VPN for Journalists: Protecting Sources and Communications

A VPN is one layer in a much bigger stack. Here's what it actually contributes to protecting sources, and what it doesn't.

Quick answer

A VPN for journalists mainly hides your IP address and encrypts your connection between your device and the VPN server, which is useful when you're on hotel or newsroom Wi-Fi, working from a country that blocks certain sites, or trying to keep your network-level location less visible to casual observers. It does not, on its own, anonymize a source who contacts you by email, protect a document once it reaches your laptop, or stop a platform from identifying you once you're logged in. Treat a VPN as one layer in a stack that also includes encrypted messaging, careful metadata handling, and — for genuinely high-risk source contact — Tor, not as a complete source-protection solution by itself.

What "protecting sources" actually requires

Journalists who search for a VPN for journalists are usually really asking a bigger question: how do I keep a source, a document, or a conversation from being traced back to me or to them? That's a fair question, but it doesn't have a single-tool answer. Source protection is a chain of separate problems — network-level exposure, account-level identity, device security, metadata in files, and human operational security — and a VPN addresses exactly one link in that chain: what your internet service provider, a network operator, or someone monitoring the network you're connected to can see about your traffic. It's worth being precise about that scope from the outset, because overestimating what a VPN covers is itself a risk. A reporter who believes a VPN makes them "anonymous" and then emails a source from their normal, logged-in email account has not actually reduced the exposure that matters most in that scenario.

None of this means a VPN is pointless for journalism — it isn't. It means the right way to evaluate one is to ask, specifically, which threats in your own situation are network-level threats, and which aren't. The rest of this guide walks through that distinction in practical terms.

What a VPN actually changes about your connection

Functionally, a VPN does two things. First, it encrypts the traffic between your device and the VPN provider's server, so that whoever operates the network you're physically connected to — a hotel, an airport, a newsroom's shared Wi-Fi, a mobile carrier, or an ISP — sees only that you're connected to a VPN server, not the content or destination of your traffic. Second, it replaces your visible IP address with the VPN server's IP address for anything you connect to afterward, so a website, a news tip line, or a cloud storage service sees the VPN's server location rather than yours.

Both of those are genuinely useful properties for a reporter. If you're filing from a hotel network while on assignment, a VPN keeps that network's operator from being able to casually inspect what sites and services you're using. If you're researching a story and don't want the sites you visit to log your newsroom's or your home network's IP address against that research, a VPN addresses that specific exposure. If you're working in or reporting on a country where certain independent news sites, messaging apps, or research tools are blocked at the network level, a VPN can often route around that block by making your traffic look like ordinary encrypted traffic to a server elsewhere.

What a VPN does not do is anonymize you to the services you're actually using. If you log into your personal Gmail account through a VPN, Google still knows it's you — the VPN changed your visible IP address, not your account identity. If you fill out a web form with your name, or a source recognizes your writing style or the specific questions only you would ask, a VPN hasn't changed any of that. It's a network-layer tool, not an identity-layer or content-layer one, and conflating those layers is the single most common mistake in how people reason about VPN protection.

VPN vs. Tor: which one is actually built for source contact?

This is the question that matters most for anyone reporting on genuinely high-stakes material — investigations into powerful institutions, organized crime, or state actors, where a source could face serious consequences if identified. A commercial VPN and Tor solve related but different problems, and it's worth being clear-eyed about which is which rather than assuming "encrypted connection" means "same protection."

A commercial VPN routes your traffic through a single provider's server. You're trusting that one company not to log your activity, not to be compelled to hand over logs it does have, and not to be compromised. That's a meaningfully smaller attack surface than an unencrypted connection, but it still concentrates trust in one entity — the VPN provider itself becomes a single point that, in theory, could see the mapping between your real IP address and your VPN session, even if it says it doesn't log that mapping.

Tor routes traffic through at least three independently operated relays, encrypting it in layers so that no single relay knows both who you are and what you're connecting to. The entry relay knows your IP address but not your destination; the exit relay knows your destination but not your IP address. That design specifically avoids the "single party you have to trust" problem that a commercial VPN doesn't fully solve. This is why organizations that specifically build tools for anonymous source contact — SecureDrop is the standard example newsrooms use for tip lines — are built to run over Tor, not over a VPN.

The practical takeaway: for day-to-day newsroom work, research, and general network privacy, a VPN is a reasonable and convenient tool. For the specific act of a source making first contact with you, or you communicating with a source who needs to remain unidentifiable, Tor — ideally through a purpose-built system like SecureDrop rather than ad hoc browsing — is the tool actually designed for that threat model. Some VPN providers also offer a "Tor over VPN" or similar routing option; that can be a reasonable middle ground, but it's not a substitute for understanding why Tor exists as a separate tool in the first place, and you should not assume it gives Tor's full guarantees by default without reading how that specific provider implements it.

