Switch on a VPN in a café and the network operator will usually lose sight of which websites you visit. Open your usual shopping account and the shop still knows it’s you.

Both can be true. A VPN changes the route your connection takes and the internet address websites see. That can give you useful privacy from one observer without making you anonymous to another.

The question worth asking is simple: who do you want to reveal less to?

The short version

  • Your network sees less. A correctly configured VPN usually hides browsing destinations from your internet provider and local Wi-Fi operator, while leaving the VPN connection visible.
  • Websites can still recognize you. Accounts, cookies and other signals survive a change of IP address.
  • The VPN company becomes part of your trust decision. It can see connection information, but properly working HTTPS still protects page contents and passwords from it.

Follow one connection

An IP address is an address used to route internet traffic. It can also suggest your approximate location. A personal VPN sends traffic through an encrypted connection, often called a tunnel, to a server run by the VPN provider. The server forwards it onward. For traffic taking that route, websites normally see the VPN server’s public IP address rather than your home or mobile connection’s address. Mozilla explains the basic route.

The VPN tunnel ends at that server. HTTPS is a separate layer: it encrypts the connection between your browser and the website’s server, including the journey through the VPN. With HTTPS working correctly, neither the café nor the VPN operator can simply read your password, the page you’re viewing or the form you submit. The website receiving those details can. EFF’s encryption guide explains that distinction.

A VPN and HTTPS protect different parts of the route

  • The VPN provider can see your connecting IP.
  • The website normally sees the VPN’s public IP for traffic routed through it.
  • The website can read information you send to it.
Text description of the diagram

Your traffic passes through your internet provider to the VPN server, then to the website. VPN encryption ends at the VPN server. Properly working HTTPS continues from your browser through the VPN server to the website, protecting page contents from the network and VPN provider. The website receives those contents.

Two layers, different endpoints: the VPN tunnel ends at the VPN server; HTTPS continues to the website. Assumes an ordinary personal VPN, relevant traffic routed through it, working HTTPS and an uncompromised device. Sources: Mozilla, What is a VPN?; EFF, What Should I Know About Encryption?

Without HTTPS, traffic can become readable after it leaves the VPN server. A VPN cannot turn an unencrypted website into an encrypted one.

Who can see what

This comparison assumes an ordinary personal VPN, relevant traffic and DNS lookups routed through it, working HTTPS, and an uncompromised device. Managed workplace devices may have additional monitoring.

ObserverCan ordinarily seeDoes not ordinarily see
Internet provider or local Wi-Fi operatorYour connection to a VPN server; timing and amounts of trafficThe sites reached inside the tunnel; HTTPS page contents
VPN providerYour connecting IP; destination IPs; often domain names; traffic timing and amountsHTTPS page contents, passwords or full page addresses
Website you visitIts own pages and information you send; your account or cookies; the VPN’s IPYour original public IP solely from this tunneled connection

Domain visibility depends on how names are looked up and how connections are established. Seeing a destination is different from reading its contents. The VPN provider’s ability to observe information is also different from a promise not to retain it. EFF’s VPN guide covers these trust boundaries.

Why a website still knows you

Imagine changing VPN servers and returning to a shop where you’re already signed in. Your session still identifies your account. Cookies can also let a site recognize a returning browser without knowing your name. A VPN does not clear those cookies or log you out. MDN describes how cookies preserve sessions and support tracking.

Sites may also combine browser and device characteristics into a fingerprint. Changing your network address does not remove the characteristics your browser reveals. Browser protections can reduce this tracking; the VPN tunnel itself does not provide that function. Mozilla’s fingerprinting explanation describes the signals involved.

Location is another separate channel. If you grant a site location access, your browser may supply a position obtained from the device, such as GPS. Selecting a VPN server abroad does not revoke that permission. MDN’s geolocation documentation explains the permission and device-based lookup.

When a VPN earns its place

A VPN can be useful when you want to reduce what an unfamiliar network learns about your browsing, or keep your home IP address away from sites you visit. It may also help reach services blocked by a particular network, although access is not guaranteed. Workplace VPNs serve another purpose: connecting staff to company resources. They should not be treated as privacy from the employer.

Public Wi-Fi deserves some perspective. HTTPS already protects the contents of ordinary encrypted web connections, whether you’re at home or in a café. A VPN can add protection for network-level information, but a claim that every café user urgently needs a subscription overstates the case. EFF explains how HTTPS changed public Wi-Fi risk.

A scam can still arrive through an encrypted connection. A VPN does not validate a seller, fix a reused password or remove spyware. Some VPN products bundle malicious-site blocking, but that is an additional feature with its own limits. Device updates and careful handling of unexpected downloads still matter. EFF’s malware guide explains why protection on the device remains necessary.

Five checks before you rely on it

  1. Check who runs it. Find the operator, privacy policy and business model. Read what “no logs” actually excludes and what it permits. A published independent audit is useful evidence; check its date and scope. It cannot guarantee future behavior.

  2. Check what goes through it. A browser-only service may leave other apps outside its coverage. “Split tunneling” or “app exclusions” deliberately sends selected traffic around the VPN. Review exclusions rather than assuming the connected symbol covers everything. Mozilla explains split tunneling.

  3. Check failures and leaks. Look for a kill switch designed to block traffic if the tunnel drops. Check your provider’s instructions for your operating system. DNS lookups translate site names into network addresses; a DNS leak can expose those lookups outside the tunnel. Ask how the app handles both IPv4 and IPv6, the two address systems. A changed IP alone does not prove every connection is covered.

  4. Keep HTTPS and updates on. Use your browser’s HTTPS-only or secure-connection setting where available, and stop at certificate warnings. Keep the VPN app, browser and operating system updated. Mozilla’s HTTPS-only guide shows what encrypted-only browsing does.

  5. Review the identifiers you still share. Check which accounts are signed in, enable browser tracking protection, and review site location permissions. Choose these settings for your actual goal. You may want privacy from a hotel network while intentionally staying signed in to email.

Quick check

1. You turn on a VPN, then sign in to your shopping account. Can the shop connect your visit to that account?

A. Yes · B. No

Show answer to question 1

Answer: A. Your sign-in identifies you regardless of the IP address used to reach the shop.

2. Which layer protects a password from the VPN provider during a normal, correctly secured website login?

A. The VPN tunnel alone · B. HTTPS

Show answer to question 2

Answer: B. HTTPS continues between browser and website after the VPN tunnel ends.

3. Your VPN is connected, but one app is excluded through split tunneling. Is that app’s traffic necessarily inside the VPN?

A. Yes · B. No

Show answer to question 3

Answer: B. An exclusion deliberately allows traffic to take another route.

One useful step today

Finish this sentence: “I want my VPN to reveal less to ______.” Then check the relevant row above and one setting that supports that goal. A clear privacy goal is more useful than a reassuring connected icon.