← Back to Blog

WebRTC and DNS Leaks: 7 Profile Checks Before Your First Account Login

We analyze how WebRTC and DNS leaks reveal the real IP in anti-detect browsers and provide a checklist of 7 checks before the first login to a new account.

📅October 1, 2026

One unnoticed WebRTC or DNS leak can nullify months of account farming with a single login. Platforms like Facebook, TikTok, and Instagram have long learned to match the "declared" proxy IP with the real IP that leaks through the browser. In this article, we provide a specific checklist of 7 checks to perform before the first opening of a new profile, rather than after a ban.

What are WebRTC and DNS leaks and why do they kill a profile?

When you launch a profile in an anti-detect browser and connect a proxy, you expect the site to see only the proxy IP. In practice, the browser simultaneously uses two mechanisms that can reveal your real IP: WebRTC (a technology for video calls and P2P connections) and DNS requests (the conversion of domain names to IP addresses). If these channels are not masked, the platform receives two different addresses for one profile — this is a classic trigger for the fraud systems of Facebook, TikTok, or Instagram.

For an arbitrageur, this means an instant ban of the advertising account even before launching the campaign. For an SMM specialist managing 20-30 client accounts, this poses a risk of mass blocking of several profiles if they use one real IP through a leak. For a seller scraping Wildberries or Ozon through multiple accounts, a DNS leak can lead to all "anonymous" requests being tied to one real address and quick blocking due to geography.

The main problem is that the leak is not visible to the naked eye — the profile opens normally, ads run, and the feed loads. The problem surfaces after a few hours or days when the platform's algorithm accumulates statistics and matches IP addresses between different profiles. That’s why checking should be part of the routine before the first login, not a reaction to an already occurred ban.

How WebRTC reveals your real IP

WebRTC (Web Real-Time Communication) is a built-in browser protocol for direct exchange of audio, video, and data between devices without server involvement. To establish such a connection, the browser must discover the real public and local IP address of the device through the ICE (Interactive Connectivity Establishment) mechanism. It does this regardless of which proxy is configured in the system or browser because WebRTC operates at the network stack level, not the HTTP traffic level.

In practice, it looks like this: you log into Facebook through a residential proxy with an IP from Germany, but a script on the page via WebRTC retrieves your home or work IP from Russia. Facebook records both addresses, compares geolocations, sees the mismatch, and marks the profile as suspicious. Even if a ban does not occur immediately, the account enters a heightened control mode — action limits decrease, and ad reach drops.

Regular browsers like Chrome and Firefox do not block this leak by default — you need to either disable WebRTC through flags or use an anti-detect browser with built-in protection. Dolphin Anty, AdsPower, Multilogin, GoLogin, and Octo Browser have a separate switch for WebRTC mode: you can completely disable the protocol, substitute the public IP with the proxy address, or leave only the local IP without the public one. For multi-accounting, the right choice is to substitute with the proxy IP rather than complete disabling, as complete disabling of WebRTC can itself become a detectable pattern.

How DNS requests expose your real location

A DNS leak occurs when the browser or operating system sends a request to convert a domain to an IP not through the proxy, but directly through the provider's DNS server. This is especially characteristic of SOCKS5 proxies, which do not always intercept DNS traffic by default, unlike HTTP(S) proxies with full tunneling. As a result, the site receives the proxy IP for HTTP requests, but the provider's DNS server "sees" your real region, and this information can be matched through third-party analytics scripts or anti-fraud systems.

For an arbitrageur launching ads through Facebook Ads or TikTok Ads from a specific GEO, a DNS leak means that the platform sees the provider from one country, while the IP address is from another. This is a direct signal of proxy usage, which often leads to additional verification or blocking of the campaign at the moderation stage. For an SMM agency managing client accounts from different cities, a DNS leak can reveal that all profiles are physically managed from one location, breaking the logic of "different people managing different accounts."

Checking for DNS leaks separately from WebRTC is critical because these are two different data transmission channels, and protection against one does not guarantee protection against the other. Many beginners only configure WebRTC substitution and believe the profile is secure, forgetting that a DNS request can bypass the proxy with incorrect network adapter settings or when using a system proxy instead of a proxy within the anti-detect browser.

7 checks before the first login to a profile

Below is the sequence of actions to perform for each new profile before logging into Facebook, Instagram, TikTok, or accessing Wildberries under a new account.

  1. Check the type of proxy and protocol. Ensure that SOCKS5 or HTTP(S) with full DNS tunneling support is used, not "bare" SOCKS without DNS proxy.
  2. Open a leak checking service before entering the platform. Go to browserleaks.com/webrtc and browserleaks.com/dns within the anti-detect browser profile — not in regular Chrome.
  3. Compare the public IP with the proxy IP. The address shown by the service in the WebRTC section should match your proxy IP, not your home or mobile IP.
  4. Check the list of DNS servers. In the DNS Leak Test section, all servers should belong to the country and provider of the proxy, not your real internet provider.
  5. Check geolocation by time zone and browser language. The time zone, system language, and geolocation in the anti-detect browser profile should match the country of the proxy IP — a mismatch is also read as a suspicious pattern, even though it does not formally constitute a WebRTC/DNS leak.
  6. Test the profile on whoer.net or ipleak.net. The second independent service provides a control check — if both services show the same clean result, the risk of leakage is minimal.
  7. Record the test result in the profile accounting table. For agencies and teams managing dozens of accounts, it is important to keep a log: date of the check, proxy IP, result of the WebRTC/DNS test. This saves hours when investigating mass bans.

