What Does a VPN Hide? (And What It Can't)

What Does a VPN Hide? (And What It Can't)

If you switch on a VPN expecting it to hide everything you do online, you're giving it more credit than it deserves. A VPN hides your real IP address, your IP-based location, and your browsing activity from your internet provider and whoever runs the Wi-Fi you're on. That's a genuine layer of privacy, but it isn't magic.

It doesn't hide what you do while logged in to an account, it doesn't stop cookies or browser fingerprinting, and it doesn't touch your phone's GPS. Without extra tools, it doesn't even hide the fact that you're using a VPN. Below, we break down what a VPN hides, who it hides it from and where the gaps are.

What a VPN hides:

  • Your real IP address and IP-based location, from websites and apps
  • The sites you visit, from your ISP, employer network or Wi-Fi owner
  • Your downloads and torrent traffic, from your ISP
  • The fact you use a VPN, but only with obfuscation

What a VPN doesn't hide:

  • What you do while signed in to Google, Facebook or other accounts
  • Cookies, trackers, your browser fingerprint and your GPS location
  • Your VPN connection and how much data you use
  • Your activity from a VPN provider that chooses to log it

What a VPN Hides

A VPN hides the contents and destinations of your traffic from everyone between your device and the VPN server. It wraps your connection in an encrypted tunnel, so your ISP, your router and anyone sniffing a café network see scrambled data headed to one address. Our explainer on how VPN encryption keeps your traffic unreadable covers the mechanics.

Diagram of a laptop sending traffic through an encrypted VPN tunnel past a home router and ISP to a VPN server, which connects out to websites using its own IP address.

Your IP Address

A VPN swaps your real IP address for the server's, so websites and apps see the VPN's address instead of yours. Your IP address is the number your ISP assigns to your connection, and websites use it to tie visits to a household.

There's one catch. Your ISP still knows your real IP, because it assigned it, and the VPN provider sees it when you connect. The sites on the other end can't see it, but not every party in the chain is shut out.

Your Location (IP-Based)

Websites that guess your location from your IP see the VPN server's city instead of yours. Connect to a server in Amsterdam, and a streaming service treats you as a visitor from the Netherlands. This only covers location worked out from your IP. GPS is a separate system, and we cover that gap below.

Your Browsing Activity From Your ISP

With a VPN on, your ISP can't see which sites you visit or what you search for. That matters, because an FTC staff report found many ISPs collect troves of personal data and combine browsing and app usage to target ads. The six providers it studied in 2021 covered about 98% of the US mobile internet market.

HTTPS already hides page content from your ISP: about 95% of Chrome page loads on Windows use it, and Chrome 154 turns on "Always Use Secure Connections" by default in October 2026. What HTTPS doesn't hide is the domain name and your DNS lookups (the requests that turn a site name into an address). A VPN hides those too. Our guide on whether your internet provider can see your history with a VPN goes deeper.

Your Traffic on Public Wi-Fi

On public Wi-Fi, a VPN hides your DNS requests, session cookies and data in transit from other people on the network and from whoever runs the hotspot. Whether you open your bank, your inbox or your social feeds, the router sees one encrypted stream headed to the VPN server. The router has no way to tell those sites apart.

Your Downloads and Torrenting

A VPN hides what you download, and the fact that you're using BitTorrent, from your ISP. Other peers in a swarm see the VPN's IP rather than yours. If you use qBittorrent, our walkthrough on binding your VPN to qBittorrent stops downloads from running outside the tunnel.

The Fact You're Using a VPN (With Obfuscation)

A standard VPN hides what you're doing, but not that you're using a VPN. Your ISP can tell a tunnel is in use even though it can't see inside it. Obfuscation, sometimes called stealth mode, makes the tunnel look like ordinary HTTPS traffic, which can help on networks that block VPNs. Our guide on how to make a VPN undetectable explains the options.

