By Eric L.
09/08/2026 · 7 MIN READ

A VPN, or virtual private network, is an app that wraps everything your device sends online in an encrypted tunnel to a server run by the VPN provider.

Your Wi-Fi network and your internet provider see one encrypted connection to that server and nothing else. Websites see the server's address instead of yours. That's really all it does: it moves the point where your traffic stops being private, from your local network and your ISP over to a server you picked. Everything good and everything bad about VPNs falls out of that one move.

WHAT THE TUNNEL CHANGESFIG. 01
you → encryption → server → site
      ▲                  ▲
 network sees       site sees the
 one address        server address

[!] doesn't hide you from a site
    where you're logged in

What happens without a VPN

Open a website and your device asks a DNS (the internet's phone book) server, usually your ISP's, for the site's address. In plain text. Then it connects straight there. HTTPS encrypts the page itself, so nobody in the middle gets to read it. But your ISP, and whoever runs the Wi-Fi you're on, still sees the name of every site you visit, when you went there, and how much data moved. And the site sees your real IP address (your connection's number, like a house number), which hands over your country, city and provider. The full picture is in what can my ISP see.

WITHOUT A TUNNELFIG. 02
you → your ISP → the site
  └─ ISP sees: which site, when
  └─ site sees: your address, city
nothing here is hidden by HTTPS alone

HTTPS already covers part of this, and less than most people assume: what does the HTTPS padlock actually mean.

How a VPN works: what it changes

The app creates a virtual network interface on your device. Every packet from every app goes into it, gets encrypted, and heads out to the VPN server. The server decrypts it, hands it to the website, then encrypts the reply on the way back.

● WITHOUT A VPNYour deviceWi-Fi and ISPsee every site nameThe sitesees your real IP● WITH A VPNYour deviceWi-Fi and ISPone encrypted streamVPN serverdecrypts hereThe sitesees the server's IPthe seat movesWhether the provider writes any of it down is a policy question.
The tunnel doesn't remove the seat that sees your sites; it moves it to the VPN server.
  • Your network and ISP see an encrypted stream to one address. No site names, no DNS queries, no app traffic. Just how much data moved and the fact that you're on a VPN.
  • Websites see the VPN server's address. As far as they can tell, you're wherever that server is.
  • On public Wi-Fi, whoever's at the next table and the coffee shop's router both see the same encrypted stream, which closes every gap HTTPS leaves open.
WHAT SWITCHES, WHAT DOESN'TFIG. 03
changes      address, traffic, location
no change    accounts, cookies, fingerprint
The three that change are about your network position. The three that don't are about who already knows your name.

What actually gets swapped, what doesn't, and how to check it yourself: does a VPN hide your IP address.

How a VPN tunnel is built: authentication and encryption

Two things happen when you hit connect. First, your device and the server prove they are who they say they are, using keys or certificates, so nobody can pretend to be the server. Second, they agree on a session key and start encrypting with it. Those rules are what people mean when they say protocol (the rules two machines use to talk). WireGuard is the fast, simple, modern one. OpenVPN is the old workhorse. VLESS with Reality is built to make your tunnel look like a boring HTTPS connection to a boring website, which matters a lot on networks that block VPNs. The comparison is in WireGuard vs OpenVPN and what is VLESS.

WHAT HAPPENS WHEN YOU HIT CONNECTYour deviceVPN server1. Both prove who they arekeys or certificates, so nobody can fake the server2. They agree on a session keyand start encrypting with itencrypted tunnelTHOSE RULES ARE THE PROTOCOLWireGuardfast, simple, modernOpenVPNthe old workhorseVLESS + Realitylooks like boring HTTPS
Prove who you are, then agree on a key: a protocol is the set of rules for both steps.

It's TLS 1.3 with AES or ChaCha20. Yes, the same stuff your bank uses, which is a low bar in 2026 but a real one. There's no practical way to read any of it without the keys.

If the checks disagree with each other and you'd rather not untangle it yourself, hand the results to an AI along with your setup.

