People search how a VPN works after a café, a landlord Wi-Fi, or a billboard that promised invisibility. The packet capture is calmer. A virtual private network encrypts traffic from your device to a server you chose, then that server talks to the rest of the internet as itself. The site sees the VPN exit. Your ISP sees a tunnel, not the hostname you typed. That is how a VPN works. It is a hop. It is not a cloak of night.
I am writing this on 1 September 2026. WireGuard is the protocol most honest apps default to. OpenVPN and IKEv2 still exist for corporate and stubborn networks. None of them make you anonymous if you then sign into Gmail. None of them replace a credit freeze. If you wanted a privacy product that starts at the bureaus, that is the identity theft essay.
The tunnel, the keys, the exit
How a VPN works, mechanically: your client and the VPN server agree on keys. Every packet you send is encrypted so the network in the middle — the coffee shop, the hotel, your ISP — can see volume and destination of the tunnel, not the sites inside it. The server decrypts, then makes the request onward. Replies come back the same way. The public IP on the far site is the server’s, not yours. If you needed a second IPv4 that is actually yours, that is a VPS or a leased prefix, not a VPN.
Protocols are how the keys and the packets are shaped. WireGuard is small, fast, and the 2026 default in apps that are not stuck in a procurement PDF. OpenVPN is the older TCP/UDP workhorse that still punches through silly firewalls. IKEv2/IPsec is what phones keep alive when you leave Wi-Fi. PPTP is a museum. If a vendor still leads with PPTP, close the tab. How a VPN works does not change with the logo on the app. The protocol and the operator do.
| Piece | What it does | What it does not |
|---|---|---|
| Client | Encrypts, picks a server, (hopefully) a kill switch | Make Chrome private by itself |
| Tunnel | Hides destinations from the local network | Hide you from the VPN company |
| Exit IP | The address sites and DNSBLs see | A guaranteed streaming catalog |
| DNS through the VPN | Stops your ISP from seeing lookups | Magic if the app leaks WebRTC |
A kill switch is the unfashionable half of how a VPN works in real life. If the tunnel drops and the laptop keeps talking, you just published your home IP to the next request. DNS leaks are the other half: the tunnel is up, but lookups still go to the ISP resolver. WebRTC can publish a local address in the browser even while the VPN is “connected.” Test those three before you trust a brand. A pretty dashboard is not a test.
What privacy a VPN actually buys
The privacy you bought is this: the network you are sitting on does not get a clean log of every host you visit, and the sites you visit do not get the IP of the apartment. That matters on shared Wi-Fi. It matters if your ISP sells clickstream. It matters if you needed a different country for a catalog that still accepts the exit. That is the adult version of how a VPN works for privacy.
It does not matter if you then paste a password into a phishing page. Encryption to a hostile origin is still a hostile origin. HTTPS already encrypted the last hop to the site; a VPN encrypts the hop before that. Running both is normal. Running a VPN instead of HTTPS is folklore. Mixed content on a WordPress origin is a site problem. Fix it on the host, do not put a tunnel in front of a lock icon you broke.
Commercial VPN companies ask you to trust their no-logs page. Some have been in court and the disk was empty. Some have been in court and it was not. How a VPN works does not include a personality transplant for the operator. If you cannot name the jurisdiction and the audit, you bought a prettier ISP. Self-hosting WireGuard on a VPS you control is the version where the logs are yours. Snapshot the guest. Do not put the VPN daemon in a world-writable folder.
When a VPN is the right tool
- Untrusted networks: hotels, airports, a client’s guest SSID.
- You needed a chosen exit country, and the catalog still accepts it.
- You run WireGuard on a box you can restore, not a mystery app.
- You already use HTTPS, a password manager, and a freeze at the bureaus.
What a VPN will not fix
A VPN will not make you faster. Extra hop, extra handshake. A nearby exit is less bad; it is still not a CDN. A VPN will not get you off a DNSBL if the exit is already listed — and cheap shared exits often are. A VPN will not hide a dedicated server you published. If the job was a clean origin for mail or a shop, buy the origin. We sell those. We do not sell a consumer VPN app.
iCloud Private Relay is the cousin everyone mixes in. Relay is a two-hop Safari cloak on iCloud+. A VPN is a device tunnel you aimed. Read VPN vs iCloud Private Relay if that was the actual tab. How a VPN works is still the device-wide hop. Relay is not.
Malware, session cookies, and a reused password are outside the tunnel. So is a WordPress plugin that stored emails in a world-readable backup. So is an open recursive resolver on a VPS you forgot. How a VPN works will not patch those. The WordPress hardening piece is the other half of the privacy story for anyone who runs a site.
Buy a VPN the way you buy a lock: for a door you can name. Test the kill switch. Test DNS. Prefer WireGuard. Prefer an operator you can explain, or a WireGuard peer on a VPS you snapshot. Ignore the 4.9-star GIF. That is how a VPN works when it is a tool instead of a billboard.
Reader discussion
Join the conversation.
Questions, corrections, and useful context are welcome.