ZunavekZunavek

Diagnostic methodology

Updated October 8, 2026 · Published by Zunavek

A diagnostic result describes what this browser, network path, or public service revealed at the time of the check. It cannot establish every property of a VPN, device, website, or mail system. Failed requests and missing data are coverage limits; they are not proof of a security failure.

IP and network information

HTTP requests reveal the public address used to reach the service. IP geolocation and ASN data come from lookup datasets and public registration services. Geolocation is approximate, particularly for VPNs, mobile networks and anycast DNS addresses. A network's registered country is not proof of a device's location or a company's headquarters.

ASN profiles show GeoIP dataset ranges, not a live BGP announcement table. Peer counts, network classifications and reputation are unavailable when no supporting evidence is present. Risk labels are dataset-based indicators and can be incomplete or stale.

Browser and connection fingerprints

Browser collectors inspect signals such as canvas output, WebGL, fonts, audio and device settings. TLS and TCP observations describe the connection that reaches our service and may reflect an intermediary. Matching a fingerprint or displaying a score does not prove identity, tracking, automation, or uniqueness across the whole internet.

WebRTC and DNS observations

WebRTC gathers ICE candidates using STUN. A public candidate matching your HTTP address is ordinary address exposure, not evidence that a VPN was bypassed. A different address merits investigation but may reflect dual-stack routing or a relay. Proving a VPN bypass requires knowing the expected VPN addresses and the direct connection's address. A blocked or unsupported test cannot establish safety.

DNS tests identify resolvers used for generated lookup requests. Resolver ownership helps interpret the path, but a cloud provider or unfamiliar resolver does not by itself prove a leak or protection. Compare results with your browser, operating system and VPN DNS configuration.

Forwarded headers observed by the server may be inserted by our CDN or reverse proxy. Their presence alone does not establish that your browser or VPN disclosed extra information.

Email and domain checks

The Email Security Checker inspects public DNS policies and guarded HTTPS policy endpoints. It cannot prove message alignment, SMTP acceptance, report receipt, or inbox placement. DKIM selectors are not enumerable from a domain: an unknown selector is a coverage limit. The Email Header Analyzer interprets submitted headers; authentication claims are trustworthy only when they originate from a mail server you trust.

Domain Security examines public HTTPS, certificate, DNS, routing, registration and disclosure signals. It does not exploit vulnerabilities, authenticate into private applications, or certify compliance.

Scores, examples and updates

Scores summarize implemented checks and their weights; they are not an independent security standard. Read individual findings and unavailable evidence before acting on a grade. Examples illustrate a mechanism unless test conditions and actual measurements are supplied. Guide updates should cite primary sources and state the relevant browser or provider version when behavior depends on it.

Primary references

See our privacy policy before running a scan. For corrections, contact [email protected].