KotoVPN

Guide · Updated August 15, 2026

What a VPN actually protects you from

What does a VPN actually protect you from?

What does a VPN actually protect you from?

A VPN hides your browsing from your ISP and whoever runs the network you are on, and changes the location an IP address reveals. It does nothing against malware, phishing, cookies, fingerprinting, or any account you log into. It relocates who can watch you rather than removing the watcher.

What does a VPN protect you from, exactly?

A VPN protects one thing well: the visibility of your connection to whoever sits between your device and the wider internet. That is your ISP, the operator of the café or hotel or office network you are using, and anyone passively watching that local segment. With the tunnel up, all of them see an encrypted connection to a single server address and nothing about what travels inside it — not the sites you load, not the lookups you make, not the content of anything.

It also changes the address and apparent location that the sites themselves see. To a website, you arrive from the VPN server rather than from your own line, which is what lets a VPN move you past a block keyed to your country and stop a site building a profile against your home address.

That is the whole protective claim, stated honestly. Everything a VPN is genuinely good for is a variation on removing one specific observer from one specific part of the path. The rest of this page is about which observer that is, what it costs, and the long list of threats the tool does not touch — because the gap between what a VPN does and what its advertising implies is where almost every wasted purchase happens.

What does a VPN actually move, and where to?

The mechanism worth understanding is that a VPN does not delete the exposure. It moves it. Without a VPN, your ISP can log which addresses and domains your connection reached; that is the specific observation the tool removes. With a VPN, your ISP sees encrypted traffic to one server, and the VPN provider now sees where you go instead. You have swapped one party for another, and you are paying for the privilege.

That swap is only an improvement if the new party keeps less than the old one and is harder to compel. So the two questions that decide whether a VPN protects you at all are the provider’s logging policy and its jurisdiction — not its speed, not the length of its protocol list, not the number of servers on the marketing page. This is why our shortlists lead with audit history and where a company is incorporated.

Jurisdiction is concrete here rather than abstract. Of the four providers we cover, Proton VPN is Swiss, NordVPN is incorporated in Panama, PureVPN is in the British Virgin Islands after leaving Hong Kong in 2021, and FastestVPN is in the Cayman Islands — all outside the Fourteen Eyes intelligence-sharing arrangement. Being outside it is not immunity, because every country has legal process, but a provider incorporated inside one of those states is more exposed to routine requests whose results can be shared onward.

The logging half is where the difference between a marketing line and a tested claim becomes visible. A no-logs policy is only worth what an outside party has confirmed, and even a confirmed one is a snapshot. When KPMG examined PureVPN across all protocols in February 2023, it found the service broadly compliant but flagged two things: origin IP addresses appearing in the error logs of failed manual connections, and some logs recording first- and last-connection times with a connection count. PureVPN says both were remediated and verified. The point for a threat model is that a provider you cannot audit is a provider you are trusting blind, and the thing you are trusting it with is exactly the visibility your ISP used to have.

Which observer are you actually removing?

Before a VPN can protect you from anything, you have to be able to name the party you want to stop seeing your connection. Each one implies a different requirement, and a provider that answers one does not automatically answer another. If you cannot name the observer, the honest position is that you do not yet know whether you need the tool — a point our guide on whether you need a VPN makes at more length.

This page goes a layer deeper than that framing: it is about what each observer can and cannot see once the tunnel is up, so you can tell whether the one you care about is actually inside the tool’s reach.

