Guide
How does a VPN work?
A VPN builds an encrypted tunnel to a server elsewhere, so your traffic exits from that server's IP. Here is what happens, step by step.
On this page
VPN stands for virtual private network, which describes the original use case — joining a private corporate network over the public internet. Today the term usually means a commercial service that puts your traffic through a server in another city. Mechanically, both are the same four ingredients: a handshake, a tunnel, encryption, and an exit.
The five steps
- Handshake. Your VPN client authenticates to the provider's server — with certificates or a pre-shared key, plus a per-session key exchange. Both sides agree on ciphers, and each gets fresh session keys.
- Tunnel creation. The client creates a virtual network adapter (
utun0on macOS,wg0on Linux, a TAP/WinTUN adapter on Windows) and adds a route that captures traffic. - Encryption and encapsulation. Each packet is encrypted and wrapped inside a new UDP or TCP packet addressed to the VPN server. Your ISP now sees only "encrypted traffic to the VPN", not the destinations inside.
- Exit. The provider's server unwraps the packet and sends it to the real destination from its own IP address. Replies come back the same way.
- Leak control. A kill switch blocks traffic if the tunnel drops, and DNS settings ensure name resolution travels inside the tunnel rather than to your ISP's resolver — the subject of DNS leaks.
Protocols: WireGuard, OpenVPN, IKEv2
| Protocol | Character | Good for |
|---|---|---|
| WireGuard | Modern, ~4,000 lines of code, fast handshakes, kernel-speed throughput | Phones, laptops, low-latency use, gaming |
| OpenVPN | Battle-tested, configurable, heavier | Networks with awkward firewalls, legacy devices |
| IKEv2/IPsec | Very stable across network changes | Mobile devices moving between Wi-Fi and cellular |
| L2TP/IPsec, PPTP | Old, weak or slow | Nothing — avoid |
Protocol choice affects speed more than privacy: all of the top three are considered secure when configured correctly, and the real differences are latency and how gracefully they reconnect.
What happens to your IP address
With a full tunnel, every site you visit sees the VPN server's address. That address usually belongs to a datacentre, which is exactly why sites label it that way — see datacenter IPs and how sites detect VPNs. Your actual address still exists; it is simply on the other side of the tunnel, visible to your ISP and the VPN provider.
Two consequences worth internalising:
- Split tunnelling — routing only some apps through the tunnel — means the rest of your traffic shows your real address. That is a feature, not a bug, but it surprises people.
- IPv6. A tunnel that carries only IPv4 can leave IPv6 traffic running in the clear, which is the most common leak in a dual-stack world. Check both rows with the VPN test and read IPv6 in 2026 for the background.
What a VPN does not hide
- That you are using a VPN — the provider's address range is well known, and traffic patterns are recognisable.
- Your accounts. Signed in is signed in; the address is irrelevant to identification.
- Cookies and browser fingerprints, which track you across sessions regardless of address.
- Your ISP's view of volume and timing. It cannot read the contents, but it sees the encrypted flow and the VPN endpoint.
- Malware or bad links. A tunnel is a private path, not a filter.
Choosing and verifying one
Prefer providers with published audits, a documented no-logs stance, WireGuard support, a kill switch and an honest jurisdiction. Free services deserve their own scrutiny — see are free VPNs safe. Then verify rather than trust: after connecting, the IP checker should show the provider's address and country, the WebRTC test should not show your local address, and DNS should resolve through the tunnel. If anything still points at your home ISP, the tunnel is not doing its job.
Bottom line: a VPN moves your exit point and encrypts the path to it. It is excellent at hiding your traffic from the local network and your browsing from the ISP; it is not a cloak of invisibility against the sites you log in to.
Frequently asked questions
Does a VPN change my IP address?
Yes — with a full tunnel, websites see the VPN server's address instead of yours, with the country of that server. Your real address is unchanged at the network level and remains visible to your ISP and the VPN provider.
Can my employer see what I do with a VPN?
They see an encrypted connection to the VPN and the volume, not the destinations inside it — provided your traffic is actually tunnelled, and device-level management software is not installed. Corporate devices often have such software, which sees everything regardless.
Does a VPN make me anonymous?
No. It hides your IP from the sites you visit, but logins, fingerprints and the provider's own logs can identify you. For strong anonymity you need Tor, the Tor Browser and discipline — see Tor vs VPN.
Keep reading
- How to check if your VPN actually works
- How IP geolocation works
- Does a VPN slow down your internet?
- Tor vs VPN
- Proxy vs VPN
- What is a proxy server?
- Are free VPNs safe?
- How to find your IP address on a computer
- How to find your router's IP address
- How to trace an IP address
- What is a DNS server?
- Does incognito mode hide your IP address?
- Browse all IP guides
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.