms later. If your home IPv6 connects within that window, IPv6 wins.
When does a connection use IPv6?A connection uses IPv6 only when three things hold: the device has a global IPv6 address, the site has an AAAA record, and IPv6 connects first. If any of them fails it uses IPv4. With a proxy that only handles IPv4, the IPv6 connection bypasses it. When does a connection use IPv6? ① Device has global IPv6 The router advertised a prefix No IPv4 Yes ② Site has an AAAA record All four AI sites do today No IPv4 Yes ③ IPv6 connects first IPv6 starts; IPv4 ~250 ms later No IPv4 Yes IPv6 Bypasses an IPv4-only proxy Defaults per RFC 6724 and RFC 8305; systems vary.
IPv6 is used only when all three hold. The site controls the second; you control whether the device has IPv6, which family it tries first, and whether the proxy takes IPv6.

The proxy is where it goes wrong. RFC 7359 describes exactly this for VPNs: many only support IPv4, so they install an IPv4 default route that sends all IPv4 traffic into the tunnel, while packets to IPv6 addresses still go out through the local IPv6 router and the VPN does nothing about them. A proxy app’s TUN mode works the same way, with a virtual adapter and routes that pull traffic in; in the TUN documentation of the open-source proxy core mihomo, for example, IPv4 and IPv6 routes are configured separately. Take over only IPv4 and you get the same leak.

System proxy mode is different. The browser hands the proxy a “host:port” with the CONNECT method and the proxy makes the connection (RFC 9110), so your device’s IPv6 preference doesn’t apply to those requests. Programs that ignore the system proxy, and requests your rules send direct, are still connected by your device itself and prefer IPv6 like anything else.

There is one more case: IPv6 really does go through the proxy, but the proxy side’s IPv6 exit sits in a different region from its IPv4 exit. The check only sees the result and flags both; the region and network type of the IPv6 exit tell you whether it is your home line or another route.

Which AI sites have IPv6 addresses

A site is reachable over IPv6 if its domain has an AAAA record. We queried Cloudflare’s and Google’s public DNS on 1 October 2026 (Beijing time), and both agreed on which names have one:

  • ChatGPT / OpenAI: chatgpt.com, chat.openai.com, auth.openai.com and api.openai.com have AAAA records. The bare openai.com is IPv4-only; www.openai.com has IPv6.
  • Claude / Anthropic: claude.ai, claude.com, platform.claude.com, api.anthropic.com and anthropic.com all do.
  • Gemini: gemini.google.com, aistudio.google.com and the sign-in domain accounts.google.com all do.
  • Muse: muse.ai does.

Every one of these also has IPv4 addresses, so the choice is made on your side. Cloudflare’s documentation says it generates AAAA records for proxied domains by default, that only Enterprise customers can turn this off, and that client software decides between IPv4 and IPv6 when both exist. ipjudge.org has AAAA records too, so the IP that opened this site can also be an IPv6 address. DNS records change, so trust what you see when you look. One catch: with a proxy running, a local AAAA lookup may be answered by the proxy app; mihomo’s DNS documentation says that with ipv6 set to false in its DNS section, AAAA queries get empty answers.

How IP Judge tests for it

The check runs on the home page and on the Claude, ChatGPT, Gemini and Muse pages, in the “IPv4 exit” and “IPv6 exit” rows of “Browser and connection checks”:

  1. Your browser fetches https://1.1.1.1/cdn-cgi/trace and https://[2606:4700:4700::1111]/cdn-cgi/trace. Both are official addresses of Cloudflare’s public resolver; the first can only be reached over IPv4 and the second only over IPv6, so the browser has no choice to make.
  2. /cdn-cgi/trace is a troubleshooting endpoint Cloudflare lists. It returns plain text in which ip= is the visitor IP it saw and loc= the matching country or region code. Each request gets up to 8 seconds.
  3. The two loc values are compared. It compares regions, not IPs, since an IPv4 and an IPv6 address are never the same.
How IP Judge reads your IPv6 exitThe check contacts 1.1.1.1, reachable only over IPv4, and 2606:4700:4700::1111, reachable only over IPv6, and reads the region code each one reports. Same region is green “Consistent”, different region is amber “Different route”, and no IPv6 reply within 8 seconds shows “Not detected”. How IP Judge reads your IPv6 exit IPv4 only1.1.1.1 IPv6 only2606:4700:4700::1111 Compare the two region codes (loc) Same regionBoth rows green Consistent Different regionListed under How to fix; −4 in the Claude score Different route No IPv6 reply in 8 sNo IPv6, or it was blocked: not a problem Not detected Regions are compared, not IPs: v4 and v6 always differ.
Both addresses belong to Cloudflare’s 1.1.1.1 service, one reachable only over IPv4 and one only over IPv6, so each reveals one of your exits.

What you’ll see:

  • Different regions: the IPv6 row turns amber with “Different route” and notes that it is in a different region from your IPv4 exit. The issue is added to “How to fix”.
  • Same region: both rows say “Consistent”. No IPv6 answer within 8 seconds: “Not detected”. Either there is no IPv6, or the probe was blocked; neither is a problem by itself.
  • The IPv6 exit gets its own card under “Who sees which of your IPs”: red “Region not supported” if it is in mainland China, Hong Kong or Macau, amber “Different exit” elsewhere. The WebRTC check compares against it as well.
  • The “IP used for Claude” and “IP used for ChatGPT” rows are read by requesting claude.ai and chatgpt.com directly, and the browser picks IPv4 or IPv6 on its own. An address with colons there means your browser reached that site over IPv6, and that is the address the site sees. Gemini offers no way to read the IP it sees, so rely on the IPv6 row for it.

