Follow the connection, one part at a time
Without a consumer VPN, your device connects through a local network and internet provider toward the destination. With a VPN enabled, selected traffic travels through an encrypted tunnel to the VPN server before continuing toward the destination.
The tunnel has endpoints. It is not an invisible protective layer around every possible activity. The VPN provider is part of the path, and the destination still receives the traffic needed to provide its service.
HTTPS is a separate protection between a client and a website. When used correctly, it protects the content of that connection even beyond the VPN server. A VPN does not make a plain HTTP destination equivalent to an HTTPS one.
The Electronic Frontier Foundation’s VPN guidance emphasizes the trust decision involved in choosing a provider. A useful purchase begins with understanding that change of trust.
What different observers may still learn
| Observer | What a VPN can change | What it does not automatically remove |
|---|---|---|
| Local network or internet provider | The route and visibility of traffic carried inside the tunnel. | The fact that you are online, traffic timing and a connection to a VPN endpoint. |
| VPN provider | It becomes an intermediary for routed traffic. | The need to trust its policies, implementation and operations. |
| Destination website | It may see the VPN exit address instead of your usual public address. | Account identity, cookies and information you submit. |
| Someone controlling your device | Network routing may change. | Their access to local files, keystrokes, screenshots or application data. |
Visibility depends on the protocols, configuration and observer. Avoid absolute claims such as “nobody can see anything.” The more precise question is which information is protected from which party in the situation you care about.
A VPN can be useful without being complete anonymity. Many security tools protect one layer well while leaving other layers to different controls.
Public Wi-Fi: useful caution without the scare story
A public network can be untrusted, but modern HTTPS already protects much ordinary web content in transit. A VPN can add a consistent encrypted route through that local network for the traffic it carries. It does not eliminate every risk of using an unfamiliar network.
Connect to the legitimate network, keep sharing services restricted and avoid ignoring certificate warnings. If a captive portal is required, understand that you may need to complete its login before the VPN can establish a connection.
Keep the operating system and browser supported and updated. A VPN is not a repair for a vulnerable device. For particularly important activity, consider whether you can use a trusted connection instead of relying on a complicated setup on an unknown network.
Test the VPN before travelling. Download the app, verify account access and understand the reconnect behavior while you still have a familiar network and time to troubleshoot.
A changed IP is not a changed identity
If you log into an account, that service can usually associate the session with the account regardless of which IP address it sees. Cookies, browser characteristics and information you voluntarily provide can also connect activity.
Changing the IP can still be useful for reducing exposure of the usual network address to a destination. It is simply a narrower outcome than erasing identity. A VPN should not be marketed as a way to make every action untraceable.
A private browsing window addresses another limited set of local-browser behaviors. It does not turn a VPN into anonymity, and the VPN does not make a private window immune to account identification.
Before choosing a service, write the concern in one sentence: “I want traffic carried through an encrypted tunnel on unfamiliar networks” is actionable. “I want complete privacy from everyone” is too broad for one product to satisfy.
Understand kill switches, DNS and split tunneling
A kill switch is intended to prevent certain traffic from taking a direct route when the VPN is unavailable. Its behavior depends on the app, platform and settings. Unexpected disconnection, manual app exit and system startup are distinct situations.
DNS turns names into network destinations. If your requirement includes routing DNS through the VPN, verify the actual setup. An encrypted DNS resolver outside the tunnel and a provider-operated resolver inside it have different trust implications; a test result needs context.
Split tunneling intentionally creates exceptions. It can help a local service or incompatible application, but those exceptions should be understood and limited. A browser extension typically has a narrower scope than a device-wide app.
Use the setup and checking guide to establish a baseline. No browser check can prove that every background process and every future failure state behaves correctly.
Read privacy evidence with the right questions
Start with the current privacy policy, service terms and identity of the operating company. Identify the data categories discussed, retention statements, payment and support handling and any exceptions. A headline about “no logs” may refer to browsing activity while account records still exist.
If the provider points to an audit, look for the actual report or a meaningful public scope. Note the date, systems, app versions and limitations. An audit is evidence about what was examined, not a guarantee that every future configuration or business practice is covered.
Open-source software can enable inspection, but public code alone does not establish production behavior. Likewise, a jurisdiction label does not answer every question about processing locations or legal exposure.
Our provider reviews identify when our evidence is limited. We have not independently audited the VPNs we cover and do not manufacture privacy scores to make a table look complete.
Use the right tool for the other risks
| Concern | A more relevant additional control |
|---|---|
| Account takeover | Unique passwords, multifactor authentication and protected recovery methods. |
| Phishing | Careful verification of the destination and requests for sensitive information. |
| Malicious downloads | Supported software, appropriate device protection and cautious installation. |
| Lost files | Independent backups and tested recovery. |
| Employee access to business systems | Organizational identity, permissions and offboarding controls. |
These controls complement a VPN rather than compete with it. Choose a security bundle only if its components meet your actual needs and work on the intended devices. More product labels do not automatically create more useful protection.
Choose a provider from a realistic requirement
Use our VPN shortlist to compare the five services covered at launch. Proton VPN offers a Free route for one-device evaluation; NordVPN is a candidate for an everyday multi-device setup; PIA is relevant when simultaneous device count matters.
Those are conditional starting points, not universal privacy rankings. Check operating-system support, the current terms and the evidence relevant to your threat model. Test normal use early and avoid making a long commitment based on an absolute anonymity claim.
If the requirement involves serious personal risk, a consumer comparison article is only a starting point. The decision needs a threat model and technical guidance specific to the circumstances.
Frequently asked questions
Can my internet provider see that I use a VPN?
It can generally observe that your device connects to a VPN endpoint, along with traffic timing and volume. The visibility of content and destinations depends on the protocols and configuration.
Does a VPN replace HTTPS?
No. They protect different parts of the connection. Continue to use HTTPS and take certificate warnings seriously.
Can websites identify me while the VPN is on?
Yes. A logged-in account, cookies and other identifiers can still identify a session. A different public IP is not complete anonymity.
Sources & editorial notes
Sources checked on September 6, 2026. Product details can change by country, platform and billing term. Prices shown are snapshots, not live quotes.
- EFF: VPN trust and limitations
- Proton VPN: documented protection features
- PIA: kill-switch and routing behavior
This guide combines published documentation with our editorial analysis. We have not measured provider performance or conducted an independent security audit. Read our methodology. Report a correction.

