New here? Answer six questions for a recommendation, or test the connection you are on.
Check what your connection is actually doing.
WebRTC, DNS, IPv6 and clock leaks.
What a site learns from your address.
What a tunnel does not change about you.
Latency, jitter and throughput to our endpoint.
Six questions, one recommendation, its limits.
Set one up properly.
Server and peer files, keys made in-browser.
Split tunnelling, returned as minimal CIDRs.
Per-packet overhead, MTU to set, MSS clamp.
Six protocols: ciphers, roaming, visibility.
Know what is happening out there.
Providers ranked on OONI measurements.
Exploited appliance flaws, ordered by EPSS.
Paste wg0.conf or client.ovpn and get it graded.
Real handshakes at a host you name.
Counts and dates come from the source named; thresholds, grades and wording are ours, with the rule shown on each page.
Every answer is computed or measured: names resolved through a listener we control, real OONI measurements from inside the country, keys generated in your browser and never sent. Where a check cannot prove something the page says so, a small sample as insufficient, a filtered probe as inconclusive, and a score always shows its count.
No page can confirm a no-logs claim, a safe jurisdiction, or a tunnel unbreakable by a state adversary. Those are not observable from outside. We observe reachability, leakage, timing, packet overhead, published vulnerabilities and what a host answers.