# What a VPN Actually Does

> What a VPN really routes and hides, and what it does not: the encrypted-tunnel model, who can see what, and when a VPN is mostly theater.


---

# What a VPN Actually Does

You've seen the ads - a hooded figure, a world map, the promise that one app makes you invisible, untraceable, safe. Then you turned it on and nothing visibly changed, and you were left wondering what you actually bought. The confusion isn't your fault: VPNs are sold on a feeling and explained almost nowhere.

This guide replaces the feeling with a model you can reason from. By the end you'll know exactly what a VPN moves, exactly who can see what before and after, and exactly when turning one on changes nothing real. No fear, no hype - only the wiring.

## How to read this

- **Want the one-sentence answer?** A VPN is an encrypted tunnel to a relay server: your provider sees encrypted traffic to the VPN, websites see the VPN's address instead of yours. Phase 1 makes that picture solid.
- **Want to stop being fooled by marketing?** Read in order. Phase 2 walks the "who sees what" ledger, and Phase 3 is the clear-eyed part - where the promises quietly break.

## The phases

1. **[The Tunnel - What a VPN Really Is](01-the-tunnel.md)** - the encrypted-tunnel mental model: a VPN doesn't hide you, it *relays* you through one trusted server, and that single move is the whole product.
2. **[Who Sees What - The Visibility Ledger](02-who-sees-what.md)** - exactly what changes when the tunnel is on: your ISP goes blind to your destinations, websites see the VPN's address, and one party gains the view your ISP lost.
3. **[Where the Promises Break](03-where-the-promises-break.md)** - the clear-eyed part: HTTPS already encrypted your pages, you are not anonymous, and the VPN provider is now the one you're trusting. When a VPN actually helps, and when it's theater.

> This guide assumes the basics of how traffic moves and gets addressed. If "ISP," "IP address," or "request" feel shaky, skim [How the Internet Works](/guides/how-the-internet-works) and [IP, DNS & Ports](/guides/ip-dns-and-ports) first - they make this one click into place.


---

# The Tunnel - What a VPN Really Is

You click *Connect* in the VPN app, a little shield turns green, and... your email still loads, your videos still play, your bank still works. Nothing on screen tells you what changed. That silence is exactly why VPNs feel like magic - and why the marketing fills the gap with hooded figures. The real thing is simpler and far more useful to understand.

Forget "invisibility" for a moment. A VPN does one concrete, mechanical thing. Once you see that one thing, every claim you'll ever read about VPNs becomes easy to check.

## The normal path, before any VPN

Start with what happens with no VPN at all, so we have something to compare against. You open a site. Your request leaves your device, goes to your router, then to your **ISP** (the company you pay for internet), and the ISP forwards it out toward the website. The reply comes back the same way.

```text
   You ──▶ Router ──▶ ISP ──▶ Website
       (everything passes THROUGH your ISP)
```

*What just happened:* Every single thing you do online flows through your ISP. They're the on-ramp to the entire internet for you - there is no other road out of your house. That position is the whole reason a VPN exists.

📝 **Terminology.** *ISP* = Internet Service Provider - Comcast, your phone carrier, the coffee-shop Wi-Fi's owner. Whoever sits between you and the rest of the internet. Hold onto this; the next two phases are largely a story about what your ISP can and can't see.

## What "VPN" actually stands for

**What it actually is.** VPN stands for **Virtual Private Network**. Strip the jargon and it means: a private, encrypted connection ("tunnel") running *over* the public internet to one specific server you've chosen to trust. That server then talks to the rest of the internet *for* you and passes the answers back through the tunnel.

**Why the name confuses people.** "Private network" sounds like it builds you a secret, separate internet. It doesn't. You're still using the same public internet as everyone else. The only thing that's private is the sealed pipe between your device and that one server - like a covered walkway across an open public plaza. People can see the walkway exists; they can't see who's inside it or where you go after you step out the far end.

## The tunnel, drawn

Here's the same trip with the VPN on. The shape is the key thing - read it slowly:

```text
   You ══════════════▶ VPN Server ──▶ Website
        encrypted tunnel              VPN fetches
                                      the site for you
   Router & ISP can only see:
   "encrypted traffic going to the VPN server" - nothing else
```

*What just happened:* Your traffic still leaves through your router and ISP - there's no other exit. But now it's wrapped in encryption and addressed to the VPN server. Your ISP can see *that you're talking to a VPN* and *how much*, but not what's inside or where it's ultimately headed. The VPN server unwraps it, fetches the actual website, and sends the answer back through the same sealed tunnel.

