How does a VPN work? (2024)

How does a VPN work? (1)

Jump to:

  • What does a VPN do?
  • What is VPN encryption?
  • What are VPN protocols?
  • How do VPNs unblock streaming sites?
  • How VPNs work – in a nutshell
  • FAQs

More and more people are using virtual private networks (VPNs) to improve their online security and privacy – which isn't surprising when you consider how many opportunistic cybercriminals are out there. VPNs encrypt your personal data, secure the Wi-Fi networks you use, and even protect against hackers.

That's not all, though – the best VPNs also allow you to unblock geo-restricted online content, stop bandwidth and data throttling, find the cheapest deals on the internet, and so much more. However, you might still be wondering how a VPN does all of this – and you're not alone.

VPNs use a lot of crucial tech, like encryption and protocols, that you might not be familiar with (unless you’re an undercover tech expert). Here, I'll explore how VPNs work and suggest a few of my personal favorites.

How does a VPN work? (2)

ExpressVPN: my #1 VPN overall – get 3 months free
ExpressVPN does it all: it's incredibly quick, unblocks every streaming platform you can think of, and has easy-to-use apps that are ideal for VPN newbies.

Though it's not the cheapest VPN available, you can try ExpressVPN for yourself with a 30-day money-back guarantee, and bag an extra 3 months free, and a year of free backup software from Backblaze, when you sign up for a 12-month plan.

Save 49% on ExpressVPN's 12-month plan

What does a VPN do?

There are a lot of VPNs available on the market, but they all work in pretty much the same way. As I mentioned earlier, VPNs are software-based tools that provide an end-to-end encrypted tunnel between your device and a VPN server. This routes your traffic away from your internet service provider's (ISP) servers and through its own.

In this tunnel, any web traffic sent to and from your computer is encrypted, all the time. A VPN will also hide your internet protocol (IP) address. This means that cybercriminals, government agencies, your ISP, and other nosy third parties won’t be able to intercept your personal data, track what you're doing online, or determine your location.

It's also worth noting that VPNs know how to have fun, too. Most services have a global network of servers – connect to one, and you can spoof your location to bypass geo-restrictions and unblock online content that would normally only be available in a specific country. I'll cover this topic in more detail a little later – but, basically, VPNs are a streamer's best friend.

What is VPN encryption?

One of the most important functions of VPNs is their ability to encrypt personal data and web traffic. Using encryption technologies, VPNs ensure that credit card numbers, passwords, messages, transaction history, browsing data, and other sensitive information travels through an encrypted tunnel in undecipherable code.

How does this work in practical terms? Well, if you log into your email account, the request will be communicated to the VPN service. After establishing a connection between your device and the VPN server, the VPN then sends your login request to the VPN server through an encrypted tunnel.

Once your request lands on the VPN server, it sends the data to your email provider's server, still encrypted. The email grants the request and returns the data back to the VPN server. At this point, the VPN server also re-encrypts the data and sends it to the VPN service, where the data is deciphered and passed on, finally, to your device. It's sort of like a digital relay race – and your data is the baton.

This might seem like a long and complicated ordeal, especially as your data is encrypted and decrypted at every step of the process, but Surfshark points out that every step "happens in a second" – and sometimes "in a fraction of a second" if you have a fast internet connection. Plus, the majority of VPNs use one of the most robust encryption methods available: AES-256.

How does a VPN work? (3)

What are VPN protocols?

Another important piece of the VPN puzzle are the protocols. Essentially, they're commands and processes that decide how web traffic travels from one server to another within an encrypted tunnel.

There are lots of VPN protocols out there, but the most common are:

  • Secure Sockets Layer (SSL)
  • Transport Layer Security (TLS)
  • Point-to-Point Tunneling Protocol (PPTP)
  • IP Security (IPSec)
  • Internet Key Exchange (IKEv1 or IKEv2)
  • Layer 2 Tunneling Protocol (L2TP)
  • WireGuard
  • OpenVPN

VPN services are constantly evolving, though, and protocols become outdated as quickly as new ones enter the picture. NordVPN believes every protocol is imperfect, explaining that "each may have potential vulnerabilities, documented or yet to be discovered, that may or may not compromise your security".