What a VPN Doesn't Hide

A VPN doesn't make you completely anonymous or invisible online. It changes your IP address and encrypts your connection, but much of your digital footprint travels through other channels. We look at those in our piece on whether you can be tracked when you use a VPN.

Your Activity When You're Logged In

Once you're signed in to Google, Facebook or Netflix, those services recognize you by your account, not your IP. The VPN changes nothing about what that account records. Your Google searches, your YouTube watch history and your Facebook likes attach to your profile regardless of which server you use.

Cookies, Trackers, and Browser Fingerprinting

Advertisers keep recognizing a browser behind a VPN through stored cookies and fingerprint details. Cookies are small files sites save on your device. Fingerprinting is different: a site reads details like your screen size, fonts and browser version, and combines them into an identifier without any cookies.

That identifier is surprisingly unique. EFF's 2010 Panopticlick study of around half a million browsers found 84% had unique configurations, rising to 94% among browsers with Flash or Java. EFF relaunched the tool in 2020, and the EFF's Cover Your Tracks test shows how unique your browser fingerprint is. Clearing cookies or using a tracker blocker matters as much as the IP swap.

Browser fingerprint test results listing screen resolution, fonts, time zone and browser version, with a line saying the browser has a unique fingerprint.

Your GPS Location

A VPN doesn't hide your GPS location. If you accept a browser's location prompt, you hand over your real position even with the VPN on, because HTML5 geolocation uses GPS and Wi-Fi rather than your IP. Apps with location permission read GPS directly.

Most VPNs don't try to spoof GPS. A few have added a location override on some platforms, but these add-ons come and go. The reliable fix is to deny location access to anything that doesn't need it.

Your VPN Connection and Data Usage

Your ISP and router can still see that you're connected to a VPN server, how much data you use, and when each session starts and ends. The home router sees one steady encrypted connection to a single server IP, just not the sites inside it. Carriers also count every megabyte, and the tunnel's overhead adds roughly 5 to 15% on top, depending on the protocol and what you're doing.

Data You Share With Sites and Apps

Anything you type into a form, post publicly or grant an app permission to read is outside the VPN's reach. Whatever you share, such as your name, email and payment details, goes to the service directly. A VPN can protect data on the way there, not after it arrives.

Your Activity From the VPN Provider

A VPN shifts trust from your ISP to the VPN provider, which sees your real IP and, if it chooses to log, where your traffic goes. That's why the no-logs policy matters more than any feature list.

Real-world cases show which policies hold. When Swedish police raided Mullvad in 2023, they left with no customer data, because none existed. Windscribe faced a Greek court case in 2025 where authorities found only billing data, and an ExpressVPN server seized in Turkey in 2017 produced nothing usable. Others failed: PureVPN handed connection timestamps and IP addresses to the FBI in 2017, and IPVanish produced user-specific logs in a 2016 case. Connection logs alone can identify you as well as browsing history can, so a "no activity logs" claim that still keeps them falls short.

Leaks That Can Expose You Anyway

A leak lets part of your traffic slip outside the tunnel, exposing your real IP or browsing even while the VPN shows as connected. Badly built apps leak most: a 2016 CSIRO Data61, UNSW and UC Berkeley study of 283 Android VPN apps found 18% didn't encrypt traffic at all and 38% contained some kind of malware.

Watch out

A VPN is not anonymity. If the connection drops without a kill switch, your traffic falls back to your normal connection and your real IP is exposed until you notice. Our explainer on what a VPN kill switch does shows why it should always be on.

DNS Leaks

A DNS leak sends your site lookups to your ISP's servers instead of the VPN's, so your ISP sees every domain you visit. In the same study, 66% of the apps leaked DNS queries. Windows is a common culprit: starting with Windows 8, Smart Multi-Homed Name Resolution sends DNS requests over all available adapters. See our explainer on what a DNS leak is for the background.

