Clearnet leakage is the highest severity hidden service vulnerability. It occurs when the application or server makes outbound requests to clearnet addresses, revealing the server IP to the request destination. Test for this with the following method:
Set up a simple HTTPS logging server on a clearnet IP you control. Configure it to log all incoming requests including source IP. From the hidden service application, trigger every feature that might make external requests: user avatar loading, external link previews, email validation via MX lookup, third-party authentication callbacks, CDN-hosted resources, and update checks. If any requests appear in your logging server from an IP that is not a Tor exit node, you have clearnet leakage.
Confirm iptables rules are blocking outbound clearnet traffic from all non-tor processes: iptables -L OUTPUT -v -n. The rule allowing outbound traffic only for uid debian-tor should be visible. Test by attempting an outbound connection from the application user: sudo -u www-data curl http://1.1.1.1. This should fail with connection refused or permission denied.