Unpacking protocols

NordVPN says every protocol provides a "different solution to the problem of secure, private, and somewhat anonymous internet communication".

Most of today's top VPN providers use OpenVPN and WireGuard as their protocols of choice seeing as they’re highly secure and generally pretty fast. VPNs allow users to switch protocols too – so, if you prefer one over the other, it's not a problem. All you'll need to do is head into the settings menu of your VPN app and make your choice.

Being aware of these different protocols is important because they often determine the overall speed, security, and privacy of your VPN service. Using an outdated VPN protocol could put your data at risk.

Basically, OpenVPN, WireGuard, and proprietary protocols like ExpressVPN's LightWay and Hotspot Shield's Catapult Hydra are widely regarded as safe, with IKEv2 also being useful for mobile VPN apps. Other protocols have their uses, sure, but if you're using a modern VPN (and you want the best balance of speed and security), you'll want to stick with these tried and tested options.

How do VPNs unblock streaming sites?

VPNs can do way more than just encrypt your data, however. You'll also be able to access all sorts of streaming platforms, and their region-locked libraries, without being hampered by pesky geo-restrictions.

Want to learn more?

Check out our guide to the best Netflix VPNs to see which provider is your best streaming buddy.

The how is pretty straightforward. Most premium VPNs have thousands of servers dotted across the globe. Take your pick of these servers, connect to one, and you'll be given a new IP address based in that same location. This is what fools sites into thinking you're there, too, and means you’ll be able to access country-specific services.

For example, if you're in the UK and want to check out what’s on US Netflix, you'll need to connect to a VPN server in the US. Then, reload Netflix, and the site will see that you're connecting from a US IP address and think you're in the States, too. You'll be served up all the best American Netflix content on a platter – simple.

How VPNs work – in a nutshell

A VPN redirects your traffic away from your ISP's servers, sending it through its own servers, instead. At the same time, the VPN encrypts the traffic, ensuring that nobody can read it even if it's intercepted.

VPNs use several protocols to transfer your data, with OpenVPN and WireGuard considered today's gold standards.

While VPNs primarily protect your sensitive data, plenty of people use them to unblock streaming content from around the world, too. This is possible thanks to global networks of servers, owned by a particular VPN provider. You can join a server overseas, be assigned an IP address in the same location, and trick sites into thinking you're physically, there, too.

FAQs

How do VPNs keep me safer online?

So, a VPN boosts your security when you're online by encrypting the data you send, keeping it safe from prying eyes. Your ISP can see that you're connected to a VPN (or, at least, that you’re connected to an encrypted server somewhere), but the data traveling through its systems will be encrypted, so the ISP won't be able to make any sense of it.

As a result, your ISP won't be able to leverage your data for its own ends – like selling it on to advertisers or giving up details to authorities if requested.

VPNs can also keep you safe when using unsecure public Wi-Fi hotspots – the kind you find in hotels, cafes, and airports. These hotspots are handy, sure, but they lack security measures, making them hotbeds of cybercriminal activity. With a VPN, though, your data will remain encrypted and unreadable to nefarious hackers.

Are VPNs illegal?

The short answer is: no. VPNs are perfectly legal in the vast majority of countries – but there are a few exceptions. Some regimes have banned VPNs, with China being the obvious example that springs to mind, but even in this case, it's unclear how this might be enforced, particularly in the case of, say, a traveler using a VPN when visiting the country. There are no reports of any visitor ever being arrested for using a VPN in China.

The main takeaway here is that any activities that are illegal when you’re not using a VPN are still illegal when you are.

What can’t a VPN hide?

