If KuaiLian VPN may leak IPv6, run IPv6 tests while connected; if ISP v6 remains, temporarily disable IPv6 on device/router for A/B tests and check in-app anti-leak/disable-IPv6 toggles plus split-tunnel rules.
DNS tests looked clean but IPv6 sites still showed carrier v6 ranges—the tunnel carried IPv4 only. Disabling system IPv6 made behavior match VPN egress. Don't merge DNS and IPv6 tool results.
Resolver issues → DNS leak guide. Split rules → split tunnel.
How to test
- While connected, use reputable IPv6 test pages.
- Compare VPN off, VPN on, VPN on + system IPv6 off.
- Test Wi-Fi and cellular separately.
Mitigation paths
- In-app disable IPv6 / anti-leak toggles if present.
- Temporarily disable IPv6 on the device adapter for A/B tests.
- Router-level IPv6 off affects whole LAN—use carefully.
- Split tunnel direct v6 domains can mimic leaks—review rules.