The icon in the app is lit, but that's not yet proof that traffic is going through the tunnel. Below are four checks, from the simplest to the most revealing.
The short answer
The minimal check is to compare your IP address before and after connecting. The full check is to make sure DNS queries aren't leaking past the VPN and that the services you need actually open.
Check 1. IP address
The quickest one. Open a «My IP» page before connecting and note the address and country. Connect the VPN and refresh the page. The address and country should change to those matching the location you selected.
If the address hasn't changed, traffic is bypassing the tunnel. The causes: the client shows «connected» but the connection isn't established; a second VPN profile is active in the system; the browser is serving the page from cache — reload ignoring the cache.
Check 2. DNS leak
Subtler and more important. DNS is the service that turns a site name into an address. If queries go directly to your ISP's servers, bypassing the tunnel, then your IP address is swapped but your ISP still sees the list of domains you requested.
You check this on sites that show which DNS servers are being used. With a properly working VPN there shouldn't be any of your home ISP's servers there. If they appear, that's a DNS leak, and a swapped IP doesn't make up for it.
Check 3. WebRTC
WebRTC is a browser mechanism for calls and video. To connect directly, it determines the device's real addresses and can hand them to a page, bypassing the VPN.
Test it on your own device
8 hours free, no card required. Full access to all servers.
You check this with specialized WebRTC-testing pages. If your home address is visible there while the VPN is on, there's a leak. It's fixed by disabling WebRTC in the browser settings or with an extension; note that after this, calls in the browser will stop working.
Check 4. Actual access
The most practical one. Open the service you turned the VPN on for. If it works, the goal is achieved, no matter what the tests show.
The reverse also happens: the IP changed, there are no leaks, but a particular site won't open. That means the site restricts access specifically from data-center addresses. Changing the location helps.
What these checks don't show
- They don't check whether the service keeps logs: that's a matter of policy and jurisdiction, not a network test.
- They don't make you anonymous: if you're logged in to an account, the service knows who you are with any IP.
- They don't test the strength of the encryption — only the fact that traffic goes through the tunnel.
If a check fails
- Change the location in the app.
- Check the system VPN settings — a second active profile is intercepting traffic.
- Restart the app completely, not just minimizing it.
- Reload the check page ignoring the cache.
- Restart the device if the routes are «stuck».