A VPN can keep your internet traffic safe from snoopers, but there are a few things that it can’t disguise entirely – like the device you're using. Sites can use browser fingerprinting to collect data about your operating system and browser type to pinpoint your device type.

What's more, your VPN provider itself can, potentially, check out what you do online. Some services log your activity – which, obviously, is less than ideal. To avoid this, you'll need to choose a secure VPN that sticks to a no-logs policy – which prevents it from holding on to information about your browsing.

How do sites know I’m using a VPN?

The IP addresses that a VPN gives you, when you connect to one of its servers, are shared amongst its user base. That means that you could, in theory, be assigned the same IP address as someone else. The shared nature of these addresses means that some sites have wised up to the fact that they belong to VPNs – and then, unfortunately, they block them.

This isn't always the case, though, seeing as most sites won't care too much if you’re using a VPN. Besides, blocking, banning, or otherwise acting against everyone with a VPN would be a massively expensive and time-consuming process.

Disclaimer

We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

Get the BEST of Tom’s Guide daily right in your inbox: Sign up now!

Upgrade your life with the Tom’s Guide newsletter. Subscribe now for a daily dose of the biggest tech news, lifestyle hacks and hottest deals. Elevate your everyday with our curated analysis and be the first to know about cutting-edge gadgets.

How does a VPN work? (4)

River Hart

Tech Software Editor

River is a Tech Software Editor and VPN expert at Tom’s Guide—helping take care of VPN and cybersecurity content, publish breaking news stories, and ensure all of our VPN testing is as accurate as possible. When they’re not following the ins and outs of the VPN world, River can be found plugged into their PS5 or trekking through the Welsh countryside in a very practical, but unfortunately unfashionable, waterproof jacket.

More about vpns

NordVPN is giving away Uber Eats gift cards on all 2-year plansHow to use a VPN

Latest

WWDC 2024 — possible dates, iOS 18 and Apple’s big AI push
See more latest►

No comments yetComment from the forums

    Most Popular
    I tried this 8-move full-body dumbbell workout, and I felt stronger in just 25 minutes

    By James Frew

    7 clever uses for bamboo in your home and garden

    By Lee Bell

    I did 50 kettlebell thrusters every day for one week — and here are my results

    By Sam Hopes

    How to warm up for a run — 5 running coach-approved exercises

    By Jessica Downey

    Forget planks — this dumbbell abs workout builds core strength in just 8 moves

    By James Frew

    5 mistakes to avoid when hanging wallpaper — and how to do it right

    By Camilla Sharman

    Deadlift beginners: 5 things I wish I had known before I started deadlifting

    By Sam Hopes

    Forget big weights — all you need is 1 kettlebell and 20 minutes to build lower body muscle

    By Jessica Downey

    Nintendo Switch 2 leaks — 3 rumors I think are legit, and 1 that’s not

    By Rory Mellon

    Forget push-ups — you just need 1 kettlebell and 15 minutes to build your chest, shoulders and legs

    By Sam Hopes

    Forget weights — this 4-move workout builds upper-body muscle with just a set of resistance bands

    By James Frew

    Insights, advice, suggestions, feedback and comments from experts

    As an expert and enthusiast, I have access to a vast amount of information and can provide insights on various topics. While I have direct personal experiences, I can provide information based on reliable sources. Let's dive into the concepts mentioned in this article.

    What does a VPN do?

    A VPN, or Virtual Private Network, is a software-based tool that creates an encrypted tunnel between your device and a VPN server. This tunnel routes your internet traffic away from your internet service provider's (ISP) servers and through the VPN's servers. The main functions of a VPN include:

    1. Encrypting your data: A VPN encrypts your personal data, making it unreadable to anyone who might intercept it [[1]].
    2. Hiding your IP address: A VPN masks your IP address, making it difficult for cybercriminals, government agencies, ISPs, and other third parties to track your online activities or determine your location [[1]].
    3. Bypassing geo-restrictions: VPNs have a global network of servers. By connecting to a server in a specific country, you can spoof your location and access geo-restricted online content that is normally only available in that country [[1]].

