What a VPN Can't Protect You From

VPN marketing tends to blur into "total online protection." The actual product is narrower and more specific than that — and knowing where it stops is what keeps you safe.

Quick answer

A VPN encrypts the connection between your device and its server, and it hides your real IP address from the sites and services you connect to. That's it — that's the actual job. It does not detect or remove malware, does not stop phishing pages from tricking you, does not prevent tracking cookies or browser fingerprinting, does not protect an account whose password is already known to an attacker, and does not make you anonymous if you're logged into Google, Facebook, or any other account while connected. What a VPN doesn't protect against is, in short, almost everything that happens after your traffic reaches its destination or before it leaves your device — a VPN secures the pipe, not the endpoints.

What a VPN actually does, in one paragraph

Before listing what a VPN doesn't protect against, it helps to be precise about what it does — because the gap between those two lists is the entire point of this guide. A VPN (virtual private network) creates an encrypted tunnel between your device and a server run by the VPN provider. Two things follow from that. First, anyone positioned between your device and that server — your internet service provider, the operator of a coffee-shop Wi-Fi network, someone on the same public network sniffing traffic — sees only encrypted data, not the content of what you're doing or the individual sites you visit. Second, the websites and services you connect to see the VPN server's IP address instead of your own, which is why a VPN can make it look like you're browsing from a different city or country. That's the whole mechanism. It's a genuinely useful one, but it's narrow, and a lot of online risk lives entirely outside it.

Nearly every misunderstanding about VPNs comes from treating "encrypts my connection and hides my IP" as if it meant "protects me online" in some general sense. It doesn't. Below is a walk through the specific things a VPN does not do, organized roughly by where the risk actually sits — on your device, on the sites you use, in your own behavior, or with the VPN provider itself.

What a VPN doesn't protect against: malware and malicious downloads

A VPN has no visibility into the files you download or the programs you run. If you download an infected attachment, install a trojanized app, or get tricked into running a malicious script, the VPN tunnel your traffic travels through does nothing to inspect, block, or clean that file — it just carries the bytes, encrypted, from one point to another. Once malware is on your device, it's on your device regardless of whether a VPN was active during the download. Some VPN apps bundle an optional ad/tracker/malicious-domain blocker as a separate feature (NordVPN's Threat Protection and Proton VPN's NetShield are examples of this pattern), and those can catch some known-bad domains before a connection is even made. That's a genuinely useful layer, but it's a distinct feature bolted onto the VPN app, not a property of the VPN tunnel itself — and it's not a substitute for antivirus software, keeping your operating system patched, or being careful about what you install.

Does a VPN stop phishing attacks?

No, and this is one of the most consequential gaps because phishing is how a huge share of account takeovers actually start. A phishing page is a real, "legitimate" — in the technical sense of correctly using HTTPS and a valid certificate — website that's designed to look like your bank, your email provider, or a service you use, in order to get you to type in your username and password. A VPN encrypts the connection to that page exactly as reliably as it encrypts the connection to the real site, because from a purely technical standpoint the VPN has no way to know the page is fraudulent — it's not reading the content, evaluating the design, or checking who registered the domain. The encryption a VPN provides secures data in transit; it says nothing about whether the destination deserves your trust. Recognizing phishing attempts — checking the actual domain in the address bar, being suspicious of urgent "your account will be suspended" language, not clicking links in unexpected emails — is a skill a VPN cannot substitute for. Some browsers and security suites include phishing-site blocklists that will actually warn you before you land on a known bad page; a VPN's optional threat-blocking feature, where present, may also draw on a domain blocklist, but again that's a separate feature, not the VPN function itself.