Which threats are network-level, and which aren't?

Because a VPN only addresses network-level exposure, it helps to lay out what does and doesn't fall into that category before deciding how much weight to put on VPN choice specifically.

Network-level (a VPN helps here): your ISP or a shared network's operator logging which sites and services you connect to; a government-level network block on specific sites or services; a local network operator (hotel, airport, café, even a hostile actor running a rogue Wi-Fi access point) intercepting unencrypted traffic; websites and services logging your home or newsroom IP address against your research activity.

Not network-level (a VPN doesn't help here): a source's identity being deducible from the content of what they send you, or from who else knew the information; metadata embedded in a document or photo (author name, GPS coordinates, device identifiers, edit history) that survives independent of how it was transmitted; your email provider, cloud storage account, or messaging app itself retaining logs of who you communicated with and when, regardless of the network you used to access it; a compromised or malware-infected device, which exposes everything on it regardless of network encryption; call records and metadata held by phone carriers; physical surveillance; and a source being identified through old-fashioned reporting — someone noticing who was in a meeting, who had access to a document, or who made an unusual phone call.

Realistically assessing which category your actual risk falls into is more useful than picking a VPN and assuming the problem is solved. Most reporters, most of the time, are dealing with ordinary network-level exposure — and a VPN is a good, proportionate response to that. A smaller number of stories involve source protection risks that a VPN alone cannot meaningfully address.

What should a journalist actually look for in a VPN?

Given that scope, here's what's worth prioritizing when picking a provider for journalism-related use, roughly in order of relevance to this specific use case.

A logging policy you can actually read, not just a "no logs" badge. "No logs" as a headline claim can mean very different things depending on what categories of data are excluded from that claim — connection timestamps and bandwidth use are sometimes retained even under a "no activity logs" policy. Read the actual privacy policy, not the homepage summary, and look for specifics about what is and isn't collected.

Jurisdiction. Where a VPN provider is legally domiciled affects what legal process it can be compelled to comply with, and how that interacts with its stated logging policy. This matters more for a journalist weighing source protection than for an average consumer, because it changes the realistic worst case if a provider were legally compelled to produce records it does have. Proton VPN's Swiss jurisdiction is a commonly cited example of a legal environment often described as more favorable to user privacy; read our Proton VPN review for more on how that fits into their overall privacy positioning.

A kill switch. A kill switch blocks all network traffic if the VPN connection drops unexpectedly, rather than silently falling back to your unprotected connection. For a reporter who specifically doesn't want a moment of unencrypted, unmasked traffic to slip through during a dropped connection, this is one of the more concretely useful features to confirm is present and actually enabled by default (some apps ship with it off).

Independent audits, read for scope and date, not treated as a permanent seal of approval. A provider that has commissioned an independent audit of its no-logs claims or app source code has given you a stronger signal than an unverified claim — but an audit is a snapshot of a specific system at a specific time, not an ongoing guarantee. If you're citing a provider's audit as a reason to trust it, check the audit's actual date and scope rather than treating "audited" as a blanket claim covering everything the provider does today.

Resistance to network-level blocking, if you work in or report on countries with restrictive networks. Some VPN protocols are easier for network operators to detect and block than others. If part of your work involves operating in a country where VPN use itself is restricted or heavily monitored, that's a materially different — and higher-stakes — situation than ordinary VPN use, and it deserves its own careful research into that specific country's legal risk around VPN use, not just a feature checklist.

Multi-platform, multi-device support. Journalism work happens across a laptop, a phone, and sometimes a shared newsroom device. A provider with solid apps across the platforms you actually use, and a reasonable simultaneous-device limit, matters more in practice than it might seem on a feature list.

Does a VPN protect me on public or hotel Wi-Fi while traveling for a story?

This is one of the clearest, least ambiguous cases where a VPN directly helps. Public and hotel Wi-Fi networks are shared infrastructure you don't control, and in some cases haven't been configured with the security practices a newsroom's own network would have. A VPN encrypts your traffic before it leaves your device, which means that even on a network you don't trust, someone else on that same network — or operating it — can't casually read your traffic in transit. This is a genuinely strong match between the tool and the threat: "untrusted local network" is precisely the network-level problem a VPN is designed to solve. It's a good habit to connect the VPN before doing any work-related browsing on unfamiliar networks while on assignment, rather than connecting after the fact.

