By Eric L.
09/08/2026 · 6 MIN READ

A VPN and an antivirus protect different things and neither replaces the other.

A VPN encrypts your traffic and hides your address from the network you're on and from your ISP; it does nothing about a malicious file you download or a fake site you type your password into. An antivirus watches files and programs on the device; it does nothing about who sees your traffic. Whether you need both depends on the device: on phones and modern computers the built-in protection already covers most of what a third-party antivirus does, while nothing built in covers what a VPN does.

VPN AntivirusFIG. 01
hides your traffic     ✓      ✗
hides your address     ✓      ✗
stops malicious files  ✗      ✓
stops phishing pages   ✗      ✓
    └─ neither does the other's job

What a VPN protects

  • Your traffic on shared and public networks: the coffee shop, the hotel, the office.
  • The list of sites you visit, from your ISP and the local network.
  • Your IP address from websites and from the other party in direct connections.
  • Your accounts when abroad, by making logins look like they come from home.

What it doesn't: it carries whatever you send. A phishing page is just as fake through a VPN, and a trojan downloads just as well. The full picture is in what is a VPN.

TWO DIFFERENT JOBSFIG. 02
a tunnel   protects traffic
           in transit
antivirus  protects files and
           processes on the device
   └─ neither covers the other's
      half, and both halves exist

What an antivirus protects

  • Files: it scans downloads, attachments and installers for known malware and suspicious behavior.
  • Running programs: it stops software that tries to encrypt your files, log keystrokes or spread on the network.
  • Sometimes web pages: many suites block known phishing and malware domains in the browser.

What it doesn't: your traffic is as visible to the network as ever, and your address is your own. An antivirus with a "VPN" bundled is two products in one box, not one product doing both jobs.

WHAT EACH ONE STOPSFIG. 03
eavesdropping on the network  VPN
a fake hotspot                VPN
a malicious download          AV
ransomware already running    AV
phishing on a page            neither
Nothing here catches a convincing fake login page. That part still depends on you, not the software.

Where a VPN and antivirus overlap

Both may block known malicious domains: an antivirus in the browser, a VPN through DNS filtering. Both may warn about dangerous networks. That's the extent of it. Everything else is separate.

WHERE THEY OVERLAPFIG. 04
some suites block known-bad domains
some tunnels do the same filtering
  └─ that overlap is the whole of it
everything else is separate work

Is Windows Defender or built-in protection enough?

Windows. Microsoft Defender is a competent antivirus, on by default, updated automatically. For most home users it's enough; a third-party suite adds features, not necessarily protection.

macOS. XProtect and Gatekeeper check downloaded apps and known malware; the system is locked down more tightly than Windows. A third-party antivirus is rarely necessary for ordinary use.

iOS. Apps run in sandboxes and can't scan each other; "antivirus" apps on iPhone are mostly web filters. The real protection is keeping iOS updated and installing from the App Store.

Android. Google Play Protect scans installed apps. The main risk is APKs from outside the store; avoid those and Play Protect covers the rest.

On every platform, the two things that matter most are updates and not installing what you don't trust. An antivirus is a safety net under those, not a substitute.

BUILT-IN PROTECTION, SYSTEM BY SYSTEMWINDOWSMicrosoft Defenderon by default,updated automaticallyenough for mostMACOSXProtect, Gatekeepercheck downloaded appsand known malwarerarely need moreIOSApp sandboxesapps can't scaneach otherkeep iOS updatedANDROIDGoogle Play Protectscans installed apps;main risk:outside-store APKsNone of these hides your traffic or your address: nothing built in covers what a VPN does.
Each system already guards its own files and apps; none of them guards your traffic on the network.

When you need both a VPN and antivirus

  • A Windows PC used by several people, or one that downloads a lot: Defender or a third-party antivirus, plus a VPN for networks outside the house.
  • A laptop that travels: the VPN is the more important of the two, because the threats on hotel Wi-Fi are network threats. See is public Wi-Fi safe.
  • A phone: built-in protection plus a VPN. Third-party antivirus adds little.
RUNNING BOTHFIG. 05
some suites include their own tunnel
two tunnels fight over the route
some scanners inspect encrypted
traffic by installing a certificate
   └─ that last one is worth checking
      before you accept it

Running a VPN and antivirus without conflicts

Some security suites inspect traffic and can block a VPN's connection, or a VPN app can stop the suite's web filter from seeing anything (which is expected: the traffic is encrypted). If the VPN fails to connect after installing a suite, add the VPN app to the suite's exceptions. If the suite complains it can't scan web traffic while the VPN is on, that is the VPN working; rely on the suite's file scanning instead. The troubleshooting order is in VPN not working on Wi-Fi.

WHAT REDUCES RISK MOSTFIG. 06
updates installed promptly  ##########
second factor everywhere    #########
a password manager          ########
antivirus                   #####
a tunnel                    ####
A VPN lands near the bottom of this list on purpose: it's a network fix, not a substitute for the habits above it.

If you're deciding what to actually spend money on, describe what you already have.

Prompt for an AI
Help me decide what I actually need.

Devices: (which, and which operating systems).
What I already run: (built-in protection /
a paid antivirus / a VPN / none).
What worries me: (malware / being watched on
public networks / account takeover / all three).
Budget: (none / small / not a constraint).

Rank what to do first for my situation, and say
plainly where built-in protection is already
enough.
Do not recommend buying something that duplicates
what I already have.

What actually reduces risk most

  1. Updates, on every device, automatically.
  2. Unique passwords in a manager, with 2FA on email; see password managers.
  3. Installing only from official stores and sites.
  4. A VPN on networks you don't control.
  5. Built-in antivirus on, a third-party one only if you have a reason.

A VPN and an antivirus sit at different layers. The question isn't which one, but whether each layer is covered.

TWO LAYERS, TWO DIFFERENT GUARDSYour devicefiles and downloadsrunning programsantivirus guards thisdownloads scanned hereWebsitea fake pagestays fakethe network: Wi-Fi, hotel, ISPVPN: traffic encrypted, address hiddenyour traffica trojan downloads just as wellThe tunnel carries whatever you send or fetch; what arrives on the device is the antivirus's job.
Each covers one layer: the tunnel guards the trip, the antivirus guards what lands on the device.

404 VPN covers the network layer: a VLESS tunnel with DNS inside it, and a kill switch in the Android app. The builds you can download today are Android and macOS, with the other platforms in progress; for Istanbul and Marseille the web dashboard also offers WireGuard configs. Details on the security page; get started here.