Tracking cookies, browser fingerprinting, and account-based tracking

This is probably the single biggest source of confusion about what a VPN doesn't protect against, because "hides your IP address" sounds a lot like "makes you untrackable," and it isn't remotely the same thing. Modern web tracking relies on far more than your IP address:

  • Cookies — small files a site stores in your browser that persist across visits and, for third-party ad networks, across different sites entirely. A VPN doesn't touch cookies at all; they're stored and read by your browser, independent of your network connection.
  • Browser fingerprinting — a technique that identifies you based on the combination of your browser version, installed fonts, screen resolution, timezone, installed plugins, and dozens of other small signals, which together are often unique enough to re-identify a device even with cookies cleared and even with a different IP address on every visit. A VPN changes your IP; it changes essentially nothing else about your fingerprint.
  • Account-based tracking — if you're logged into Google, Facebook, Amazon, or any account while browsing, that service already knows exactly who you are regardless of what IP address the request came from. Being logged in overrides IP-based anonymity completely; the site doesn't need your IP to identify you when your account session already does.

None of this means a VPN's IP-masking is worthless — hiding your IP still prevents a specific and real category of tracking, particularly IP-based geolocation and tracking by parties who only have your network-level identity to go on, like your ISP monitoring which sites you connect to. But if the goal is minimizing tracking broadly, a VPN is one tool among several — it needs to be paired with cookie management, a privacy-respecting browser configuration, and awareness of which accounts you're logged into, not treated as a complete answer on its own.

What a VPN doesn't protect against: weak or reused passwords

A VPN operates at the network layer. Your password is an application-layer credential — something you type into a login form, checked against a database on a company's server. These are unrelated systems. If your password is weak, reused across multiple sites, or exposed in a data breach at some other company, a VPN does nothing to change any of that. An attacker who already has your email address and a leaked password doesn't need to intercept your network traffic at all — they can just log in directly, from anywhere, using the credentials they already have. This is precisely why credential-stuffing attacks (trying leaked username/password pairs against many different sites) work at such scale: the attack doesn't touch your network connection at any point, so a VPN is simply not in a position to interfere with it. A password manager that generates and stores a unique password per site, plus two-factor authentication wherever it's offered, addresses this category of risk. A VPN doesn't.

Does a VPN stop social engineering and scams?

No. Social engineering is the practice of manipulating a person — not a device or a network — into handing over information, access, or money voluntarily. A fake tech-support call claiming your computer is infected and asking for remote access, a romance scam that builds trust over weeks before asking for a wire transfer, a fraudulent invoice email asking an employee to redirect a payment: none of these rely on intercepting network traffic, so none of them are affected by whether a VPN is running. A VPN has no way to evaluate whether the person on the other end of a call or chat is who they claim to be, or whether a request is legitimate. Guarding against social engineering is fundamentally about verifying requests independently — calling a company back on its official number rather than one given to you in a suspicious message, being skeptical of urgency and pressure — and a VPN sits entirely outside that process.

What a VPN doesn't protect against: a compromised device

If your device already has spyware, a keylogger, or remote-access malware installed, a VPN doesn't help and in some scenarios can create a false sense of security that makes things worse. A keylogger captures what you type before it's ever handed off to the network stack, so it doesn't matter whether that traffic subsequently travels through an encrypted VPN tunnel — the attacker already has your keystrokes directly from the compromised device. Similarly, spyware that takes screenshots, accesses your camera, or reads files directly off the disk isn't operating over the network in a way a VPN would ever see. A VPN protects data in transit between your device and its server; it has no visibility into and no control over what's happening on the device itself. Device security — OS and app updates, reputable antivirus/anti-malware software, not installing software from untrusted sources, and locking the device itself — is a separate and, for most people, more consequential category of protection than anything a VPN provides.

Does a VPN hide what you type into a website?