📝 **Terminology.** *Encryption* here means the data is scrambled so anyone who intercepts it sees noise, not content. *Tunnel* is the everyday name for that scrambled connection between you and the VPN server. Nothing mystical - it's a lockbox that only your device and the VPN server hold the key to.

## The one move that is the entire product

Everything a VPN sells you comes from a single relocation: **the public-facing end of your connection moves from your house to the VPN server.**

Before, the internet's exit point for you was your ISP, and the address the world saw was *yours*. After, the exit point is the VPN server, and the address the world sees is the *server's*.

```mermaid
flowchart LR
  you[Your device] ==>|encrypted| vpn[VPN server]
  vpn -->|its own address| web[Websites]
  isp[Your ISP] -.->|sees only:<br/>traffic to VPN| you
```

That's it. That relocation is what makes a website think you're in another country, what hides your browsing destinations from your ISP, and - as we'll see in Phase 3 - what hands a brand-new view of your activity to the VPN company. One move, every consequence.

> **For builders:** if you've ever SSH'd into a jump host and run commands from *there* to reach a database that won't accept your laptop directly, you already understand a VPN. Same idea: a trusted middle machine acts on your behalf, and the far end sees the middle machine, not you. A corporate VPN is literally this - it puts your laptop "inside" the office network so internal services answer you.

## Why this matters before we go further

People argue about VPNs endlessly - "does it hide my IP?", "can my ISP see me?", "am I anonymous?" - and talk past each other because they're missing this picture. Every one of those questions is *"what can a given party see, given the tunnel ends at the VPN server?"* Now that you can draw the path, you can answer them yourself instead of trusting an ad. That's the next phase.

## Recap

1. **Without a VPN, everything you do flows through your ISP** - your only on-ramp to the internet.
2. **A VPN is an encrypted tunnel to one server you choose to trust**, which fetches the internet on your behalf.
3. **Your ISP still carries your traffic** but now sees only encrypted data headed to the VPN - not its contents or final destination.
4. **The whole product is one move:** your connection's public exit point relocates from your house to the VPN server.

```quiz
[
  {
    "q": "In plain terms, what is a VPN?",
    "choices": ["A separate, secret internet only you can access", "An encrypted tunnel to one server that relays your traffic to the rest of the internet", "Software that deletes your browsing history", "A faster replacement for your ISP"],
    "answer": 1,
    "explain": "A VPN is a private encrypted connection over the public internet to one trusted server, which then fetches the internet for you."
  },
  {
    "q": "With a VPN on, what can your ISP still see?",
    "choices": ["The full contents of every page you visit", "Nothing at all - the ISP is bypassed entirely", "That you're sending encrypted traffic to a VPN server, and how much", "Only the websites, not the VPN"],
    "answer": 2,
    "explain": "Your traffic still flows through the ISP, but it's encrypted and addressed to the VPN, so the ISP sees the VPN connection exists - not its contents or final destination."
  },
  {
    "q": "What single change produces all of a VPN's effects?",
    "choices": ["It encrypts your hard drive", "The public exit point of your connection moves from your house to the VPN server", "It assigns you a brand-new device", "It blocks all advertisements"],
    "answer": 1,
    "explain": "Relocating the connection's public-facing end to the VPN server is the one move behind every VPN consequence - new visible IP, hidden destinations, and shifted trust."
  }
]
```


---

# Who Sees What - The Visibility Ledger

The single most useful question about any privacy tool is boring and specific: **who can see what, exactly?** Not "is it safe" - that word means nothing without naming a watcher. Once you list the parties watching your traffic and ask what each one observes with the VPN off versus on, the whole topic turns from vibes into a table you can read.

So let's build that table. There are only a handful of parties who can see anything, and a VPN changes precisely two columns. Knowing which two is the difference between using a VPN well and being sold one.