  • Your ISP: sees an encrypted connection to one server and the timing and volume of it, nothing more. This is the observer a VPN removes most completely, and for most buyers it is the only one that applies.
  • A network operator you do not trust — a workplace, a landlord, an airport: same as the ISP case, plus they lose the domain names they could otherwise read from your DNS lookups and the server name in the TLS handshake.
  • A state: harder. A VPN hides your traffic from the state’s view of your line, but the state can compel your provider through legal process, block VPN protocols outright, or use deep packet inspection to spot and drop the tunnel. Here jurisdiction and obfuscation matter more than any privacy feature.
  • A rights holder monitoring peer-to-peer swarms: a VPN removes the real address they would otherwise log, which is the specific exposure behind copyright enforcement letters. The provider’s stance on that traffic then becomes the whole question.
  • A service that geo-restricts you: not really an observer at all. You are changing the location your IP reveals, and privacy features are beside the point — obfuscation and a working address matter, logging policy does not.

What stays exposed whichever VPN you pick?

This is the section the advertising skips, and it is the reason readers trust a review that includes it. A VPN operates at the network layer. Most of the threats people buy one to escape live above that layer, on your device or inside your accounts, where the tunnel has no reach at all.

Malware and phishing are not network problems in the sense a VPN addresses. A malicious download arrives through the tunnel just as cleanly as a legitimate one, and a phishing page loads perfectly over an encrypted connection. Several providers bundle a "threat protection" toggle that blocks known-malicious domains, and it is worth knowing precisely what that is and is not. When AV-TEST measured these features against 3,209 malicious URLs, NordVPN’s blocked 83.42% and Proton VPN’s NetShield blocked 4.43% — but that test was commissioned by NordSec, NordVPN’s own parent company, and it graded the features as though they were antivirus. NetShield is built to block ads, trackers and known-bad domains, not to behave like a virus scanner, so the gap is largely a scope difference rather than a straight quality gap. Read either way, the lesson for your threat model is the same: a VPN’s domain blocker is not antivirus, and even the best of them let through roughly one malicious URL in six.

Tracking is the other big misconception. A VPN does not stop cookies, browser fingerprinting or advertising identifiers, because all three operate above the network. A tracker does not need your IP address when it can read a cookie you are carrying or assemble a fingerprint from your browser’s configuration, and an ad ID on your phone identifies you regardless of which country your traffic appears to come from. Changing your apparent address moves one weak signal and leaves the strong ones untouched — the detail our companion piece on whether you can be tracked on a VPN works through.

The account problem is the starkest of all. The moment you log in to something, the address you arrived from is the least identifying thing about the session. A VPN cannot make you anonymous to a service you have handed your name to, and it cannot protect a device that is already compromised — a keylogger or a malicious extension sees your traffic before it ever reaches the tunnel. Two smaller leaks fill out the picture: a WebRTC request can reveal your real address, but only where split tunnelling or an unhandled IPv6 connection already gives it a path around the tunnel, not under a full tunnel where it travels through the tunnel like everything else; and the server name in your TLS handshake is hidden from your local network but still readable by the VPN provider and by the exit server’s upstream, exactly as your ISP would have read it.

Avoid

  • Treating a VPN as a substitute for antivirus, a password manager, updates or two-factor authentication — it replaces none of them
  • Believing a "threat protection" or ad-blocking feature is a virus scanner; it blocks domains, and cannot inspect a file
  • Assuming a VPN makes you anonymous to a site you have logged into
  • Expecting a VPN to stop cookies, fingerprinting or ad IDs, which live above the network layer it works on

Why the provider becomes the thing you have to trust

Because a VPN relocates visibility rather than removing it, the provider is not a detail — it is the entire security model. Everything your ISP could once see is now available to one company, and the only thing standing between that company and your browsing history is a policy, a jurisdiction, and whatever an auditor was allowed to check. A provider that logs, or that can be compelled and holds the records to hand over, has quietly re-created the exposure you paid to remove.

That is not a hypothetical failure mode. In 2017, PureVPN supplied user connection logs to the FBI in a criminal case while advertising a no-logs policy, which is the reason it scores 4 rather than higher on transparency in our rubric — later audits do not erase that it happened. The provider can also watch you in ways unrelated to the tunnel: FastestVPN’s own privacy policy, quoted in its published audit, lists a Facebook Pixel among the analytics tools running on its website, so the company gathering your traffic is itself feeding a tracker on the site where you signed up.