Prompt for an AI
Help me work out whether my VPN is doing its job.

What the check shows: IP address (which one),
country (which), DNS leak (yes / no / not sure),
WebRTC (shows a real address / shows nothing).
Device: (Android / iPhone / Windows / macOS).
App: (name).

Tell me which of these is normal and which is a
sign of a problem, and in what order to fix them.
If something is missing, ask for it rather than
assuming.

Check the answer against what's actually on your screen. Models are usually a version or two behind, and menus move around.

THREE LAYERS, THREE JOBSFIG. 04
HTTPS     the contents of a page
DNS       who learns the site names
tunnel    the route and the visible
          address
   └─ turned on separately, broken
      separately

What a VPN protects

  • Your traffic on shared and public networks.
  • The list of sites you visit, from your ISP and your local network.
  • Your IP address, from websites and from whoever's on the other end of a direct connection, like a call or a game.
  • Your accounts while traveling. Connecting to a server back home keeps your bank and your email from panicking about a login from another continent.
WHAT IS IN THE ENVELOPEFIG. 05
outside   the VPN server address
          packet size and timing
inside    the real destination
          the request, the cookies
   └─ the network forwards the
      envelope without opening it

What a VPN doesn't protect

  • The sites you log into. They know exactly who you are from your account, your cookies and your browser fingerprint (the traits that identify your browser), no matter what address you show up with.
  • You from phishing and malware. The tunnel carries whatever you hand it. It doesn't stop to ask whether that link looked sketchy.
  • You from the VPN provider. The server is where your traffic gets decrypted, so the provider lands in exactly the seat your ISP used to be in. Whether it writes any of that down is a policy question, and how to read one is in what does no logs mean.
  • Anything at all, if the tunnel leaks. DNS outside the tunnel, IPv6 outside the tunnel, or a dropped connection that quietly falls back to the open network will undo the whole thing. That's why a kill switch (no tunnel, no internet) and DNS inside the tunnel matter.
WHEN YOU NEED ONEFIG. 06
hotel and cafe Wi-Fi      yes
a network that filters    yes
reaching a work network   yes
your own home network     optional
wanting to be anonymous   wrong tool
Four rows are about which network you are on. The last one is about a promise no VPN was built to keep.

When do you need a VPN?

  • Any time you're on Wi-Fi you don't control: coffee shops, airports, hotels, offices.
  • When you'd rather your ISP didn't keep your browsing list.
  • When you're traveling, for banking and email.
  • On networks that inspect or throttle traffic.

At home on your own network the case is weaker. Your ISP still sees your site list, but nobody else is sitting on that network with you. Honestly, though, leaving it on everywhere is the right call for most people: the speed you give up is smaller than the odds you forget to flip it on in the one place it mattered. What that speed actually costs is in does a VPN slow down your internet.

And the thing a VPN isn't: an invisibility cloak. If you log into your own accounts through the tunnel, those accounts still know it's you. Anyone selling you total anonymity is selling you something else.

THREE CHECKS, ONE MINUTEFIG. 07
[ ] address changed to the server
[ ] DNS queries go through tunnel
[ ] WebRTC does not expose real IP
    └─ fail any one and the tunnel
       is only partly working

How to check your VPN is working

Once you're connected, open What Is My IP: the address and country should be the server's, not yours. Then run the WebRTC leak test and the IPv6 leak test, plus a DNS leak test. If all four come back showing only the server, you're good. The Is My VPN Working page runs them all at once. If one of them shows your real address, the tunnel is only half doing its job, and that's worth fixing before you trust it with anything.

404 VPN builds the tunnel with VLESS in its apps, keeps DNS inside it, blocks traffic during reconnects with a kill switch on Android, and publishes a privacy policy that lists what is and isn't stored. For Istanbul and Marseille it also offers WireGuard configs from the web dashboard, to use in the WireGuard app. The connection is described on the how it works page, and you can get started here.