By Eric L.
09/09/2026 · 8 MIN READ

Is a VPN safe? On its own, neither safe nor unsafe. It's an encrypted tunnel to someone else's server, and everything hinges on whose server, what gets written down there, and what you do while the tunnel is up. A good VPN hides your list of sites from the coffee shop Wi-Fi and from your ISP. A bad one does the opposite: it collects that list itself, sells it, and throws in ads. And then there are the cases where the VPN is honest and useless, because the hole is somewhere else.

Here are five situations where a VPN makes you less safe, not more. If none applies, your tunnel is doing its job. If one does, it's an evening's fix.

WHEN A VPN MAKES THINGS WORSEFIG. 01
[!] a free app from the store
[!] tunnel up, DNS leaking around it
[!] kill switch turned off
[!] trusting the "no logs" banner
[!] expecting what it does not do
    └─ ten minutes to check all five

1. The free app from the store

Servers and bandwidth cost money. An app that doesn't charge you is charging someone else, and the product it sells is usually you: ad SDKs inside the app ship your device ID and habits to ad networks, and some services rent out your connection so that strangers exit to the internet from your address. You hid from your ISP to expose yourself to a company with no name and no address. How to tell an honest free tier from that is in Free VPN: what it actually costs.

WHAT THE APP RECEIVESFIG. 02
all traffic from the device
the list of sites you open
timing and volume
the ability to change replies
   └─ so the question is not
      "does it work" but
      "who did you hand this to"

A related confusion is expecting a tunnel to do an antivirus's job: VPN vs antivirus.

2. The tunnel is up and DNS is leaking around it

The most common failure, and an invisible one. The connection is established, your IP has changed, and your device is still asking the ISP's DNS server "where is this site". The list of sites goes to the ISP exactly as before, except now you're confident you're protected. Two minutes to check: What Is My IP should show the server's country, and the WebRTC and IPv6 leak tests shouldn't show your real address. The fixes, platform by platform, are in Is my DNS leaking.

3. The kill switch is off

Tunnels drop. Not because the service is bad, but because your phone hopped from Wi-Fi to cellular or the elevator ate the signal. For those seconds your device goes online directly, and whatever was open goes out unencrypted, with your address attached. A kill switch simply cuts the internet for that moment. Without it your protection works "almost always", and "almost" isn't a word that belongs in privacy. Details in What is a VPN kill switch.

WI-FI TO CELLULAR: THE TUNNEL DROPS FOR A FEW SECONDSTunnel upTunnel dropsTunnel back● KILL SWITCH OFFencryptedgoes out directlyencryptedunencrypted, your address attached● KILL SWITCH ONencryptedInternet cutencryptednothing goes out until it is back
A dropped tunnel only needs a few seconds of open network; the kill switch takes those seconds away.

4. You believe the "no logs" banner

The VPN server stands exactly where your ISP used to stand: it can see domains, timing and volume. Whether it records any of that is policy, not technology. "No logs" on a landing page means nothing; a policy that lists what is stored and what isn't means something, because you can check it. A service that "stores nothing at all" is either not running a business or not telling you everything: at minimum it stores your email and subscription status. What a real policy reads like is in What does no-logs VPN mean.

● WITHOUT A VPNYouYour ISPdomains, timing, volumeSites● WITH A VPNYouYour ISPlist of sites hiddenVPN serverdomains, timing, volumeSiteswritten down? policyThe server stands where the ISP stood. Trust a policy that lists what is stored, not a banner.
A VPN does not remove the watcher, it replaces one, and the policy decides what gets kept.

5. You expect things a VPN doesn't do

It doesn't make you anonymous: you signed into your email and your social accounts, and the site knows who you are through any tunnel. It doesn't hide your browser fingerprint: screen, fonts and time zone go to the site straight from the browser. It isn't an antivirus: a malicious download comes through the tunnel just fine. It doesn't stop phishing: a fake bank page loads inside the tunnel like the real one. If those were the reasons you installed it, your security didn't go up; your confidence did, and that is the worst combination.