## The cast of watchers

Every time you load a page, a small, fixed set of parties is in a position to observe something:

```text
   You ─ Router ─ ISP ─ ( the internet ) ─ Website
                  ▲                          ▲
         your ISP / network owner      the site you visit
```

*What just happened:* Two watchers matter most for everyday privacy: **your ISP** (or whoever runs the network you're on - airport Wi-Fi, your employer, your landlord) and **the website** you're visiting. A VPN inserts a third party - the VPN provider - into this picture, and that addition is the heart of this phase.

## Column one: what your ISP sees

**With the VPN off.** Your ISP is the road every request travels. They can see the *destinations* you connect to - which sites, by address - and how much data, and when. They cannot read the *contents* of properly secured (HTTPS) pages, but the list of where you went is right there in front of them.

```text
   ISP log, VPN OFF:
   10:01  you → news-site.example      (which sites you visit:
   10:02  you → bank.example            fully visible)
   10:04  you → some-forum.example
```

*What just happened:* Even though the *contents* are encrypted by HTTPS, your ISP still sees the *list of destinations*. That list alone is revealing - the sites you read, the bank you use, the forum you frequent.

**With the VPN on.** That list collapses to one line:

```text
   ISP log, VPN ON:
   10:01  you → vpn-server.example   (encrypted)
   10:02  you → vpn-server.example   (encrypted)
   10:04  you → vpn-server.example   (encrypted)
```

*What just happened:* Your ISP now sees only repeated encrypted connections to the VPN server. The destinations vanished from their view. This is the single most real, most defensible thing a VPN does: **it takes your browsing destinations away from your ISP and the local network owner.**

⚠️ **Gotcha.** "Hidden from the ISP" does not mean "hidden from everyone." The destinations didn't disappear - they moved. Someone still sees them. Hold that thought; it's the trap the whole next phase is built around.

## Column two: what the website sees

**With the VPN off.** The website you visit sees the address you're connecting from - your public IP, the one tied to your household via your ISP. That address reveals your rough geographic area and your provider, and lets the site (and trackers on it) recognize that a series of visits came from the same place.

**With the VPN on.** The site sees the **VPN server's** address instead of yours.

```text
   What the website records as "your" address:
   VPN OFF →  203.0.113.42   (your home, your city, your ISP)
   VPN ON  →  198.51.100.7   (the VPN server, maybe another country)
```

*What just happened:* From the website's point of view, the visitor now appears to be the VPN server. This is why a VPN can make a streaming service think you're in another country, and why your home IP is no longer the thing tying your visits together. The site sees the VPN's address; your real one stays behind the tunnel.

## The ledger, side by side

Here's the entire change, in one view. These two rows are *the* thing a VPN does - no more, no less:

```text
   WATCHER          VPN OFF                    VPN ON
   ───────────────  ─────────────────────────  ─────────────────────────
   Your ISP / Wi-Fi  sees every destination     sees only "→ VPN, encrypted"
   The website       sees YOUR IP address       sees the VPN SERVER's IP
```

```mermaid
flowchart LR
  isp[ISP sees] -->|VPN off| d1[your destinations]
  isp -->|VPN on| d2[only: traffic to VPN]
  site[Website sees] -->|VPN off| a1[your real IP]
  site -->|VPN on| a2[VPN server IP]
```

Notice what's *not* in this ledger: there's no row that says "no one can see anything anymore." A VPN doesn't erase visibility. It **redistributes** it - and the party that gains the view is the subject of Phase 3.

## Where this genuinely helps

This is the real case *for* a VPN, and it's a solid one:

- **Untrusted networks.** On coffee-shop, airport, or hotel Wi-Fi, the network owner is a stranger. The tunnel takes your destinations away from them. Solid, legitimate use.
- **Your ISP profiling or selling your browsing.** In places where ISPs log and monetize destination data, the tunnel removes that list from their reach.
- **Appearing to be somewhere else.** Whether for a region-locked service or to test how a site behaves from another country, swapping the visible IP does exactly that.

> **For builders:** that last point is a daily tool. Spin up a VPN exit (or an SSH tunnel) in another region to check that your CDN, your geo-routing, or your "available in your country" banner behaves correctly from there. You're using the IP-relocation property deliberately - same mechanism, professional purpose.