A VPN encrypts data in transit between your device and the VPN server, and (assuming the destination site uses HTTPS, which the overwhelming majority of sites now do) that data stays encrypted the rest of the way to the destination too. But the site itself — and anyone with legitimate access to its backend systems, or anyone who breaches it — sees exactly what you typed into its forms once it arrives, VPN or not. If you type your real name, address, or credit card number into a checkout form, the VPN's encryption protected that data from being read in transit by, say, someone on the same public Wi-Fi network; it did not and cannot prevent the destination company from seeing, storing, sharing, or eventually losing that same data in a breach. A VPN is not a way to submit information to a website without that website receiving it.

What a VPN doesn't protect against: data breaches at companies you use

When a company you have an account with is breached and its user database — including, potentially, your email, password hash, address, or payment details — is stolen, that theft happens on the company's servers, long after your original connection to sign up or make a purchase ended. There is no way for a VPN, which only secures your own connection to a service, to prevent or even be aware of a breach happening on that service's infrastructure later on. This is worth internalizing because it's one of the more common reasons people are surprised their information leaked "even though I always use a VPN" — the VPN was never the layer that could have stopped that particular incident. The realistic response to this risk is breach monitoring (services that alert you when your email address turns up in a known breach), unique passwords per site so one breach doesn't compromise other accounts, and minimizing what personal data you hand to services in the first place.

Does a VPN make you completely anonymous online?

No, and treating a VPN as an anonymity tool is one of the more consequential misreadings of what it does. IP masking is one input into how identifiable you are online, but it's far from the only one. Being logged into any account defeats IP-based anonymity for that session, as covered above. Browser fingerprinting can re-identify a device across sessions and IP addresses. Payment details, if you've ever paid for anything while using that device or account, link back to a real identity regardless of the IP address on a given connection. And behavioral patterns — the specific combination of sites you visit, the times you're active, how you write — can be identifying on their own, independent of any technical signal. A VPN raises the bar for a narrow kind of network-level tracking; it doesn't clear it entirely, and for anyone whose threat model genuinely requires strong anonymity — journalists and activists working under serious risk are the clearest example — a VPN is one component of a much broader operational-security practice, not a replacement for it. See our guide on VPNs for journalists for a more threat-model-specific treatment of this.

Does a VPN protect against your own ISP if you're logged into other services?

A VPN does hide the specific sites and services you connect to from your ISP's view — that's a real and useful property, and it's one of the more common legitimate reasons people use one. But it's easy to overstate what this buys you. Your ISP not being able to see which sites you visit doesn't mean those sites can't see, store, and act on everything you do once you're there — and most of the profiling that shapes the ads you see and the content you're shown happens at the destination-site level (via cookies, account data, and fingerprinting), not at the ISP level. A VPN closes one specific visibility gap involving one specific party. It doesn't touch the much larger amount of tracking and data collection that happens downstream of that.

What a VPN doesn't protect against: apps and permissions on your phone

Mobile apps request permissions — location, contacts, microphone, camera, storage — directly from the operating system, and once granted, an app can access that data whether or not a VPN is active. A flashlight app that asks for and is granted access to your contact list, or a game that requests precise location and gets it, operates entirely outside what a VPN can see or restrict; the VPN only governs the network traffic, not the operating-system-level permission grants that let an app read data off the device in the first place. Auditing and limiting app permissions on your phone — checking what each installed app can actually access, and revoking permissions that aren't necessary for the app to function — is a separate and important practice that a VPN doesn't replace.

Does a VPN stop location tracking?

Partially, and only for one specific method of location inference. A VPN masks the IP address a site or service sees, which prevents the coarse, city-or-region-level location estimate that's typically derived from IP address alone. But most precise location tracking on modern devices doesn't rely on IP address at all — it comes from GPS, Wi-Fi network triangulation, and Bluetooth beacon data that apps request directly through OS-level location permissions, none of which a VPN has any influence over. A ride-hailing app that has location permission still knows precisely where you are, VPN or not, because it's asking your device's GPS chip directly rather than inferring anything from your IP address. If limiting location tracking specifically is the goal, the more directly relevant controls are your device's location-permission settings per app, not the VPN.