"NO LOGS" IS A PROMISEFIG. 03
not verifiable from outside
only audits and track record help
open code can be read
jurisdiction changes obligations
   └─ there is nothing in a banner
      to check

The one that is actually dangerous: certificate installs

The most harmful "VPN" looks innocent. The app asks you to install a profile or a certificate "for the secure connection to work". A root certificate lets whoever issued it decrypt your HTTPS traffic wholesale: banking, email, passwords. A real tunnel never needs it; it needs permission to add a VPN configuration, nothing more. If an app insists on a certificate, delete it, then check Settings, General, VPN & Device Management on iPhone, or the credential storage on Android, for anything you don't recognize. This is the one scenario where a VPN isn't "slightly worse" but the exact opposite of its purpose.

WHEN IT GENUINELY HELPSFIG. 04
hotel, airport and café Wi-Fi
a network that rewrites DNS
an ISP that inspects traffic
   └─ in these three the comparison
      is against no protection at all

When a VPN really is safer than none

Public Wi-Fi, where the network owner and everyone on it can see domains and DNS; a tunnel closes that. A home ISP that monetizes browsing data. Travel, where you join dozens of strange networks. Working with company services from a coffee shop. In all of these the tunnel does what it should, provided the first four points are in order. The public-Wi-Fi case in detail: Is public Wi-Fi safe.

THE TEN-MINUTE CHECKFIG. 05
[ ] address changed to the server
[ ] DNS resolves inside the tunnel
[ ] WebRTC exposes nothing
[ ] traffic stops when it drops
[ ] no certificate was installed
Four of these are inconvenient if they fail. The fifth, a certificate you did not expect, is the one that hands someone your traffic outright.

Is your VPN safe? The ten-minute check

  1. Open the privacy policy and find the list of what is stored. No list, only a slogan: minus one.
  2. Connect and check the IP, WebRTC and IPv6 pages above.
  3. Turn the kill switch on and switch from Wi-Fi to cellular: the internet should drop for a few seconds, not fall back to the open network.
  4. Look at the app's permissions: a VPN doesn't need contacts, SMS or the microphone.
  5. Check that there's a paid plan and that the free plan has stated limits. Neither: you're the payment.

VPN red flags in one minute

No paid plan at all. A certificate install. No company name or country. "No logs" with no list behind it. Permissions for contacts, SMS or microphone. Hundreds of identical five-star reviews with no text. Any one of these isn't a verdict; two together are a reason to look elsewhere rather than to argue for this one.

VPN RED FLAGS IN ONE MINUTENo paid plan at allthen you are the paymentA certificate installcan decrypt your HTTPSNo company nameand no country“No logs” bannerwith no list behind itContacts, SMS, microphonea VPN needs none of themIdentical 5-star reviewshundreds, with no textOne flagnot a verdict, look closerTwo togetherlook elsewhere, do not argue for it
One of these is a question; two of them are an answer.

If a specific app worries you, gather the facts and hand them over.

Prompt for an AI
Help me assess a VPN app before I install it.

Name: (which). Developer: (as listed in the
store). Developer country: (if listed).
Price: (free / subscription / both).
What it says about its protocol: (quote it, or
"not stated").
What it says about logs: (quote it, or "not
stated").
Permissions it requests: (list them).

Say which of these signals are worrying and why.
Separately, say what a trustworthy listing would
include that this one does not.
Do not judge it on reviews or ratings.

Bottom line

Whether a VPN is safe is decided by three things, none of them the word "VPN": whose server, what it writes down, and whether the leaks on your side are closed. All three are checkable, and checking takes less time than reading this.

404 VPN lists in its privacy policy what is kept and what isn't: no browsing history, DNS queries, traffic content or source IP after connection; email, subscription status and aggregated volume statistics are kept. VLESS in the Android and macOS apps, WireGuard configs for Istanbul and Marseille from the dashboard, DNS inside the tunnel, a kill switch in the Android app, and a free plan with stated limits: 2 GB a day and one device. Verify all of it yourself, starting on the home page.