## Recap

1. **The useful question is always "who sees what?"** - name the watcher before judging safety.
2. **A VPN changes exactly two columns:** your ISP loses your destination list, and websites see the VPN's IP instead of yours.
3. **HTTPS already hid page *contents* from your ISP** - the VPN's contribution is hiding the *list of destinations*.
4. **Visibility isn't erased, it's redistributed** - which sets up the catch in the next phase.

```quiz
[
  {
    "q": "With a VPN on, what does your ISP see?",
    "choices": ["Every website you visit, in full", "Only repeated encrypted connections to the VPN server", "Your passwords in plain text", "Nothing - the ISP is removed from the path"],
    "answer": 1,
    "explain": "Traffic still flows through the ISP, but it's encrypted and aimed at the VPN, so they see a stream of connections to the VPN server, not your destinations."
  },
  {
    "q": "With a VPN on, what IP address does a website record for your visit?",
    "choices": ["Your real home IP address", "No IP address at all", "The VPN server's IP address", "A random address that changes every second"],
    "answer": 2,
    "explain": "Because the VPN server fetches the site on your behalf, the site sees the server's address, not yours."
  },
  {
    "q": "What's the most accurate description of what a VPN does to visibility?",
    "choices": ["It erases all visibility so no one can see anything", "It redistributes visibility - your ISP loses the view, someone else gains it", "It encrypts your traffic so even websites can't read it", "It makes your traffic invisible to the websites themselves"],
    "answer": 1,
    "explain": "A VPN doesn't make traffic unseeable; it moves who can see your destinations. That shifted view is the focus of the next phase."
  }
]
```


---

# Where the Promises Break

This is the phase the ads don't want you to read, and the one that'll actually save you money and false confidence. A VPN does something real - you saw it in Phase 2. But the gap between what it does and what it's *sold* as is enormous, and that gap is where people get hurt: they pay for a feeling of safety they don't have, and take risks they wouldn't take sober.

So let's be the friend who tells you the truth. Three big promises, examined plainly. None of this means VPNs are useless - it means you'll know exactly what you're buying.

## Promise 1: "A VPN encrypts your traffic and keeps it safe"

**The half-truth.** Yes, a VPN encrypts the tunnel between you and the VPN server. But here's the part the ad skips: **for any modern website, your traffic was already encrypted.** That's what the padlock in your browser means - HTTPS encrypts the connection between your device and the website, end to end, with or without a VPN.

```text
   On a public Wi-Fi, visiting an HTTPS site:
   No VPN:  [you]══encrypted by HTTPS══[website]   ← contents already safe
   VPN on:  [you]══tunnel══[VPN]══encrypted by HTTPS══[website]
```

*What just happened:* The contents of an HTTPS page are unreadable to the Wi-Fi snoop *either way*. The VPN adds a second wrapper around the destinations, but it did not "finally" encrypt your bank login - HTTPS did that already. The "hackers can steal everything on public Wi-Fi" pitch describes a world that mostly ended when the web moved to HTTPS.

📝 **Terminology.** *HTTPS* is the secure version of the web's protocol - the `https://` and padlock you see on nearly every site today. It encrypts the conversation between your browser and the server. If you want the full mechanism, see [HTTPS & TLS](/guides/https-and-tls). The key takeaway: your page *contents* are already protected; the VPN's real job is hiding the *list of destinations* from your ISP, not rescuing content that was exposed.

⚠️ **Gotcha.** The one place the "public Wi-Fi" worry still has teeth: if you visit a plain `http://` site (no padlock), or ignore a browser certificate warning, content *can* be exposed - and there a VPN does add protection. But the right fix is to not use unencrypted sites and never click past certificate warnings. A VPN papers over that; it doesn't make ignoring warnings safe.

## Promise 2: "A VPN makes you anonymous"

This is the big one, and it's the one most likely to get someone in trouble. **A VPN does not make you anonymous.** It changes the *address* websites see; it does not erase *who you are*.

Consider everything that still identifies you with the VPN on:

```text
   Still you, VPN or not:
   • Logged into Google / Amazon / your bank?   → they know it's you, IP irrelevant
   • Browser fingerprint (fonts, screen, etc.)  → trackers re-identify you
   • Cookies from before you connected           → still tagging you
   • The VPN provider                            → sees your real IP + your destinations
```

*What just happened:* The moment you log into any account, the new IP is meaningless - the service knows you by your login, not your address. Trackers identify browsers by dozens of subtle traits beyond IP. A VPN swaps one identifier out of many. "Anonymous" requires a completely different and far more demanding toolkit; a consumer VPN is not it.