Should I use a VPN to communicate with a source, or is that not enough?

A VPN alone is not enough for genuinely sensitive source communication, and it's worth being direct about that rather than implying otherwise. If a source's safety depends on their identity and the content of what they share staying confidential, the communication channel itself needs to be end-to-end encrypted — meaning the message content is unreadable to anyone but you and the source, including the messaging provider — and ideally designed with metadata minimization in mind (who messaged whom, and when, can be as revealing as the message content itself in some investigations). A VPN doesn't provide either of those properties; it protects the network path, not the message itself or the record of who talked to whom.

In practice, this usually means: use an end-to-end encrypted messaging app for the actual conversation, understand what metadata that app does and doesn't retain, and — for the initial, highest-risk moment of a source reaching out for the first time — point sources toward a purpose-built anonymous tip system (SecureDrop is the standard example many newsrooms run) rather than an ordinary email address, even a VPN-protected one. A VPN is a reasonable additional layer on top of all of that — it doesn't hurt, and it does remove one layer of network-level exposure — but it should never be the only measure a source's safety rests on.

Can a VPN keep a government or ISP from knowing I'm a journalist working on a sensitive story?

A VPN can meaningfully limit what your ISP or a local network operator sees about your specific browsing activity — which sites you visit, which services you use — by encrypting that traffic and routing it through the VPN's servers instead. What it generally cannot hide is the fact that you are using a VPN at all; VPN traffic has recognizable characteristics that a sophisticated network operator can often detect, even if it can't see what's inside that encrypted traffic. In most countries that's a non-issue. In a smaller number of countries, VPN use itself is monitored, restricted, or illegal, and simply being observed using one can draw attention regardless of what you're actually doing with it.

If your work involves reporting from or on a country with that kind of restrictive environment, that changes the calculus considerably, and it moves well beyond what a general "which VPN should I use" article can responsibly advise on — the right answer depends on the specific country's current legal environment, which changes over time, and on organizational-level operational security guidance, not a single product choice. For that specific situation, consulting your organization's security desk or a press freedom organization's digital security resources is more appropriate than relying on general consumer VPN guidance.

What about the device and files themselves, not just the network?

It's worth stating plainly: a VPN protects data in transit, not data at rest. Once a document, a recording, or a set of notes is sitting on your laptop or phone, a VPN has nothing to do with whether that device is secure. Full-disk encryption, a strong device passcode, keeping software updated, and being deliberate about what's stored on a device that travels with you to sensitive assignments all matter independently of VPN choice. Similarly, files themselves can carry metadata — a photo's embedded GPS coordinates and device identifier, a document's author field and edit history — that a VPN does nothing to strip. If a document or image needs to be shared without that metadata attached, it needs to be scrubbed of it deliberately before sharing, as a separate step from any network protection.

What are the most common mistakes journalists make when relying on a VPN?

The mistakes that come up most often aren't technical failures of the VPN software itself — they're mismatches between what a reporter assumes a VPN covers and what it actually covers. A few patterns are worth naming directly, because each one shows up repeatedly in how VPNs get discussed in newsroom security training.

Treating "connected to a VPN" as equivalent to "safe to do anything." A VPN connection is a precondition for certain kinds of privacy, not a blanket state of safety. Logging into a personal, named account, filling in a form with identifying details, or discussing a story over a phone call are all unaffected by whether a VPN is running. The VPN changes what the network layer reveals; it doesn't change what you reveal yourself.

Switching on a VPN only for "sensitive" moments. Turning a VPN on and off based on a judgment call about which specific browsing session feels risky is less reliable than simply leaving it on as a default habit while traveling or working on a story. It's easy to misjudge in the moment which activity actually matters, and a connection that's "usually on" is a much simpler habit to maintain than one that requires a decision every time.

Assuming a VPN protects a shared or borrowed device. A VPN app installed on a laptop doesn't know or care who's using that laptop. If a device is shared with colleagues, left unlocked, or used across multiple stories with different sensitivity levels, the VPN is not the control that keeps those stories' materials separated — file organization, account separation, and device locking are.

Not checking whether the kill switch is actually enabled. Many VPN apps ship with the kill switch available but off by default, on the assumption that most users would rather have uninterrupted internet than a hard stop on a dropped connection. For a journalist relying on the VPN for a specific privacy property, that default is worth checking and changing rather than assuming.

Using the same VPN session and browser profile across unrelated stories. This is less about the VPN itself and more about a broader habit: mixing research for different sensitive stories in the same browser session, with the same cookies and login state, can link activity together in ways a VPN's IP masking doesn't prevent. Separate browser profiles, or separate devices for the most sensitive work, address a different layer of exposure than the VPN does.

