By Eric L.
09/08/2026 · 7 MIN READ

A proxy changes your visible address for a single app and usually encrypts nothing.

A VPN encrypts all traffic from the device and sends it through one server you trust. Tor sends traffic through three volunteer-run relays so that no single point knows both who you are and where you're going, at a heavy cost in speed. They solve different problems: a VPN is the everyday tool for privacy and public Wi-Fi, Tor is for anonymity against a determined observer, and a proxy is for changing an address in one program without touching the rest.

AT A GLANCEFIG. 01
                      proxy VPN Tor
encrypts everything   ✗     ✓   ✓
one app only          ✓     ✗   ✗
hides from the ISP    ✗     ✓   ✓
stays fast            ✓     ✓   ✗
hides from the exit   ✗     ✗   ✓
The bottom row is the whole case for Tor: it is the only option where no single party learns both who you are and where you went.

VPN vs proxy vs Tor: who sees what

Your ISP or Wi-Fi seesThe service seesWebsites see
Nothingevery domain, timing, volumenoneyour real IP
HTTP/SOCKS proxyevery domain (DNS often bypasses the proxy)your IP and destinationsproxy IP
VPNone encrypted connection to the VPN serveryour IP and destinationsVPN IP
Torone encrypted connection to a Tor entry relayentry knows your IP, exit knows destination, neither knows bothexit relay IP

The row that surprises people is the proxy: DNS queries frequently go straight to the ISP even with a proxy configured, so the ISP keeps the list of sites while the sites see a different address. What the ISP sees in each case is broken down further in what can my ISP see.

WHO SEES WHATFIG. 02
          ISP sees    site sees
nothing   site names  your address
proxy     the proxy   proxy address
VPN       one server  server address
Tor       entry node  exit address
Every option still leaves somebody watching. Tor is the only one where no single party sees both your address and your destination.

What is a proxy?

A proxy is a server that forwards requests on your behalf. HTTP proxies handle web traffic; SOCKS5 proxies forward any connection. Neither encrypts by itself: whatever leaves the app unencrypted crosses the network unencrypted. Proxies are configured per app, so everything else on the device goes direct.

Use a proxy when you need a different address in one program, on a server for automation, or when speed matters more than privacy. Don't use a plain proxy on public Wi-Fi expecting protection; it doesn't provide any.

Modern "proxy protocols" such as VLESS blur the line: they encrypt traffic with TLS and, in TUN mode, capture the whole device like a VPN. In that mode the difference from a VPN is naming, not effect.

WHAT A PROXY ISFIG. 03
one application, not the device
often no encryption of its own
configured inside the program
   └─ close the program and you are
      back to a direct connection

What a VPN does differently

A VPN creates a virtual network interface and routes every app through an encrypted tunnel to one server. The ISP and local network see nothing but an encrypted stream; websites see the server's address. It's fast, works for all apps at once, and includes practical features: kill switch, DNS inside the tunnel, split tunneling.

The trade-off is trust. The VPN server decrypts your traffic and forwards it, so the provider is in the position the ISP was in. Whether it records anything is a policy question, covered in what does no logs mean. A VPN protects you from the network and the ISP; it doesn't make you anonymous to a provider that keeps logs or to a website you log into.

Use a VPN for public Wi-Fi, privacy from the ISP, appearing from your home country while traveling, and any everyday situation where speed matters.

WHAT A TUNNEL ISFIG. 04
the whole device, not one app
always encrypted
configured once
   └─ trust moves from your ISP
      to the server operator

What is Tor and how does it work?

Tor routes traffic through three relays chosen from thousands run by volunteers. The entry relay knows your IP but not your destination; the exit relay knows the destination but not your IP; the middle relay knows neither. Each hop is separately encrypted. Tor Browser adds a hardened browser that resists fingerprinting, which a VPN can't do, because fingerprinting happens in the browser, not the network.

THREE RELAYS: NO ONE KNOWS BOTH ENDSYouEntry relayMiddle relayExit relaySiteeach hop encrypted separatelyHTTPS essentialISP SEESTor in useKNOWSyour IPnot whereyou goKNOWSneithernot you,not the siteKNOWSthe sitenot whoyou areSEESexit IPThe exit relay can read anything that is not HTTPS. The price of three hops is speed.
No relay holds both your address and your destination, and past the exit only HTTPS keeps the content private.

The costs: speed is a fraction of a normal connection, many sites block or challenge Tor exit addresses, and the exit relay can see unencrypted traffic, so HTTPS is essential. Tor also stands out: the ISP can see that you're connecting to Tor, even if not what you do through it.

Use Tor when anonymity from a determined observer matters more than speed: research, whistleblowing, situations where linking your identity to your activity is the risk. It's the wrong tool for streaming, banking, or anything that needs your real identity anyway.

COMBINING THEMFIG. 05
tunnel then Tor   hides Tor use from
                  your ISP
Tor then tunnel   rarely what people
                  mean, and awkward
   └─ each extra hop costs speed and
      adds a thing that can break

Can you use a VPN and Tor together?

VPN, then Tor (VPN over Tor's entry): the ISP sees only a VPN connection, not Tor, and the Tor entry relay sees the VPN's address instead of yours. This is the common combination and it works with any VPN plus Tor Browser. It doesn't make Tor faster.

Tor, then VPN: rare, mostly useful to reach services that block Tor exits, and it requires a VPN provider that accepts connections from Tor. Not recommended for most people.

Proxy plus VPN: pointless unless the proxy is needed for an application-specific reason; the VPN already covers what the proxy would do.

CHOOSINGFIG. 06
one app, speed matters   proxy
the whole device         VPN
public Wi-Fi             VPN
anonymity is the goal    Tor
streaming and video      not Tor
Video is the case people get backward: reaching for Tor, the slowest and most anonymous option, is exactly the wrong move for it.

The three aren't interchangeable. Describe the actual task.

Prompt for an AI
Help me choose between a proxy, a VPN and Tor.

What I want to do: (describe the task).
How many apps are involved: (one / all of them).
Network I am on: (home / work / public Wi-Fi /
a country that filters).
Does speed matter: (yes / no).
Is anonymity the goal, or privacy: (which).

Say which tool fits and what it does not cover.
If my goal needs something none of the three
provides, say so plainly instead of picking the
closest one.

VPN, proxy or Tor: which to use

  • Banking, email, work, everyday browsing, public Wi-Fi: VPN.
  • Anonymity against someone who can watch both ends: Tor, with HTTPS, and no logins to real identities.
  • A different address in one program, speed first: proxy, ideally SOCKS5 with HTTPS destinations.
  • Not sure: VPN. It covers the proxy's use cases and most everyday privacy needs, and you can layer Tor Browser on top when a task calls for it.

Whatever you choose, verify it: after connecting, check What Is My IP and the WebRTC leak test, because a browser can reveal your real address through WebRTC regardless of proxy, VPN or Tor settings.

THE BROWSER CAN STILL GIVE YOU AWAYBrowserany setupProxy, VPN or TorWebsitesees the new addressWebRTCWebsitesees your real IPAFTER CONNECTING, CHECK BOTHWhat Is My IP shows the new addressWebRTC leak test is clean
Whichever of the three you use, the browser can still leak your real address, so test after connecting.

404 VPN is a VPN in the sense above: a VLESS tunnel for the whole device, DNS inside it, a kill switch on Android, split tunneling where you want exceptions, and a privacy policy that lists what is and isn't kept. For Istanbul and Marseille there are also WireGuard configs in the dashboard, and they too send all traffic and DNS into the tunnel. Get started here.