VPN Love
Because Your Privacy Matters

What Is a VPN? Follow One Request Through the Tunnel

The ISP sees less. The VPN provider takes the middle. Websites see a different public IP—and the same account, cookies, and device when you bring them.
By Charles Joseph · Published
Share
Share
Copy URL

A VPN doesn't make you invisible; it changes who can see what. Your internet provider loses the same view of covered destinations. The VPN company gains a powerful place in the route. Websites see a different public IP—and the same account if you sign in.

That's the whole idea before the acronyms arrive.

VPN stands for virtual private network. An app creates an encrypted connection to a VPN server, sends covered traffic through it, and lets that server make the final connection to the wider internet.

One protected hop. One new intermediary. One address swap at the destination.

VPNs Explained Without the Jargon
A visual introduction to VPN tunnels, encrypted connections, and IP addresses for anyone starting from zero.

Open Your Laptop on Airport Wi-Fi

Leave the VPN off and open a website.

Your laptop sends the request through the airport network and internet provider. HTTPS protects page contents on a secure site, but the network can still see connection metadata and destination addresses. No VPN provider handles the request. The website sees the airport's public IP plus cookies, browser signals, and any account you use.

Now turn on a full-device VPN.

The app builds an encrypted connection to a VPN server. Your operating system feeds covered traffic into it: browser tabs, email, background apps. Only deliberate exclusions or unsupported traffic take another route.

The airport network now sees one encrypted connection to the VPN server instead of the same set of covered destinations. The VPN provider handles the next hop. The website sees the server's public IP—plus the same cookies, browser signals, and signed-in account.

The contents were already protected by HTTPS. The VPN changes the first part of the route and the public address presented at the other end.

The Tunnel Ends Before the Website

Traffic doesn't stay inside the VPN forever.

Your request reaches the VPN server, leaves the tunnel, and continues to the destination. The reply returns to that server, enters the encrypted tunnel, and comes back to your device. This round trip happens continuously, usually fast enough to feel ordinary.

HTTPS still matters after the VPN server. On a properly secured site, it protects page contents across the whole web connection. Without HTTPS, traffic may be readable or alterable after it leaves the VPN endpoint.

Never ignore a certificate warning because a green VPN icon is visible. The tunnel can't make an unsafe destination secure.

Sale
Privacy Is Power: A Practical Case for Taking Back Your Data
  • Connects everyday data collection to real choices about freedom, power, and control
  • Explains why privacy matters even when you have nothing to hide
  • Turns a broad social issue into practical questions you can apply to your digital life

Privacy Is Power helps place that route change inside the larger question: who gets data, what leverage it creates, and which collection is actually necessary. A VPN solves one network boundary, not the entire privacy problem.

What the VPN Can Hide

Websites and apps receiving covered traffic see the VPN server's public IP instead of the connection's usual public IP. That removes one common clue that can identify an internet connection and suggest an approximate location.

The local network and ISP can't inspect covered destinations in the same way when the tunnel works correctly. They still see that your device connects to a VPN server, when it connects, and how much data moves.

That trade is useful on a hotel, airport, café, campus, or other shared network you don't control. It's also useful when you don't want an ISP building the same destination-level view of your covered traffic.

The NCSC's VPN guidance makes the boundary explicit: only traffic routed over the VPN receives its protection.

What the VPN Provider Can See

The provider sits where the encrypted first hop ends. It may see source addresses, connection times, server choices, traffic volume, destinations, and account information depending on its design and records.

That doesn't mean every VPN stores all of it. It means the service has a position worth investigating.

Read the privacy policy for specific operational data and retention periods. Look for independent audits, but read their scope and date. An audit can test named systems during a period; it can't certify every future server forever.

You're Moving Trust, Not Eliminating It
A thoughtful look at the central tradeoff in VPN privacy: your ISP sees less, but your VPN provider occupies a powerful new position.

“No logs” without a definition tells you almost nothing. Ask which logs, where, for how long, and why.

A Different IP Isn't a Different Identity

Sign into email through a VPN and the email provider knows it's your account. Buy something and the store receives the name, address, payment details, and order. Keep the same cookies and a site can recognize the browser before it considers the IP.

