Learned this one the hard way and it seems worth sharing since it comes up a lot.
Your VPN hiding your IP address, and your VPN hiding which websites you look up, are actually two separate things. A lot of apps only reliably do the first one unless you dig into settings.
Basically: before your VPN can protect anything, your device first has to "ask" what the actual address is for the site you're going to. That ask-and-answer step happens outside the VPN's protection unless it's specifically set up to cover it too. So your traffic looks hidden, but the list of every site you've looked up can still land on your regular internet provider.
Quick way to check: turn your VPN on, then run a DNS and WebRTC leak check. If your own internet provider's name shows up in there, you've got a leak, no matter what your IP looks like.
What fixed it for me: there was a "leak protection" switch buried in my VPN app's settings that just wasn't on by default, plus a hidden Windows setting that was quietly causing the same issue.
Anyone else run into this a different way?
Source: r/peekmyipcom · by /u/Low_Inside_6527