In the Claude environment score, IPv4 and IPv6 in the same region is worth 4 of the 15 points under Consistency; the Muse sign-up score doesn’t use it. These are IP Judge’s own weights, not published platform rules — see the Method page.

How to fix it

The goal is for IPv6 connections to leave through the same exit as IPv4, or not to use IPv6 at all. RFC 7359 puts it in that order too: if the software handles IPv6, send IPv6 traffic into the tunnel as well; if it can’t, disable IPv6 on all interfaces, which it calls a temporary workaround.

1. Have the proxy take over IPv6 (preferred)

  • Use TUN mode and turn on the app’s IPv6 options. In mihomo, the top-level ipv6 setting controls whether IPv6 traffic is accepted and defaults to true (general settings). The TUN option inet6-address gives the virtual adapter an IPv6 address; it needs top-level ipv6 set to true, and the program checks the other interfaces for IPv6 at startup and disables the feature if there is none (TUN documentation). After moving from an IPv4-only network to a dual-stack one, restart the proxy app before you test.
  • Once the proxy takes IPv6, the line still has to forward it. If it can’t, make sure IPv6 connections are dropped rather than sent direct; a dropped attempt makes the browser fall back to IPv4 under Happy Eyeballs, just a little slower.

2. Stop the proxy’s DNS from returning IPv6 addresses

That is what the mihomo DNS option above does: with no IPv6 address to connect to, programs use IPv4. It only covers lookups that go through the proxy’s DNS. Connections to literal IPv6 addresses (including IP Judge’s IPv6 probe) are unaffected, and IPv6 DNS servers from your router or the browser’s own secure DNS can still return AAAA records if they bypass the proxy. The DNS side is covered in DNS leaks.

3. Turn IPv6 off on the device, or prefer IPv4

Mac: per Apple’s support guide, choose Apple menu > System Settings, click Network in the sidebar, click a network service, click Details, then click TCP/IP, and set Configure IPv6 to Link-local only, which Apple describes as limiting IPv6 traffic to the local network. Change it for every network service you use, such as Wi-Fi and Ethernet.

Windows: Microsoft’s guidance advises against disabling IPv6 or unbinding it from adapters, since some Windows components might not function, and recommends “Prefer IPv4 over IPv6” instead. In an administrator Command Prompt, set the DisabledComponents registry value to 32 (hex 0x20), then restart:

reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters" /v DisabledComponents /t REG_DWORD /d 32 /f

Preferring IPv4 only changes the order; the IPv6 path is still there. If IPv4 is slow to connect, Happy Eyeballs can still switch to IPv6, and addresses that are IPv6-only still use it. Afterwards, check that the “IP used for Claude” and “IP used for ChatGPT” rows show your proxy exit.

Phones: we found no Apple documentation of a way to turn IPv6 off on iPhone. On Wi-Fi you can deal with it at the router or enable IPv6 in your proxy app; on mobile data the router setting doesn’t apply.

4. Turn IPv6 off on the router

If the router stops advertising a prefix, devices on your network can’t form a global IPv6 address (RFC 4862). That covers devices you can’t configure individually, such as TVs and phones, and also means every device is affected. Where the setting lives depends on the router, so check its manual.

Then re-run the check on the home page: the IPv6 row should read “Consistent” or “Not detected”, and the Claude and ChatGPT rows should show your proxy exit. Page traffic, DNS and WebRTC should agree as well; see WebRTC leaks.

FAQ

My IPv6 exit is in the same country as my IPv4 exit. Am I fine?

The check will say “Consistent”, but the same region doesn’t prove the traffic went through the proxy. If you live in the US and your proxy exits in the US, IPv6 going around the proxy still looks consistent. Open the type link after the IPv6 address to see which network it belongs to: if it is your home ISP, IPv6 is still going out locally.

The IPv6 row says “Not detected”. Do I need to do anything?

No. The IPv6-only probe got no answer within 8 seconds, either because the network has no IPv6 or because the proxy blocked it. Either way, this run didn’t see a second exit.

I set Windows to prefer IPv4. Why is the IPv6 row still amber?

The probe goes to an IPv6 address directly, so there is no IPv4 option to prefer. As long as your local IPv6 works, it shows your local exit. Preferring IPv4 matters for sites that have both kinds of address; judge it by the Claude and ChatGPT rows.

Will turning IPv6 off break anything?

The AI sites listed above all have IPv4 addresses today, so they keep working. On Windows, Microsoft recommends preferring IPv4 over disabling IPv6, and RFC 7359 treats disabling it as a stopgap. Having the proxy handle IPv6 properly is the better long-term fix.

Will ChatGPT or Claude ban me for a mismatched IPv6 exit?

No public source answers that. What is certain: when your browser reaches claude.ai over IPv6, that IPv6 address is what Claude sees, not your proxy exit. For which IP each platform sees and where it is, read Which IP do ChatGPT and Claude actually see?

Which kind of IP do you have?

Check my IP for free