By Eric L.
09/12/2026 · 7 MIN READ

A VPN server is an ordinary computer in a data center that does one job: it accepts encrypted connections from your device, unwraps them, and sends the traffic on to the internet under its own address.

Everything a VPN does for you happens because that machine sits between you and the sites you open. Understanding it is the fastest way to understand what a VPN can and can't do, because almost every limit comes from the fact that some specific box, in some specific country, run by some specific company, is doing the forwarding.

WHERE THE SERVER SITSFIG. 01
you → your ISP → VPN server → the site
  └─ encrypted ──┘
                 └─ plain, from the
                    server onward

How a VPN server works

Four things, in order, for every packet you send.

FOUR JOBS, EVERY PACKETVPN SERVER1Terminates the tunneldecrypts with the agreed keys2Rewrites the source addresssites see the server, not you3Resolves domain namesif the client is set up right4Sends the reply backthrough the same tunnelYour deviceencryptedboth waysplain, fromits addressThe site
There is no skipping step one: your traffic is readable inside the server while it is forwarded.

It terminates the tunnel. Your device and the server agreed on keys when you connected. The server uses them to decrypt what arrives, which means the traffic exists in readable form inside that machine for the moment it's being forwarded. There's no way around this: something has to put your request onto the public internet, and that something has to know where it's going.

It rewrites the source address. Your packet leaves the server carrying the server's address, not yours. This is why sites see a different country. It's also why many customers share one address: the server keeps a table of who asked for what so replies come back to the right person.

It resolves domain names, if your client is set up properly. When you open a site, something has to turn the name into an address. A correctly configured tunnel does that lookup on the server side, so your own network never sees the list of names. When it doesn't, you get a DNS leak: the tunnel carries your traffic while your provider still collects your browsing list. How to check that is in is my DNS leaking.

It sends the reply back through the same encrypted tunnel.

WHAT THE SERVER NECESSARILY SEESFIG. 02
your real address         sees it
which sites you open      sees it
timing and volume         sees it
contents under HTTPS      does not
your passwords            does not
The gap survives no matter which provider you pick: it's built into what encryption can hide.

Why VPN server location decides your speed

Every packet makes a detour through the server. That detour is physical distance, and distance is time.

THE DETOUR YOU PAY FORFIG. 03
direct     you ────────► site
tunnelled  you ──► server ──► site
   └─ if the server is far and the
      site is near, you pay twice

A server in your own country adds a few milliseconds. A server on another continent can add a hundred or more, and that shows up as pages pausing before they load rather than as a lower speed number. The distinction matters because the two are fixed differently, and does a VPN slow down your internet walks through which is which.

WHAT THE DISTANCE COSTSFIG. 04
same country              ||
neighboring country       ||||
another continent         ||||||||||
The bars track latency added by distance, not bandwidth: a longer bar means more delay, not a slower connection.

Shared vs dedicated VPN servers

Most servers carry many customers behind one address. That's usually what you want: your traffic is one stream among many, and nothing about it stands out. The cost is that one abusive customer can get the address blocked for everyone on it, which is why a service sometimes works everywhere except the one site you needed.

A dedicated address solves the blocking problem and creates a different one: that address is yours alone, so it identifies you as reliably as your home address would. Dedicated versus shared IP covers the trade in full.

SHARED OR DEDICATEDFIG. 05
shared     blends into a crowd
           a neighbor's abuse can block it
dedicated  never blocked by others
           but always, unmistakably you
The same anonymity that hides you in a crowd is what lets one neighbor's abuse get the whole crowd blocked.

Who runs the server matters more than what it runs

The software isn't the interesting part. WireGuard, VLESS and the rest are public, documented and largely interchangeable from the user's side. What differs between services is who operates the machine, under which country's law, and what they write down.

That isn't a technicality. The server sees your real address and your list of destinations because it has to. Whether that gets stored, for how long, and who can compel its disclosure are decisions made by people, not by the protocol. What "no logs" actually means is about exactly this gap between what a machine can see and what a company chooses to keep.

THE TRUST SIMPLY MOVESFIG. 06
no tunnel    your ISP holds the list
tunnel       the server operator does
The question was never whether someone can see the list, only whom you would rather have holding it.

Running your own VPN server

You can rent a small machine and be your own operator. The appeal is obvious: nobody else holds the list. The costs are just as real. You become responsible for updates, for the firewall, for fixing it when it breaks at an inconvenient hour, and you get an address used by exactly one person, which is easier to notice, not harder. Your own server versus a service does the honest arithmetic.

● YOU GAINNobody elseholds the listyou are the operator● YOU TAKE ONUpdatesyours to installThe firewallyours to configureFixing it when it breaksat an inconvenient hourAn address used by one personeasier to notice, not harder
Nobody else holds the list, but the operator's work is now yours, and your address is easier to notice.

If you're weighing it, describe your actual situation rather than reading a general comparison.

Prompt for an AI
Help me decide whether to run my own VPN server.

Why I want a tunnel: (privacy on untrusted
networks / reaching a work network / getting
around filtering / all of it).
My experience: (I use Linux and SSH / I have read
about it / none).
How many devices: (how many).
Time I will spend maintaining it: (none / a couple
of hours a month / I would enjoy it).
Where I need the exit to be: (country).

Work out honestly what I gain and lose either way
with those answers.
Do not talk me into self-hosting if my answers say
I would not maintain it.

Treat the answer as a starting point, not a verdict: the model can't know how much an outage on a Sunday would actually cost you.

How to tell which server you're on

CHECKING THE SERVER YOU GOTFIG. 07
[ ] the address check shows its country
[ ] DNS resolves inside the tunnel
[ ] latency roughly matches that distance
[ ] switching servers changes the address
The first two boxes catch the two failures that actually happen: a different server than you picked, or DNS leaking outside the tunnel.

If the country is wrong, the client picked a different server than you think. If DNS still shows your own provider, the tunnel is carrying traffic but not names. Both are common and both are fixable.

What a VPN server can't do

It changes where your traffic appears to come from, and who can watch it on the way. It doesn't log you out of anything, doesn't clear your cookies, and doesn't change your browser's fingerprint. Sites that knew you before still know you, because they recognize the account and the browser rather than the address. That boundary is the same one described in what is a VPN, and it's worth keeping in mind before blaming a server for something no server handles.

● A SERVER CHANGESWhere your trafficappears to come fromWho can watch iton the way● IT DOES NOT TOUCHYour loginsYour cookiesYour browser fingerprintSites that knew you before still know you: they recognize the accountand the browser, not the address.
A new address does not make you a stranger to sites that already know your account and browser.