Important

The check must be done specifically within the anti-detect profile, with an active proxy, and not in the main browser. A test passed in regular Chrome does not reflect the state of an isolated profile with substituted parameters.

Setting up protection in Dolphin Anty, AdsPower, Multilogin, GoLogin

In Dolphin Anty, the WebRTC setting is located in the profile creation section, under the "Proxy and WebRTC" tab. You need to select the "Altered" mode (substitute with proxy IP) instead of "Disabled" — this way the platform sees the agreed address, not the absence of the protocol altogether. After saving the profile, be sure to open it and run it through browserleaks.com before logging into the account.

In AdsPower, a similar option is called "WebRTC" on the Fingerprint tab when creating a profile — choose the "Replace" option with automatic substitution of the IP from the proxy. There is also a DNS block — it is recommended to enable "Use proxy DNS" so that DNS requests go through the same tunnel as HTTP traffic.

In Multilogin, WebRTC protection is built into the Mimic and Stealthfox engines and by default substitutes the public IP with the proxy address without manual configuration — but after linking a new proxy, it is advisable to update the profile and run the test again, as sometimes session recreation is required.

In GoLogin and Octo Browser, WebRTC settings are found in the profile fingerprint parameters (Fingerprint), under the Network section — choose the substitution mode based on the proxy, not complete blocking. Octo Browser additionally allows you to manually specify a DNS server corresponding to the proxy's country, which is useful when working with non-standard GEOs for TikTok Ads or Google Ads.

For all the listed browsers, the general principle is the same: first configure the proxy, then check that WebRTC and DNS are synchronized with this proxy, and only then open the desired platform. If you are working with residential proxies, the risk of geolocation mismatch is lower because the IP belongs to a real user in the desired country, and the DNS server is usually logically connected to that region.

Services for checking leaks

To monitor leaks, three to four trusted services are sufficient, which provide different levels of detail and allow cross-checking results.

Service What it checks When to use
browserleaks.com WebRTC, DNS, Canvas, browser fingerprint Main check for each new profile
ipleak.net IP, DNS server, and geolocation match Control check after the first one
whoer.net Anonymity, time zone, browser language, proxy flags Before launching advertising campaigns
dnsleaktest.com Detailed list of used DNS servers When suspecting a DNS leak with a specific proxy

The rule is simple: if at least one of the services shows a mismatch of IP or DNS server with the declared geolocation of the proxy, the profile cannot be used to log into the target account until the issue is resolved.

Common mistakes when setting up proxies and profiles

The first mistake is using the system proxy of the operating system instead of the proxy specified within the anti-detect browser. The system proxy is not applied to all processes, and part of the traffic, including DNS, may go directly through the provider.

The second mistake is trusting free public DNS without tying it to the country of the proxy. If the proxy is issued in Poland, and the DNS server is an American public resolver, this creates a logical mismatch that advanced anti-fraud systems of Facebook and TikTok detect.

The third mistake is reusing the same proxy for multiple profiles without rotation. Even with perfect WebRTC and DNS settings, if 10 accounts log in from one IP, the platform sees a cluster of related profiles and bans them in a chain at the first violation of one of them.

The fourth mistake is skipping the re-check after changing the proxy within an already existing profile. Many change the IP to "refresh" the account but forget to run the leak test again — WebRTC settings may have reset during the update of the anti-detect browser.

The fifth mistake is using datacenter proxies for tasks where similarity to a regular user is critical, such as for Instagram or TikTok. Platforms easily identify datacenter IPs by ASN ranges, and even with a clean WebRTC/DNS test, the account comes under increased scrutiny simply due to the nature of the IP.

Which type of proxy reduces the risk of leaks and bans

The choice of proxy type directly affects how noticeable discrepancies are even with a perfectly configured anti-detect browser.

Type of proxy Risk of detection by IP Suitable for
Residential proxies Low Facebook Ads, Instagram, TikTok, multi-accounting
Mobile proxies Minimal TikTok Ads, account warming, strict anti-fraud systems
Datacenter proxies High Scraping Wildberries, Ozon, tasks without strict verification

For advertising accounts and social networks, residential and mobile IPs reduce the very likelihood that the platform will start scrutinizing the profile, even if technically the WebRTC/DNS test has passed cleanly. For scraping marketplaces, where speed and volume of requests are important, datacenter proxies remain a working option provided that IP rotation is done regularly.

Conclusion

WebRTC and DNS leaks are not a theoretical threat, but a concrete reason for most "unexplained" bans immediately after the first login to a new profile. Checking against the 7-point checklist takes 3-5 minutes for each account but saves hours in recovering banned profiles and explaining to clients why ads or Instagram accounts have disappeared.

If you are managing multi-accounting in Facebook Ads, TikTok Ads, or handling client profiles on Instagram, we recommend combining proper WebRTC and DNS settings in Dolphin Anty, AdsPower, or Multilogin with quality residential proxies — this reduces the likelihood of mismatches that anti-fraud systems catch and makes each profile more stable from the first login.