Does split tunneling matter for journalism-related VPN use?

Split tunneling is a feature that lets you choose which apps or sites route through the VPN and which connect directly. It exists mainly for convenience — for example, routing a bandwidth-heavy local service outside the VPN while keeping browsing traffic inside it — but it's worth understanding rather than enabling casually, because it creates an explicit gap in coverage by design. If an app or site is excluded from the tunnel, it gets none of the VPN's protection: not the IP masking, not the encryption on an untrusted network.

For most journalism-related use, the simpler and more defensible default is to route everything through the VPN and only carve out specific, deliberate exceptions when there's a clear reason — for instance, a local newsroom tool that only works on an internal network and needs to see your real IP address to function. Leaving split tunneling in a "some things excluded" state by accident, without a clear reason for each exclusion, tends to undermine the reason you turned the VPN on in the first place.

What should a newsroom, not just an individual reporter, think about?

Individual VPN choice is only one piece of a larger picture, and it's worth naming the organizational layer explicitly, because a single reporter's good habits can be undermined by weak practices elsewhere in the chain. A few things worth a newsroom's attention, beyond which VPN individual reporters use:

A real, tested tip line. If a newsroom's only channel for sources to reach out is a named reporter's public email address, no amount of individual VPN use fixes that gap for a source who needs anonymity from the first message onward. A properly configured, actually-tested anonymous tip system matters more than any single reporter's VPN choice for that specific risk.

Consistent guidance, not ad hoc individual choices. When VPN and security tool choices are left entirely to individual reporters, the newsroom ends up with uneven practices — some reporters careful, others not — on stories where the source-protection stakes don't vary by who happens to be assigned. Baseline guidance, even if simple, closes that gap.

A plan for cross-border and high-risk assignments that goes beyond a VPN recommendation. Reporting from a country with a restrictive network environment, or on a story where a specific individual or organization has a strong motive to identify a source, is a different risk category from routine reporting. That calls for consultation with a security desk, legal counsel where relevant, or a press freedom organization's digital security resources — not a general "which VPN is best" recommendation applied uniformly to every assignment regardless of its actual risk level.

A practical checklist before a sensitive assignment

Pulling the guide's points into something usable in the moment: before traveling for or beginning work on a story with real source-protection stakes, it's worth deliberately checking each of the following rather than assuming they're already handled.

Network layer: confirm the VPN app is installed and working on every device you'll use, confirm the kill switch is actually enabled (not just available), and get in the habit of connecting before doing any work-related browsing on unfamiliar networks, not after.

Communication layer: confirm which app you and any sensitive sources will actually use, and that it's genuinely end-to-end encrypted for the specific feature you're using (voice, text, and file transfer aren't always covered equally by every app). Know what metadata that app does and doesn't retain about who contacted whom.

First-contact layer: if there's any chance a new, unknown source needs to reach you with something sensitive, have a properly configured anonymous tip channel publicized somewhere they can find it — not just your ordinary email address.

Device layer: confirm full-disk encryption and a strong passcode are active, keep the device's operating system and apps updated, and think deliberately about what sensitive material actually needs to be stored on a device that's traveling with you versus what can stay elsewhere.

File layer: before sharing a document, photo, or recording, check and strip metadata that could identify a source or location if it isn't supposed to be attached — this is a separate step from anything the VPN, messaging app, or device encryption handles.

Organizational layer: know who at your organization to loop in — a security desk, an editor, legal counsel — before an assignment escalates in risk, rather than making every judgment call solo in the moment.

What happens to a VPN, and to sensitive material, at a border crossing?

Border crossings are a distinct risk moment that a VPN alone does not address, and it's worth thinking through separately from day-to-day network protection. In some countries, border agents have the legal authority to search electronic devices, and in a smaller number of cases to compel a password or ask that a device be unlocked. A VPN app sitting on a laptop or phone doesn't prevent that kind of physical device search — once a device is unlocked, whatever's stored on it is visible regardless of how it was ever transmitted over a network. In fact, in a handful of jurisdictions, VPN use itself has drawn scrutiny at a border, which is one more reason the "does this country restrict VPN use" question matters before travel, not just the "which VPN is fastest" question.

Reporters who travel internationally for sensitive stories generally address this at the device and file layer, not the network layer: deciding in advance what actually needs to be on the device that crosses the border versus what can be retrieved securely after arrival, using full-disk encryption with a strong passcode, and, for the most sensitive material, considering a clean device carried specifically for travel rather than a primary device holding a full archive of past work and contacts. None of this is a VPN feature — it's a separate set of decisions a VPN can't substitute for, and it's worth planning before a trip rather than at the airport.