WebRTC Leaks

A WebRTC leak exposes your real IP through your browser rather than the VPN app. WebRTC is the browser feature behind video calls, and it can discover your ISP-assigned address, which any script on the page can read. Firefox, Chrome, Opera and Edge enable it by default. Our guide on what a WebRTC leak is covers each browser.

IPv6 Leaks

An IPv6 leak happens when your VPN tunnels older IPv4 traffic but lets IPv6 requests go out directly. The CSIRO researchers found 84% of those 283 apps leaked IPv6 traffic. Some providers route IPv6 through the tunnel or block it, while others ignore it.

Who Can See What With a VPN On

Here's how visibility breaks down across the parties who might be watching, assuming your VPN isn't leaking.

Which data your ISP, websites, network admin or employer, hackers on public Wi-Fi and VPN provider can see with a VPN on
Data ISP Websites Network admin or employer Hackers on public Wi-Fi VPN provider
IP address Visible (it assigned it) Hidden, sees VPN IP Visible on local network Hidden Visible
Sites visited Hidden Only its own site Hidden Hidden Visible unless no-logs
Page content Hidden Its own pages Hidden Hidden Hidden on HTTPS sites
DNS lookups Hidden unless leaking Not applicable Hidden unless leaking Hidden Visible if it runs DNS
Logged-in activity Hidden Visible Hidden Hidden Hidden on HTTPS sites
GPS location Not via VPN traffic Visible if you allow it Hidden Hidden Hidden
VPN use Visible, hidden with obfuscation Often detectable Visible, hidden with obfuscation Visible Visible
Data usage Visible Only its own traffic Visible Visible Visible

One caution on the employer column: it covers the network only. On a company-managed laptop or phone, monitoring software can end up seeing your activity before it ever enters the tunnel.

How to Check Your VPN Is Hiding What It Should

You can check your VPN in a few minutes with free tools, and it's the first check we run on any VPN before we trust it. Our full guide on how to test for DNS leaks walks through each site in detail.

Start with your IP. Run a what's-my-IP check with the VPN connected, and the page should show the VPN server's address. If it shows the same address as with the VPN off, the tunnel isn't working.

DNS is where most problems surface. Our quickest tell is to run a DNS leak test with the VPN off and then on: if the same ISP DNS servers appear both times, your lookups are leaking. We always follow up with the extended test on dnsleaktest.com, because it catches resolvers the standard test can miss. A clean result lists only servers owned by the VPN provider, and in our experience leaks show up more often on Windows PCs.

Extended DNS leak test results listing DNS servers, hostnames and countries that all belong to the VPN provider rather than the home internet provider.

Then check WebRTC. A WebRTC leak test can show your real ISP-assigned IP even while a normal IP check shows the VPN's, so one IP check isn't enough. Most VPN browser extensions don't stop WebRTC leaks on their own; the full desktop app or a browser setting does. Reputable paid VPNs generally pass, while failures cluster in free and poorly built apps.

Finally, look for IPv6. On ipleak.net, a leak shows up as your real IPv6 address while the IPv4 line shows the VPN server. Disabling IPv6 in your network adapter settings makes that leak impossible.

Tip

If a leak test fails, turn on the app's DNS leak protection and kill switch, switch protocol, or do a clean reinstall. For WebRTC, open uBlock Origin's settings and tick "Prevent WebRTC from leaking local IP addresses", which is off in most default installs.

Switching WebRTC off entirely also stops the leak, but it breaks browser video calls and screen sharing in Google Meet, Teams, Discord and Zoom's web client. If you don't need browser calls, open about:config in Firefox and set media.peerconnection.enabled to false.

How to Choose a VPN That Keeps Things Private

The right VPN for privacy has an audited no-logs policy, a privacy-friendly jurisdiction, a kill switch, built-in leak protection and obfuscation.

  • Independently audited no-logs policy. Look for recent third-party audits and, ideally, a raid or court order that tested it.
  • Jurisdiction. A provider based somewhere without mandatory logging, such as Switzerland, faces less legal pressure to keep records.
  • Kill switch. It blocks all traffic if the tunnel drops, so your real IP never slips out.
  • Leak protection. The app should use its own DNS servers and route or block IPv6.
  • Obfuscation and anonymous sign-up. Stealth mode helps on restrictive networks, and the less you hand over at checkout, the less links back to you.