The defensible version of trusting a provider rests on three things you can actually check: a no-logs policy confirmed by a named firm, a jurisdiction outside the reach of the party you are hiding from, and a re-audited track record rather than a single old report. Proton VPN has published five consecutive annual no-logs audits through 2026; NordVPN has six assurance engagements since 2018, the last four by Deloitte under a formal assurance standard; FastestVPN has one audit, from January 2023, never repeated. Those differences are most of the gap between them, and they are the closest thing to evidence that the provider will not simply become the new observer.

None of this is a reason to skip a VPN when your threat model genuinely calls for one. It is a reason to buy the tool for the observer you have named, to check that the provider is more trustworthy than the one you are removing, and to keep the rest of your defences — because the threats a VPN leaves on the table are the ones most likely to actually reach you.

What about the threats a VPN is sold to solve?

The advertising leans on two claims in particular, and both deserve a plain answer. The first is that a VPN protects you from hackers on public Wi-Fi. That was a real risk when most of the web was unencrypted; today the overwhelming majority of sites use HTTPS and the traffic is already encrypted end to end, so what a VPN adds on a café network is hiding which domains you contact from the network operator, not stopping your bank details being read in transit. That is worth having on a network you do not trust, and it is a much smaller claim than the pitch makes.

The second is that a VPN protects you from identity theft or fraud. It does not, in any direct sense. Identity theft happens through data breaches, phishing, credential reuse and compromised devices — none of which a VPN touches. A provider selling a VPN as identity-theft protection is selling you the wrong tool for that fear, and the right tools are unique passwords, two-factor authentication and paying attention to breach notifications.

Questions

Does a VPN protect you from hackers?
Only from one narrow kind: someone passively watching the local network you are on. It hides which domains you contact from that operator. It does nothing against phishing, malware, a breach of a service you use, or an attack on a device that is already compromised, because those happen above the network layer or on the device itself.
Does a VPN protect you from viruses or malware?
No. A malicious file downloads through the tunnel as cleanly as any other. Some providers bundle a domain blocker, but when AV-TEST measured these against malicious URLs, even the strongest — NordVPN at 83.42% — let through roughly one in six, and it is a domain blocker, not a virus scanner. Keep separate antivirus.
Does a VPN stop you being tracked online?
Not by the methods that matter most. Cookies, browser fingerprinting and advertising identifiers all work above the network, so changing your IP address leaves them intact. A VPN removes one weak signal — your address — while the strong ones keep identifying you, especially once you log in to any account.
Does a VPN hide your activity from the VPN company itself?
No — it moves your ISP’s visibility to the provider. That is why the provider’s no-logs policy and jurisdiction are the whole game. PureVPN supplied connection logs to the FBI in 2017 while advertising no logs, which is exactly the failure a confirmed, re-audited policy is meant to guard against.
Does a VPN protect you on public Wi-Fi?
It helps, but less than the adverts claim. Most sites already encrypt traffic end to end with HTTPS, so a VPN on café Wi-Fi mainly hides which domains you visit from the network operator, rather than stopping anyone reading your data. Useful on a network you do not trust; not the shield it is marketed as.

Terms used here

ISP logging

The records your internet provider keeps of which addresses and domains your connection contacted.

SNI

The field in a TLS handshake that names the site being requested, historically sent unencrypted even over HTTPS.

Jurisdiction

The country whose law governs the company operating the VPN, which determines who can compel it and by what process.

No-logs policy

A provider’s commitment not to record which sites you visit, when you connected, or what address you connected from.

Ad-blocking DNS

A resolver run by the VPN provider that refuses to answer lookups for known advertising and tracking domains.

Fourteen Eyes

A set of intelligence-sharing arrangements between allied states, expanding from the original five to fourteen participants.

Related