Does a VPN hide my physical location, or just my IP address?

This distinction trips people up because "location" gets used loosely to mean two different things. A VPN changes the location a website or service infers from your IP address — so a site might see you connecting from wherever the VPN server is, rather than your actual city. That's useful for the network-level exposure this guide has focused on. It has nothing to do with your device's actual physical location as determined by other means: a phone's GPS chip, Wi-Fi network name lookups, or cell tower triangulation performed by your mobile carrier all operate independently of your VPN connection and are not affected by it at all. A VPN also does nothing about your phone carrier's own records of which cell towers your phone connected to and when — that data exists regardless of whether you're running a VPN, because it's generated by the cellular network itself, not your internet traffic.

For a reporter meeting a source in person, or reporting from a location they don't want tied to their phone's carrier records, the relevant precautions are things like disabling location services for apps that don't need them, being deliberate about which device (if any) is carried to a sensitive meeting, and understanding that a phone, simply by being powered on, is trackable by its carrier at a level no VPN reaches. This isn't a reason to distrust VPNs — it's a reminder that "location privacy" and "network privacy" are different problems, and a VPN only ever addresses the second one.

Practical takeaway

Use a VPN for what it's actually good at: encrypting your connection on networks you don't control, reducing what your ISP or a local network operator can see about your day-to-day research and browsing, and routing around network-level blocks where that's relevant to your work. Don't rely on it for what it was never built to do: anonymizing source contact, protecting message content, stripping metadata from files, or securing a device that's already been compromised. For genuinely high-risk source protection, treat a VPN as one layer among several — alongside end-to-end encrypted messaging, a purpose-built anonymous tip system for first contact, careful metadata hygiene, and solid device security — rather than as the single tool that makes the rest unnecessary. When picking a specific provider, weight logging policy and jurisdiction more heavily than you would for ordinary consumer use, read the actual policy language rather than the marketing summary, and confirm a kill switch is present and enabled. Our individual provider reviews link out to each provider's own policy and jurisdiction information so you can verify these claims yourself.

Frequently asked questions

Is a VPN enough to protect a source, or do I need something else?

A VPN alone is not enough for genuinely sensitive source protection. It protects your network connection, but it doesn't anonymize the content of a conversation, strip metadata from files, or secure a compromised device. For sensitive source contact, use an end-to-end encrypted messaging app for the conversation itself, a purpose-built anonymous tip system such as SecureDrop for initial contact, and treat a VPN as one additional layer on top of those, not a replacement for them.

Should journalists use a VPN or Tor?

They solve different problems. A commercial VPN routes your traffic through one provider's server, which is convenient and good for day-to-day network privacy, but requires trusting that single provider. Tor routes traffic through multiple independently operated relays so no single party can see both who you are and what you're connecting to, which is why anonymous tip systems like SecureDrop are built on Tor rather than on a VPN. For general newsroom work a VPN is usually sufficient; for anonymous source contact specifically, Tor is the tool actually designed for that threat model.

Does a VPN hide the fact that I'm using a VPN?

Generally, no. A VPN can hide the content and destination of your traffic from your ISP or local network operator, but the fact that you're connected to a VPN is often still detectable to a sophisticated network operator, even if they can't see what's inside the encrypted tunnel. This matters most if you're working in a country where VPN use itself is restricted or monitored — a situation that calls for guidance beyond general consumer VPN advice.

Does using a VPN keep my source's identity safe if we email each other?

Not by itself. A VPN protects the network path your email travels over, but it doesn't change what your email provider logs about who emailed whom, and it doesn't anonymize you or your source if either of you is using an account tied to a real identity. For sensitive first contact, a purpose-built anonymous system is a better fit than email, VPN-protected or not.

What VPN features matter most for journalism-related use?

A logging policy you can actually verify by reading the real privacy policy rather than a homepage summary, a jurisdiction you understand the legal implications of, a kill switch that's enabled by default, and — where relevant — an independently audited no-logs claim, checked for its actual scope and date rather than treated as a permanent guarantee.

Is a free VPN a reasonable choice for sensitive journalism work?

Free VPN services often fund themselves through data collection, advertising partnerships, or simply weaker infrastructure and support than paid services, which runs directly against what matters for source-protection use — a verifiable, accountable logging policy. For work where the stakes include a source's safety, the cost of a reputable paid provider is a minor consideration next to the risk of an opaque free one.