Our roundup of the best VPNs for privacy ranks the options. If you want one name, Mullvad ticks every box above. You sign up with an account number and no email, it accepts cash and Monero, and it's based in Sweden. Cure53 gave its 2024 infrastructure audit a "very positive" verdict, and a 2025 pen test by Assured Security Consultants found no critical, high or medium issues. It costs €5 per month at a flat rate, with a 14-day refund window (except cash payments) and a 10% discount for cryptocurrency. Proton VPN is a strong alternative, with Swiss jurisdiction and a fifth consecutive Securitum no-logs audit in 2026.

Also recommended IPVanish logo
IPVanish
No-logs policy independently audited in 2022 and 2025, a kill switch, and unlimited simultaneous connections.

Other Ways to Close the Privacy Gaps

A VPN handles your network traffic, so the remaining gaps need other tools:

  • Use a tracker-blocking browser or extension to cut cookies and third-party trackers.
  • Clear cookies regularly, or keep separate browser profiles for work, shopping and personal accounts.
  • Stay logged out of Google and social accounts when you browse.
  • Deny location permission to sites and apps that don't need it.
  • Keep antivirus running, since a VPN doesn't scan files.
Smartphone privacy settings screen listing apps with location access set to Never, While Using or Always, with several apps switched to Never.

Bottom Line

A VPN hides your IP address, your IP-based location and your browsing from your ISP, your network admin and anyone snooping on public Wi-Fi. It won't hide what your accounts record, what cookies and fingerprinting reveal, or where your GPS says you are. Treat it as one strong layer of security, run a leak test after setup, and close the remaining gaps with a tracker blocker and tighter app permissions.

FAQ

Does a VPN hide you completely?
No. Your accounts, cookies, fingerprint and GPS still identify you. Anything close to anonymity also takes a hardened browser, separate identities and careful habits, and even then no single tool makes you invisible.
Can you be tracked with a VPN?
Yes. Beyond logins and fingerprints, anyone with access to your device can see what you do on it, and authorities can ask your VPN provider for records. That's why the audit history matters more than the marketing.
Can my employer or network admin see my activity with a VPN?
Partly. On a personal device, they see only the VPN connection. On a company-managed device, monitoring software records what you do before traffic reaches the tunnel, so assume your employer can see it.
Can websites like Netflix and Google tell I'm using a VPN?
Yes, often. Netflix shows error m7111-1331-5059 when it detects a VPN, and switching servers often clears it until that IP is blocklisted too. Google throws more CAPTCHAs, and sometimes an "unusual traffic" block, because hundreds of users share each server IP. Banks flag shared IPs as well; a dedicated IP usually stops the lockouts.
Does a VPN hide my search history or delete my browsing history?
No. A VPN doesn't touch anything stored on your device, so your browser history stays until you clear it. If you're signed in to Google, searches are also saved to your account activity, which you delete in your account settings.
Does incognito mode hide my IP address?
No. Incognito only stops your browser saving history and cookies on your device. Your ISP and the sites you visit still see your real IP. Our guide on using a VPN in incognito mode explains how the two work together.
Does a VPN hide my MAC address?
No. A VPN doesn't change your MAC address, the hardware ID of your network adapter. It stays on the local network side of the connection, where your router and nearby devices can see it.
Can a Wi-Fi owner see the sites I visit?
Partly. Without a VPN, they can log the domains you visit through DNS requests, even on HTTPS sites. With a VPN, they see only the connection to the server, though your device still appears on their router's list of connected devices.
Does a VPN protect you from malware and phishing?
No. A VPN does nothing against a phishing link or a malicious download, because it doesn't scan files. You still need antivirus and a healthy suspicion of unexpected links.