> Think of it like wearing a different coat to the same shop where the clerk knows your name and you pay with your own card. The coat changed; everything that actually identifies you did not.

## Promise 3: "A VPN protects your privacy"

Here's the redistribution from Phase 2, coming due. Your ISP lost the view of your destinations - but that view didn't vanish. **It moved to the VPN provider.** Every site you visit now passes through their server, in the clear to them, tied to your real IP.

```mermaid
flowchart LR
  you[You + real IP] ==>|encrypted| vpn[VPN provider]
  vpn -->|sees your full destination list| log[(Their logs)]
  vpn --> web[Websites]
```

*What just happened:* You didn't remove a watcher - you **swapped** one. You traded an ISP you have a contract with and laws over, for a VPN company you're taking on faith. A free VPN especially has to make money somehow, and your browsing data is the obvious product. The question "should I trust a VPN?" is really "do I trust this company *more* than my ISP, with the exact same view?" Sometimes yes. Often no. Never automatically.

⚠️ **Gotcha.** "No-logs policy" is a marketing claim, not a guarantee. A few providers have had it tested in court or by audit; most have not. You cannot verify from your couch whether a VPN keeps logs. Treat the promise as a promise, not a fact.

## So when is a VPN worth it - and when is it theater?

**Genuinely worth it:**
- You're on a network run by someone you don't trust (public, employer, landlord) and want your *destinations* hidden from them.
- Your ISP logs or sells browsing data and you'd rather hand that view to a provider you've vetted.
- You need to appear in another region - for access, testing, or routing around censorship.
- A corporate VPN to reach internal office systems. (Different goal entirely: access, not privacy.)

**Mostly theater:**
- "Protecting" HTTPS traffic from public Wi-Fi snoops - HTTPS already does that.
- Seeking anonymity while logged into your real accounts - the login gives you away.
- Believing a VPN removes all watchers - it relocates one to a company you must trust.
- A free VPN sold as privacy - you're likely the product.

> **For builders:** be precise with non-technical people who ask "should I get a VPN?" The useful answer is a question back: *"to hide what, from whom?"* If the answer is "my destinations from sketchy Wi-Fi," yes. If it's "be anonymous" or "stay safe on the internet," a VPN is the wrong tool and you'll do them a favor by saying so. Match the tool to the named threat, not to the ad.

## Recap

1. **HTTPS already encrypts your page contents** - a VPN's real contribution is hiding destinations from your ISP, not rescuing content.
2. **A VPN does not make you anonymous** - logins, cookies, and browser fingerprints still identify you.
3. **You swap watchers, not remove them** - the VPN provider inherits the destination view your ISP lost, tied to your real IP.
4. **"No-logs" is an unverifiable claim** - trust it as a promise, not a fact.
5. **Worth it for hiding destinations on untrusted networks or relocating your apparent region; theater for anonymity or "staying safe online."**

```quiz
[
  {
    "q": "Why is the 'a VPN finally encrypts your bank login on public Wi-Fi' pitch misleading?",
    "choices": ["Banks don't use the internet", "HTTPS already encrypts that connection end to end, with or without a VPN", "Public Wi-Fi can't carry encrypted traffic", "VPNs actually decrypt your traffic"],
    "answer": 1,
    "explain": "Modern sites use HTTPS, which already encrypts page contents between you and the server. The VPN adds a wrapper around destinations, not the rescue the ad implies."
  },
  {
    "q": "Why doesn't a VPN make you anonymous?",
    "choices": ["It only works on weekdays", "Logging into accounts, cookies, and browser fingerprints still identify you regardless of IP", "It shows websites your real name", "Anonymity requires two VPNs"],
    "answer": 1,
    "explain": "A VPN changes the IP websites see, but the moment you log in or get fingerprinted, your identity is known. It swaps one identifier among many."
  },
  {
    "q": "What happens to your ISP's old view of your browsing destinations when you use a VPN?",
    "choices": ["It is permanently deleted", "It moves to the VPN provider, tied to your real IP", "It is split evenly across all websites", "It becomes readable by anyone on the internet"],
    "answer": 1,
    "explain": "The destination view doesn't vanish - the VPN provider inherits it. You swap a watcher you have a contract with for a company you must trust."
  }
]
```