Advertising identifiers, browser fingerprints, device data, location permissions, and behavior can connect sessions across address changes. A VPN modifies one signal. It doesn't erase the others.

The same limit applies to region changes. A VPN server in another country can change the IP-based location a service sees. It can't move the device, rewrite an account region, supply a subscription, carry a license, or override the service's rules.

A VPN can also route around network-level filtering, and in peer-to-peer transfers it can keep other peers from seeing your ordinary public IP. Neither outcome creates permission: services can block VPN traffic, and their rules still apply.

Think “different network address,” not “new person.”

A Tunnel Can't Inspect Your Decisions

A fake bank page still looks convincing through a VPN. If you type the password, the tunnel can deliver it securely to the attacker.

A malicious installer remains malicious after encryption. A VPN doesn't scan every download, patch the operating system, repair weak passwords, or remove malware already on the device unless a separate security feature performs that job.

Use unique passwords, current software, careful download sources, and multifactor authentication. CISA recommends phishing-resistant MFA where available because account security is a different layer from network routing.

Put Account Protection on the Account

A physical security key can stop a fake login page from completing a supported FIDO sign-in even when the password is stolen. That's the kind of risk a VPN was never designed to address.

YubiKey 5C NFC: Tap or Plug In for Safer Account Access
  • Connects through USB-C or NFC, covering many newer computers and compatible phones
  • Adds a phishing-resistant physical check to passkeys and supported multi-factor logins
  • Works without a battery, code display, or wireless pairing process

YubiKey 5C NFC supports USB-C and NFC on compatible devices. Check each important account's supported authentication methods, register a recovery option, and keep a spare somewhere safe before depending on one key.

The comparison stays clean: the VPN changes the route to the login service; the key helps the login service verify that you're really you.

Whole Device Doesn't Always Mean Every Packet

A full VPN app can cover most supported device traffic. Split tunneling can deliberately exclude apps, domains, or destinations. Some traffic may bypass the app because of operating-system limits, configuration errors, unsupported protocols, or leaks.

Follow both routes.

An included browser enters the tunnel: the ISP sees the VPN-server connection, the provider forwards the request, and the site sees the VPN IP. An excluded game goes direct: the ISP sees the game connection, the VPN provider receives none of it, and the game sees the ordinary public IP.

A single Connected label can sit above both outcomes. Test the app that matters.

Failure Behavior Is Part of the Product

When a tunnel drops, the operating system needs another instruction.

With fail-open behavior, covered traffic returns to the normal route. The local network and ISP regain the destination view, the VPN provider receives none of those direct requests, and websites see the ordinary public IP.

With a working fail-closed kill switch, covered traffic stalls until the tunnel returns. That can be inconvenient. It's also the only way to prevent a silent route change.

Interrupt the connection with a harmless page open, then test after sleep, reboot, and network changes. A kill-switch toggle you haven't tested is a promise, not evidence.

The One VPN Setting That Prevents Accidental Leaks
See what happens when a VPN connection drops and how a kill switch keeps traffic from quietly returning to the open network.

Check the Route Before You Trust It

Look up the public IP with the VPN off. Connect to a nearby server and check again from the same device. The address should change, though geolocation databases can label the new location imperfectly.

Run DNS and IPv6 checks. Use our DNS leak guide to see whether name lookups escaped the intended route. Test both ordinary browsing and any app covered by split tunneling.

Before paying, identify the operator; check for maintained apps and established protocols such as WireGuard or OpenVPN; confirm device limits, required locations, and refund terms. A huge server count can't rescue a service that doesn't fit your devices or work reliably where you need it.

Then watch performance during the real task. A full call or episode exposes stalls a ten-second speed test misses. Try another nearby server before declaring the entire service slow.

Choose the Job Before the Provider

Use a VPN when the problem is an untrusted local network, ISP visibility into covered destinations, a different public IP, or authorized access to a private work network.

Don't reach for it when the problem lives in a password, phishing message, infected file, signed-in account, browser fingerprint, or company database. Those risks need different controls.

Return to the airport laptop. The VPN didn't disappear the device. It gave covered traffic an encrypted first hop, shifted trust from the local network to a provider, and changed the public IP seen by destinations.

That's useful. It's also precise. The best reason to understand a VPN is knowing exactly when that route is the protection you need—and when it isn't.