What a VPN doesn't protect against: a subpoena or legal order to the VPN provider itself

A VPN routes your traffic through a company's infrastructure, which means that company is itself a party that can, in principle, be compelled by a court or law enforcement in its own jurisdiction to provide whatever data it retains. This is exactly why logging policy and jurisdiction matter as much as they do when choosing a provider — a VPN with a genuine, independently audited no-logs policy has less to hand over even if legally compelled, but no VPN can protect you from a legal process directed at the provider itself; it can only limit what that process is able to extract. Our guide to what "no-logs" actually means covers this distinction in more depth, and it's worth reading before assuming any provider's privacy marketing is the full picture.

What a VPN doesn't protect against: your own metadata and behavior patterns

Even with a perfectly encrypted, perfectly anonymized connection, the pattern of your behavior can still identify or expose you. If you log into the same personal email account every time regardless of which network or VPN server you're connecting through, that account login is a consistent identifying thread that runs straight through any IP masking. If you write in a distinctive style, mention specific personal details, or follow a recognizable routine (connecting from the same VPN server at the same time every day, for instance), those patterns can narrow down or confirm identity independent of any network-layer protection. This is a genuinely hard problem — it's the reason serious anonymity work (the kind journalists protecting sources or activists under real threat need to think about) involves compartmen-talizing identities, being deliberate about routine, and treating a VPN as one layer of many rather than the whole solution.

Does a VPN protect against SIM swapping or phone number takeover?

No — and this one matters more than it might seem, because so many services use your phone number as a fallback account-recovery method or as the delivery channel for SMS-based two-factor codes. A SIM swap is an attack where someone convinces (or bribes, or socially engineers) your mobile carrier into transferring your phone number to a SIM card they control. Once that happens, any SMS verification codes or account-recovery texts meant for you go straight to the attacker instead, regardless of anything happening on your actual device or your network connection. This attack targets your carrier account, not your internet traffic, so a VPN — which only ever sees traffic that reaches your device — is never in a position to notice or interfere with it. The more resilient defenses are using an authenticator app or a hardware security key instead of SMS for two-factor authentication wherever a service allows it, and asking your carrier to add a PIN or extra verification step before any SIM changes are permitted on your account.

Does a VPN protect against doxxing or information that's already public about you?

No. Doxxing is the act of compiling and publishing someone's personal information — home address, workplace, phone number, family members — usually pulled from a combination of public records, data broker sites, old social media posts, and information you've shared yourself over the years. None of that comes from intercepting your current network traffic, so a VPN, which only affects the connection you're using right now, has no bearing on information that's already sitting in a public records database or on a data broker's site from years before you ever started using one. Addressing this risk means going after the information itself — submitting opt-out requests to data broker sites, tightening the privacy settings and audience visibility on old social media accounts, and being more deliberate about what personal details get posted publicly going forward. A VPN protects future network traffic; it has no mechanism for retroactively removing information that's already out there.

Can your own VPN connection still leak your real IP address?

Yes, and this is worth calling out specifically because it complicates the idea that a VPN reliably hides your IP at all. A DNS leak happens when your device sends domain-lookup requests outside the encrypted tunnel — to your ISP's DNS server, for instance — even while the rest of your traffic is routed through the VPN, which can reveal which sites you're visiting despite the VPN being "on." A WebRTC leak is a related but separate issue specific to browsers: WebRTC, a technology used for video calls and other real-time browser features, can expose your real IP address directly to a website through a browser API call that bypasses the VPN tunnel entirely, again while the VPN app itself shows as connected. And if the VPN connection drops unexpectedly — a momentary network hiccup, switching Wi-Fi networks — any traffic sent during that gap goes out over your normal, unencrypted connection unless something is actively blocking it. A kill switch is the feature that addresses that last scenario, by cutting off internet access entirely rather than letting traffic fall back to an unprotected connection; DNS-leak and WebRTC-leak protection are separate settings that reputable VPN apps include but don't always enable by default. The point for this guide is that a VPN doesn't automatically or unconditionally protect your IP address — it protects it only when it's actually configured correctly and functioning as intended, which is exactly why leak tests exist and why a kill switch is a feature worth confirming is turned on rather than assumed.

