A VPN, or virtual private network, is an app that wraps everything your device sends online in an encrypted tunnel to a server run by the VPN provider.
Your Wi-Fi network and your internet provider see one encrypted connection to that server and nothing else. Websites see the server's address instead of yours. That's really all it does: it moves the point where your traffic stops being private, from your local network and your ISP over to a server you picked. Everything good and everything bad about VPNs falls out of that one move.
you → encryption → server → site ▲ ▲ network sees site sees the one address server address [!] doesn't hide you from a site where you're logged in
What happens without a VPN
Open a website and your device asks a DNS (the internet's phone book) server, usually your ISP's, for the site's address. In plain text. Then it connects straight there. HTTPS encrypts the page itself, so nobody in the middle gets to read it. But your ISP, and whoever runs the Wi-Fi you're on, still sees the name of every site you visit, when you went there, and how much data moved. And the site sees your real IP address (your connection's number, like a house number), which hands over your country, city and provider. The full picture is in what can my ISP see.
you → your ISP → the site └─ ISP sees: which site, when └─ site sees: your address, city nothing here is hidden by HTTPS alone
HTTPS already covers part of this, and less than most people assume: what does the HTTPS padlock actually mean.
How a VPN works: what it changes
The app creates a virtual network interface on your device. Every packet from every app goes into it, gets encrypted, and heads out to the VPN server. The server decrypts it, hands it to the website, then encrypts the reply on the way back.
- Your network and ISP see an encrypted stream to one address. No site names, no DNS queries, no app traffic. Just how much data moved and the fact that you're on a VPN.
- Websites see the VPN server's address. As far as they can tell, you're wherever that server is.
- On public Wi-Fi, whoever's at the next table and the coffee shop's router both see the same encrypted stream, which closes every gap HTTPS leaves open.
changes address, traffic, location no change accounts, cookies, fingerprint
What actually gets swapped, what doesn't, and how to check it yourself: does a VPN hide your IP address.
How a VPN tunnel is built: authentication and encryption
Two things happen when you hit connect. First, your device and the server prove they are who they say they are, using keys or certificates, so nobody can pretend to be the server. Second, they agree on a session key and start encrypting with it. Those rules are what people mean when they say protocol (the rules two machines use to talk). WireGuard is the fast, simple, modern one. OpenVPN is the old workhorse. VLESS with Reality is built to make your tunnel look like a boring HTTPS connection to a boring website, which matters a lot on networks that block VPNs. The comparison is in WireGuard vs OpenVPN and what is VLESS.
It's TLS 1.3 with AES or ChaCha20. Yes, the same stuff your bank uses, which is a low bar in 2026 but a real one. There's no practical way to read any of it without the keys.
If the checks disagree with each other and you'd rather not untangle it yourself, hand the results to an AI along with your setup.
Help me work out whether my VPN is doing its job.
What the check shows: IP address (which one),
country (which), DNS leak (yes / no / not sure),
WebRTC (shows a real address / shows nothing).
Device: (Android / iPhone / Windows / macOS).
App: (name).
Tell me which of these is normal and which is a
sign of a problem, and in what order to fix them.
If something is missing, ask for it rather than
assuming.
Check the answer against what's actually on your screen. Models are usually a version or two behind, and menus move around.
HTTPS the contents of a page
DNS who learns the site names
tunnel the route and the visible
address
└─ turned on separately, broken
separatelyWhat a VPN protects
- Your traffic on shared and public networks.
- The list of sites you visit, from your ISP and your local network.
- Your IP address, from websites and from whoever's on the other end of a direct connection, like a call or a game.
- Your accounts while traveling. Connecting to a server back home keeps your bank and your email from panicking about a login from another continent.
outside the VPN server address
packet size and timing
inside the real destination
the request, the cookies
└─ the network forwards the
envelope without opening itWhat a VPN doesn't protect
- The sites you log into. They know exactly who you are from your account, your cookies and your browser fingerprint (the traits that identify your browser), no matter what address you show up with.
- You from phishing and malware. The tunnel carries whatever you hand it. It doesn't stop to ask whether that link looked sketchy.
- You from the VPN provider. The server is where your traffic gets decrypted, so the provider lands in exactly the seat your ISP used to be in. Whether it writes any of that down is a policy question, and how to read one is in what does no logs mean.
- Anything at all, if the tunnel leaks. DNS outside the tunnel, IPv6 outside the tunnel, or a dropped connection that quietly falls back to the open network will undo the whole thing. That's why a kill switch (no tunnel, no internet) and DNS inside the tunnel matter.
hotel and cafe Wi-Fi yes a network that filters yes reaching a work network yes your own home network optional wanting to be anonymous wrong tool
When do you need a VPN?
- Any time you're on Wi-Fi you don't control: coffee shops, airports, hotels, offices.
- When you'd rather your ISP didn't keep your browsing list.
- When you're traveling, for banking and email.
- On networks that inspect or throttle traffic.
At home on your own network the case is weaker. Your ISP still sees your site list, but nobody else is sitting on that network with you. Honestly, though, leaving it on everywhere is the right call for most people: the speed you give up is smaller than the odds you forget to flip it on in the one place it mattered. What that speed actually costs is in does a VPN slow down your internet.
And the thing a VPN isn't: an invisibility cloak. If you log into your own accounts through the tunnel, those accounts still know it's you. Anyone selling you total anonymity is selling you something else.
[ ] address changed to the server
[ ] DNS queries go through tunnel
[ ] WebRTC does not expose real IP
└─ fail any one and the tunnel
is only partly workingHow to check your VPN is working
Once you're connected, open What Is My IP: the address and country should be the server's, not yours. Then run the WebRTC leak test and the IPv6 leak test, plus a DNS leak test. If all four come back showing only the server, you're good. The Is My VPN Working page runs them all at once. If one of them shows your real address, the tunnel is only half doing its job, and that's worth fixing before you trust it with anything.
404 VPN builds the tunnel with VLESS in its apps, keeps DNS inside it, blocks traffic during reconnects with a kill switch on Android, and publishes a privacy policy that lists what is and isn't stored. For Istanbul and Marseille it also offers WireGuard configs from the web dashboard, to use in the WireGuard app. The connection is described on the how it works page, and you can get started here.