VPN GUIDE

How does a VPN work?

Your device encrypts traffic for the tunnel, the VPN server relays it to the Internet, and replies return through that protected path.

The path of a VPN connection

  1. The VPN app creates a virtual network interface.
  2. Selected traffic is encapsulated and encrypted before it leaves the device.
  3. Packets travel through your router and ISP to the VPN server.
  4. The VPN server removes the tunnel layer and contacts the destination.
  5. Replies return to the VPN server, are sent back through the tunnel and reach your app.

Why does the visible IP change?

The destination communicates directly with the VPN exit server, so it normally sees that server's public IP. Your original IP is still needed for the path between you and the VPN provider, but it is not normally used as the source address seen by the final website.

Which encryption?

Modern VPN services use protocols designed to establish authenticated encrypted tunnels. WireGuard, OpenVPN and IKEv2/IPsec are common families. Performance and security depend on implementation and infrastructure, not only on the protocol name.

VPN + HTTPS: the protections complement each other. The VPN protects the path to the VPN server; HTTPS protects the application connection to a compatible website.

What about DNS?

A well-configured VPN can route DNS queries inside the tunnel and use chosen resolvers. A DNS leak happens when queries unexpectedly leave through another path.

Kill switch and split tunneling

A kill switch blocks traffic if the VPN tunnel drops. Split tunneling lets you choose which apps or destinations use the VPN and which use the normal route.

Advertisement