What actually changes
Without a VPN, and unless you have moved DNS elsewhere, your ISP resolves your queries and holds a list of every domain you asked about. Encrypted DNS - DoH or DoT, now on by default in several browsers - already removes that particular record for some readers. It also sees the destination address of every connection, and where encrypted client hello is not in use it can read the hostname straight from the TLS handshake. That is a fairly complete browsing record, and in several countries it is retained by law for months.
With a VPN, all of that collapses to one destination: the VPN server. Your ISP sees an encrypted flow to a single address, its size and its timing. The domains, the pages, the contents — none of it is available. This is a real and substantial change, and it is the strongest thing a VPN does.
What your ISP can still work out
That you are using a VPN, and usually which one. VPN server addresses are published, cluster in identifiable ranges, and are easy to fingerprint, so "this customer connects to a NordVPN endpoint every evening" is trivially derivable. If the fact of VPN use is what you need to hide, an ordinary connection will not hide it — that requires obfuscation. Proton VPN ships a Stealth mode and NordVPN offers obfuscated servers plus its NordWhisper protocol; PureVPN and FastestVPN offer neither.
Timing and volume. Your ISP knows you moved 40 GB between 9pm and 1am. It cannot know from what, but traffic analysis on patterns is a real technique and a VPN does not defeat it.
Anything that escapes the tunnel. A DNS leak hands the domain list straight back, which is the single most common way people believe they are covered and are not. An IPv6 leak does the same for IPv6-capable sites. Both are worth testing rather than assuming.
- That a VPN is in use, and whose addresses you connect to
- Connection times, duration and total data volume
- Any DNS query that resolved outside the tunnel
- Any IPv6 traffic, if the client neither carries nor blocks it
The Wi-Fi owner question
Whoever runs the network — an employer, a landlord, a parent, a café — is in the same position as the ISP and often a weaker one. They see an encrypted flow to a VPN endpoint and nothing about its contents.
The important exception is a managed device. If the network operator also controls the machine, they may have installed a root certificate that lets them decrypt TLS, or endpoint software that reads activity before anything is encrypted. A VPN protects traffic in transit; it does nothing about software watching from inside. On a work laptop, assume the second.
The other exception is scope. A VPN on your phone does not cover the smart TV on the same network, and the router still logs which devices connected and when, even though it cannot see what they did.
Avoid
- Assuming a VPN hides your activity on a device your employer administers
- Assuming router logs stop existing — connection metadata is still recorded
- Believing the VPN covers other devices on the network; it covers what it runs on
Who can see it instead
A VPN does not remove the observer, it moves it. Everything your ISP could previously see is now available to the VPN provider, which is why the no-logs question and its audit history are the only parts of a VPN review that genuinely matter.
This is exactly why our rubric weights independent audit at 20%, more than any other criterion. You are transferring your browsing record from a company you did not choose to one you did. The only meaningful question is whether the second keeps it — and the only external evidence available is an audit, which is why we publish each provider’s full audit history rather than a badge.