The name is misleading: “virtual private network” describes the original use — connecting distant company sites as if they were a single network — not the personal use people talk about today.
The mechanism, though, is the same, and it is simple to grasp. Understanding it serves a practical purpose: it makes plain what it can and cannot do, without having to trust what the advertising says.
It expands on the recommendation a VPN for sensitive traffic.
The idea in one sentence
Your traffic gets wrapped inside an encrypted connection to a server, and comes out from there.
Whoever watches your connection sees a single unreadable flow towards a single address. Whoever receives the traffic at the other end sees it arriving from the server, not from you.
That is all. The rest is implementation detail.
What happens, step by step
1. The application creates a virtual network interface. The operating system sees it as an extra network adapter, and directs the traffic into it.
2. An encrypted channel is established with the server. The two parties authenticate — the server with a certificate, you with the subscription’s credentials — and agree a key.
3. Every packet gets wrapped. The original packet, with its real destination, is encrypted and put inside a new packet addressed to the server.
4. The server opens the wrapper and forwards. It extracts the original packet and sends it to the real destination, using its own address as the sender.
5. The reply comes back from the server to you, wrapped again.
Point 4 is the key to everything: the server replaces your address with its own. Both the benefits and the limits follow from that.
What each party sees
| Who | Before | After |
|---|---|---|
| Whoever runs the local network | Destinations and times | Only an encrypted flow towards one address |
| Your operator | Destinations and times | Only an encrypted flow towards one address |
| The VPN server | Does not exist | Destinations, times, and your real address |
| The sites you visit | Your address | The server’s address |
The third row is the heart of the matter. The VPN server sits in a position where it sees both things: who you are (because you are an identified subscriber) and where you go.
No other entity in the table has both pieces of information. It is why choosing the provider is the choice.
Why the content is not involved
A point clearing up the most widespread misconception.
When you visit an encrypted site, the encryption happens between your browser and the site’s server. The VPN tunnel is a second wrapper around that conversation, but it does not open it and does not modify it.
| Layer | From where to where | What it protects |
|---|---|---|
| Site encryption | Your browser ↔ the site | The content |
| The VPN tunnel | Your device ↔ the VPN server | The destination |
A precise conclusion follows: not even the VPN server can read the content of encrypted sites. It sees that you are talking to a certain service, not what you say to it.
And the symmetrical conclusion: a VPN adds no protection to the content, because it was already protected before.
Why the tunnel does not cover the Wi-Fi portal
A technical consequence with everyday practical effects.
To establish the tunnel, the device has to already be connected to the internet — it has to be able to reach the VPN server. On a public network with a sign-in portal, that means the portal has to be completed first.
Hence the obligatory sequence: Wi-Fi → portal → VPN. And the consequence: everything happening on the portal is outside the protection.
The name resolution gap
Before contacting a site, the device has to translate its name into a numerical address. That request is separate from the traffic itself, and it can leave outside the tunnel if the configuration is not correct.
When that happens, whoever watches the network does not see the content but does see the complete list of sites you ask to reach — which is exactly what the VPN was meant to hide.
Serious providers handle this with resolution servers of their own, reached inside the tunnel. It is a feature to check, and it is why dedicated test pages exist.
What happens when the tunnel drops
The tunnel is a connection, and connections break: a change of network, the device sleeping, the application restarting.
The moment it drops, the operating system does the natural thing: it goes back to using the normal connection. The traffic keeps working, and nothing flags it.
The block-if-it-drops setting changes that behaviour: instead of falling back to the normal connection, it blocks the traffic. It is inconvenient — browsing stops — and that is why some people turn it off. But it is what separates a protection from an impression of protection.
The protocols, briefly
There are various ways of building the tunnel, and providers name them in their descriptions. In summary, without going into detail:
The modern protocols are designed to be compact, fast, and efficient on mobile devices, where they resume the connection quickly after a network change.
The long-established protocols are more mature and widely supported, but heavier.
The obsolete protocols have known weaknesses and should not be used: if a service offers them as the default option, that is a signal about its seriousness.
For the user the practical choice is simple: use whatever the application offers as the default, if the provider is serious. It is not a decision requiring specialist knowledge.
Why the apparent location changes things
A side effect of point 4 with everyday practical consequences, in both directions.
