Windows: a client, not a service
Settings → Network & Internet → VPN lets you add a connection, which is why people conclude Windows includes a VPN. It does not. It includes the software to connect to a VPN server whose address, protocol and credentials you provide.
This is genuinely useful for connecting to a corporate gateway or to a server you run yourself. It does nothing on its own, and it will not hide your traffic from your ISP unless there is a server at the other end that somebody is operating.
The same distinction applies to macOS, iOS and Android, all of which ship VPN client software and none of which ship a VPN service.
Firefox: a paid subscription, not a browser feature
Mozilla VPN is a real, full-device VPN built on WireGuard and operating on Mullvad’s server network. It is a separate paid product, not something switched on inside the browser, and it is not available in every country.
Firefox does include Private Browsing and Enhanced Tracking Protection, which are frequently mistaken for a VPN. Neither encrypts traffic to a remote server or changes the address a site sees. They limit what the browser stores and which trackers load — a different problem entirely.
Opera: free, and a proxy rather than a VPN
Opera’s built-in feature is free and genuinely convenient, and it is a browser proxy. It covers traffic from Opera only. Anything else on the machine — another browser, an email client, an app — is untouched.
It also offers a small number of broad regions rather than specific countries, and it does not encrypt traffic outside the browser. For getting around a basic regional block on a web page it is fine. For anything described as privacy from your ISP across the whole device, it is not the tool.
The general rule: a "VPN" that only affects one browser is a proxy, whatever the marketing calls it. That is not automatically bad, but it is a much narrower product.
Avoid
- Treating a browser proxy as device-wide protection — other apps still leak normally
- Assuming free browser VPNs have the same funding model as paid ones
- Installing Chrome Web Store VPN extensions without checking who publishes them
Chrome extensions: the category to be careful with
Chrome has no VPN, but it is no longer true that it has nothing. IP Protection, rolling out in Incognito since 2025, sends traffic bound for domains on a Masked Domain List through a two-hop Google-operated proxy. It hides your address from listed third-party trackers, not from the sites you deliberately visit, and it is not a VPN. Beyond that, everything in the Web Store is an extension, and a VPN extension needs permission to read and change data on every site you visit — precisely the access you would want a privacy tool not to have.
That permission is unavoidable for the feature to work, which means the entire question is who is receiving it. Extensions change ownership quietly, and there is a documented pattern of popular ones being acquired and repurposed.
If you want a browser-only proxy, prefer one published by a company that also sells a full VPN and has an audit history you can check, rather than a standalone free extension whose funding you cannot identify.
When a built-in option is the right answer
Getting around a regional block on one website, occasionally, where you do not care who sees the traffic: a browser proxy is fine and free.
Connecting to a corporate network or your own server: the operating system’s built-in client is exactly right and needs nothing else.
Preventing your ISP from building a record of everything you do, on every application: none of the built-in options do this, and that is the specific job a paid VPN service exists for.