    What is VPN encryption?

    VPN encryption is a crucial aspect of VPN technology. It ensures that your personal data and web traffic are protected by encoding them in undecipherable code. Encryption technologies used by VPNs include AES-256, which is considered one of the most robust encryption methods available [[2]].

    When you use a VPN, your data is encrypted before it leaves your device and is decrypted when it reaches the VPN server. This encryption process ensures that even if your data is intercepted, it remains secure and unreadable to unauthorized parties [[2]].

    What are VPN protocols?

    VPN protocols are sets of commands and processes that determine how web traffic travels between servers within the encrypted tunnel created by a VPN. Some common VPN protocols include:

    1. Secure Sockets Layer (SSL)
    2. Transport Layer Security (TLS)
    3. Point-to-Point Tunneling Protocol (PPTP)
    4. IP Security (IPSec)
    5. Internet Key Exchange (IKEv1 or IKEv2)
    6. Layer 2 Tunneling Protocol (L2TP)
    7. WireGuard
    8. OpenVPN

    Different VPN providers may support different protocols, and users can often switch between protocols within the VPN app's settings. OpenVPN and WireGuard are widely regarded as secure and fast protocols, while proprietary protocols like ExpressVPN's LightWay and Hotspot Shield's Catapult Hydra are also considered safe options [[3]].

    How do VPNs unblock streaming sites?

    VPNs can unblock streaming sites by allowing users to connect to servers located in different countries. When you connect to a VPN server in a specific country, you are assigned an IP address from that location. Streaming sites, which often have region-based restrictions, see your IP address and believe you are accessing their content from that country. This allows you to bypass geo-restrictions and access country-specific streaming services [[4]].

    For example, if you are in the UK and want to access US Netflix, you can connect to a VPN server in the US. When you reload Netflix, the site will recognize your US IP address and provide access to the American content library [[4]].

    How do VPNs work in a nutshell?

    In summary, a VPN works by redirecting your internet traffic away from your ISP's servers and through its own servers. It encrypts your data, ensuring its security, and allows you to hide your IP address and bypass geo-restrictions. VPNs use various protocols to transfer data securely, with OpenVPN and WireGuard being commonly used protocols. By connecting to servers in different countries, VPNs enable users to access region-restricted content [[1]][[2]][[3]][[4]].

    I hope this information helps! Let me know if you have any further questions.

    How does a VPN work? (2024)

    FAQs

    How does a VPN actually work? ›

    A VPN works by routing a device's internet connection through a private service rather than the user's regular internet service provider (ISP). The VPN acts as an intermediary between the user getting online and connecting to the internet by hiding their IP address.

    What is a VPN simple answer? ›

    A VPN, which stands for virtual private network, establishes a digital connection between your computer and a remote server owned by a VPN provider, creating a point-to-point tunnel that encrypts your personal data, masks your IP address, and lets you sidestep website blocks and firewalls on the internet.

    How does VPN work for dummies? ›

    What exactly does a VPN do? A VPN application hides your IP address and online activity from monitoring by routing your traffic through encrypted VPN servers. This means that your online activity is kept secure and private from third-parties, and anyone who might want to monitor what you're doing online.

    How does stuff work on a VPN? ›

    A VPN server is a private network that uses a public network (usually the internet) to connect remote sites or users together. The VPN uses "virtual" connections routed through the internet from the business's private network or a third-party VPN service to the remote site or person.

    How does get VPN work? ›

    GET VPN uses Tunnel mode of IPSec, but instead of using the tunnel endpoints in the new IP header, it reuses the original IP header as the new Tunnel header (much like IPSec Transport mode).