Sites see you arriving from the server. That produces some behaviour that surprises anybody using a VPN for the first time:
- different content, because many services adapt what they offer to the apparent country;
- extra checks, because the server’s address is shared by many users and anti-fraud systems notice;
- blocks, because some services refuse addresses known as VPN servers;
- unusual sign-in alerts, because your bank sees an entry from a different place.
The last point deserves a note connecting this unit to the one on login alerts: when the bank reports a sign-in from an unusual location while you use a VPN, the detection system is working correctly. It is not a malfunction — it is confirmation that those checks exist and respond.
You see the network as if you were elsewhere. That has effects too: the local services on your network — printers, home devices, shared archives — are outside the tunnel and can turn out to be unreachable. Many applications offer an option to exclude the local network, and it is nearly always the right configuration.
The structural limits
They are not implementation flaws: they follow from how the technology works.
The provider sees everything. It is a necessary consequence of the traffic having to pass through there.
Your identity remains. If you sign in to a service with your account, that service knows who you are regardless of where you arrive from.
The browser stays recognisable. The technical characteristics allowing one browser to be told from another do not change with a VPN.
The device stays the same. If it has a problem — an unwanted program, an app collecting data — the tunnel carries it along with everything else.
The destination stays known to the site. A VPN hides where you come from, not who you are addressing.
The variants that are not the same thing
The term “VPN” gets used for very different configurations, and telling them apart avoids confusion.
| Variant | What it is for | Who uses it |
|---|---|---|
| A corporate VPN | Reaching the organisation’s internal resources | People working away from the office |
| A commercial VPN | Hiding destinations from the local observer | Personal use |
| A home VPN | Exiting from your own home network while away | Anybody with a router offering it |
| A proxy | Routing only one application’s traffic | Specific configurations |
| A multi-hop network | Anonymity through several independent relays | People with high requirements |
The fourth row is the most frequent source of misunderstanding: a proxy configured in the browser routes only that browser’s traffic. Everything else — other applications, system updates, background requests — goes outside it.
The last row describes a tool with far stronger guarantees: the traffic crosses several independent relays, and none of them knows both the origin and the destination. That is the substantial difference from a VPN, where a single party knows both.
The price of that guarantee is slowness and incompatibility with many ordinary uses, so it is not a tool for daily browsing. But it is useful to know it exists, because it clarifies what a VPN is not: it is not a tool for anonymity, it is a tool for changing the observer.
What happens on the device when you turn the tunnel on
A detail explaining why a VPN application requires such broad permissions, and why that has to be weighed.
To route all the traffic into the tunnel, the application has to:
- create a virtual network interface, that is, behave like an extra network adapter;
- modify the system’s routing rules, deciding what goes where;
- intercept all the traffic of every application;
- often, change the name resolution service the system uses.
These are legitimate and necessary operations — without them a VPN would not work — but they carry a consequence to keep in mind: a VPN application holds a privileged position over everything the device does on a network.
That is the technical reason why choosing the provider is not a matter of commercial preference. You are not only entrusting somebody with the transit of your traffic: you are installing on the device a component that sees everything and has permission to change its network behaviour.
On phones and tablets the operating system limits what an application can do anyway, and shows a permanent indicator when a VPN is on. On computers the permissions are broader.
It is one more reason, besides the economic ones, to rule out services you know nothing about.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Understanding what the tunnel wraps and what stays outside |
| Awareness | Recognising that the provider sees what the operator used to see |
| Secure Behaviour | Turning on the block if it drops, and accepting its inconvenience |
Reference level: FL3 — Autonomous.
Summary
- The tunnel wraps the traffic and makes it exit from another point: that is all.
- The VPN server is the only entity seeing both who you are and where you go.
- The content was already encrypted: the tunnel adds nothing on that plane.
- The Wi-Fi portal and name resolution are the two gaps to know about.
One thing to do today. If you use a VPN, look in its settings for the entry about name resolution protection. It is the most common gap, and it often closes with a switch.
Related content
- A VPN for sensitive traffic — the recommendation this expands on
- How to choose and use a VPN — how to turn this mechanism into settings
- Signs your VPN is not protecting you — what happens when the tunnel drops
- How HTTPS works — the layer protecting the content
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



