PublicIPChecker

Guide

How does a VPN work?

6 min read · Updated 2026-10-06

A VPN builds an encrypted tunnel to a server elsewhere, so your traffic exits from that server's IP. Here is what happens, step by step.

VPN stands for virtual private network, which describes the original use case — joining a private corporate network over the public internet. Today the term usually means a commercial service that puts your traffic through a server in another city. Mechanically, both are the same four ingredients: a handshake, a tunnel, encryption, and an exit.

The five steps

  1. Handshake. Your VPN client authenticates to the provider's server — with certificates or a pre-shared key, plus a per-session key exchange. Both sides agree on ciphers, and each gets fresh session keys.
  2. Tunnel creation. The client creates a virtual network adapter (utun0 on macOS, wg0 on Linux, a TAP/WinTUN adapter on Windows) and adds a route that captures traffic.
  3. Encryption and encapsulation. Each packet is encrypted and wrapped inside a new UDP or TCP packet addressed to the VPN server. Your ISP now sees only "encrypted traffic to the VPN", not the destinations inside.
  4. Exit. The provider's server unwraps the packet and sends it to the real destination from its own IP address. Replies come back the same way.
  5. Leak control. A kill switch blocks traffic if the tunnel drops, and DNS settings ensure name resolution travels inside the tunnel rather than to your ISP's resolver — the subject of DNS leaks.

Protocols: WireGuard, OpenVPN, IKEv2

ProtocolCharacterGood for
WireGuardModern, ~4,000 lines of code, fast handshakes, kernel-speed throughputPhones, laptops, low-latency use, gaming
OpenVPNBattle-tested, configurable, heavierNetworks with awkward firewalls, legacy devices
IKEv2/IPsecVery stable across network changesMobile devices moving between Wi-Fi and cellular
L2TP/IPsec, PPTPOld, weak or slowNothing — avoid

Protocol choice affects speed more than privacy: all of the top three are considered secure when configured correctly, and the real differences are latency and how gracefully they reconnect.

What happens to your IP address

With a full tunnel, every site you visit sees the VPN server's address. That address usually belongs to a datacentre, which is exactly why sites label it that way — see datacenter IPs and how sites detect VPNs. Your actual address still exists; it is simply on the other side of the tunnel, visible to your ISP and the VPN provider.

Two consequences worth internalising:

  • Split tunnelling — routing only some apps through the tunnel — means the rest of your traffic shows your real address. That is a feature, not a bug, but it surprises people.
  • IPv6. A tunnel that carries only IPv4 can leave IPv6 traffic running in the clear, which is the most common leak in a dual-stack world. Check both rows with the VPN test and read IPv6 in 2026 for the background.

What a VPN does not hide

  • That you are using a VPN — the provider's address range is well known, and traffic patterns are recognisable.
  • Your accounts. Signed in is signed in; the address is irrelevant to identification.
  • Cookies and browser fingerprints, which track you across sessions regardless of address.
  • Your ISP's view of volume and timing. It cannot read the contents, but it sees the encrypted flow and the VPN endpoint.
  • Malware or bad links. A tunnel is a private path, not a filter.

Choosing and verifying one

Prefer providers with published audits, a documented no-logs stance, WireGuard support, a kill switch and an honest jurisdiction. Free services deserve their own scrutiny — see are free VPNs safe. Then verify rather than trust: after connecting, the IP checker should show the provider's address and country, the WebRTC test should not show your local address, and DNS should resolve through the tunnel. If anything still points at your home ISP, the tunnel is not doing its job.

Bottom line: a VPN moves your exit point and encrypts the path to it. It is excellent at hiding your traffic from the local network and your browsing from the ISP; it is not a cloak of invisibility against the sites you log in to.

Frequently asked questions

Does a VPN change my IP address?

Yes — with a full tunnel, websites see the VPN server's address instead of yours, with the country of that server. Your real address is unchanged at the network level and remains visible to your ISP and the VPN provider.

Can my employer see what I do with a VPN?

They see an encrypted connection to the VPN and the volume, not the destinations inside it — provided your traffic is actually tunnelled, and device-level management software is not installed. Corporate devices often have such software, which sees everything regardless.

Does a VPN make me anonymous?

No. It hides your IP from the sites you visit, but logins, fingerprints and the provider's own logs can identify you. For strong anonymity you need Tor, the Tor Browser and discipline — see Tor vs VPN.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.