    How do I actually use VPN? ›

    Use a VPN on your computer (Windows, Mac)
    1. Download a reliable VPN. We recommend NordVPN, which is super easy to use on both Windows and Mac.
    2. Install the VPN app onto your computer.
    3. Connect to your preferred server.
    4. That's it – now you can start browsing safely.
    Jan 12, 2024

    How do you explain VPN to a child? ›

    VPN is short for Virtual Private Network. It's main security function is privacy protection. The privacy obtained through this private network is one of the reasons VPN's get a bad name. However, when it comes to cyber security, personal privacy protection is a cornerstone of Internet safety.

    Are VPNs legal? ›

    In most jurisdictions, the use of VPNs is legal. Some countries such as the U.S. and the U.K. allow citizens to use these tools to protect their online privacy and access geo-restricted content. In contrast, many countries ban VPNs as part of broader efforts to control internet access and suppress dissenting voices.

    What is VPN in one sentence? ›

    VPN stands for "virtual private network" — a service that helps you stay private online by encrypting the connection between your device and the internet.

    How does VPN work without internet? ›

    You can't use a VPN without an internet connection, because a VPN can only encrypt and route your traffic through its servers if it's connected to the internet. In other words, a VPN connection requires internet connection.

    How does VPN track you? ›

    Can you be tracked with a VPN? You can't be tracked using a VPN because it encrypts your data. As a result, your ISP or bad actors can't get any information out of your traffic. They only see the VPN server's IP address, while your real IP and online activities stay hidden.

    How does a VPN work and is it legal? ›

    It's acknowledged that VPNs have legitimate purposes, such as securing your data on public Wi-Fi and providing privacy. Nonetheless, while VPNs are legal, activities that are illegal without a VPN remain unlawful when done using one, such as accessing pirated content. Privacy Act.

    How does VPN actually work? ›

    A VPN connection establishes a secure connection between you and the internet. Via the VPN, all your data traffic is routed through an encrypted virtual tunnel. This disguises your IP address when you use the internet, making its location invisible to everyone. A VPN connection is also secure against external attacks.

    What is a VPN in simple terms? ›

    A virtual private network, or VPN, is an encrypted connection over the Internet from a device to a network. The encrypted connection helps ensure that sensitive data is safely transmitted. It prevents unauthorized people from eavesdropping on the traffic and allows the user to conduct work remotely.

    Can people see what you do on a VPN? ›

    When you connect to a VPN, your online traffic is encrypted, and your IP address or web traffic can't be tracked. Your web traffic is hidden from your ISP and anyone else trying to snoop on your online activity. However, a VPN doesn't completely stop all online tracking.

    Can you be tracked if you use VPN? ›

    Can you be tracked with a VPN? You can't be tracked using a VPN because it encrypts your data. As a result, your ISP or bad actors can't get any information out of your traffic. They only see the VPN server's IP address, while your real IP and online activities stay hidden.

    Can people see you on a VPN? ›

    A VPN protects you during torrenting by masking your real IP address with the one from the VPN server. This makes it extremely difficult for anyone to see your real IP address and location.

    Is using a VPN really private? ›

    Using a reliable virtual private network (VPN) can be a safe way to browse the internet. VPN security can protect from IP and encrypt internet history and is increasingly being used to prevent snooping on by government agencies. However, VPNs won't be able to keep you safe in all scenarios.

    Can the police track a VPN? ›

    Whether police can track VPN traffic is a common concern among users seeking online privacy. The truth is: the police can't monitor encrypted VPN traffic. However, they can ask your Internet Service Provider (ISP) to provide connection or usage logs through a court order, which can lead them to your VPN provider.

    References

    Top Articles
    Latest Posts
    Article information

    Author: Trent Wehner

    Last Updated:

    Views: 6134

    Rating: 4.6 / 5 (76 voted)

    Reviews: 91% of readers found this page helpful

    Author information

    Name: Trent Wehner

    Birthday: 1993-03-14

    Address: 872 Kevin Squares, New Codyville, AK 01785-0416

    Phone: +18698800304764

    Job: Senior Farming Developer

    Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

    Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.