Do free VPNs close any of these gaps better than paid ones?

No — if anything, a number of free VPN services introduce risks on top of the ones covered above rather than reducing any of them. A VPN service costs real money to operate — server infrastructure, bandwidth, and engineering all have to be paid for somehow — so a service offered for free has to fund that cost somewhere else, and historically that has sometimes meant logging and selling user browsing data, injecting ads into browsing sessions, or simply operating with weaker security practices than a business with a subscription-revenue incentive to protect its reputation. None of that is a rule that applies to every free VPN uniformly, but it's a pattern worth being aware of, because it means a free VPN can, in the worst case, actively work against the exact things people assume a VPN is protecting — turning the provider itself into one more party collecting data about your browsing, on top of every other gap already covered in this guide. This isn't an argument that a specific price point guarantees trustworthiness either; it's an argument for reading a provider's actual privacy policy and business model rather than assuming "VPN" is a single, uniformly protective category of product regardless of who's offering it or how they're funded.

Does a VPN protect you from legal consequences for what you do online?

A VPN changes who can see your traffic and where it appears to originate from; it does not change what's legal or illegal to do, and it does not make an action untraceable in every circumstance. If what you're doing is illegal regardless of network privacy — copyright infringement is the most commonly cited example — a VPN can make it substantially harder for a rights holder or your ISP specifically to see and report on that activity by hiding the connection from their vantage point, but it doesn't retroactively make the underlying activity lawful, and it isn't an absolute guarantee of never being identified, since identification can still happen through other means — a compromised account, a mistake made while not connected, or a legal order directed at the VPN provider itself in a jurisdiction where that provider does retain identifying logs. It's also worth being clear-eyed that some countries restrict or ban VPN use outright, or restrict it for specific purposes, which is a separate legal question from what the VPN technically protects against — using a VPN in a jurisdiction where that's itself against local law carries its own legal exposure that no amount of encryption resolves. Our guides on VPN laws in China and VPN legality in the UAE go into this by jurisdiction; the short version is that "is a VPN legal here, and for what" is a question worth answering before travel or relocation, not an assumption to make.

So what should you actually pair a VPN with?

None of the above is an argument against using a VPN — it's an argument for using it for what it's actually good at, and not relying on it for the rest. A reasonably complete personal security setup layers several distinct tools, each covering a different gap:

  • A password manager generating a unique, strong password per account, so a breach at one site doesn't cascade into others.
  • Two-factor authentication wherever it's offered, so a leaked password alone isn't enough to log in as you.
  • Reputable antivirus/anti-malware software and prompt OS/app updates, to reduce the chance of a compromised device in the first place.
  • Careful handling of email and messages — verifying unexpected requests independently, not clicking links in unsolicited messages — as the primary defense against phishing and social engineering.
  • Browser-level privacy settings (blocking third-party cookies, using a privacy-respecting browser or extension) to address the tracking a VPN's IP-masking doesn't touch.
  • Reviewing app permissions on your phone periodically, since that's where a lot of location and contact-data exposure actually originates.
  • A VPN, for what it does well: encrypting your traffic on untrusted networks (public Wi-Fi being the clearest case) and keeping your ISP and anyone on the local network from seeing which sites you connect to.

Providers differ somewhat in what they bundle alongside the core VPN function. NordVPN and Proton VPN both ship optional threat/ad-blocking features that catch some malicious domains before a connection is made, which is a small but real step beyond pure IP-masking and encryption; PureVPN and FastestVPN focus more narrowly on the core VPN connection itself. None of these extras turn a VPN into antivirus software, a password manager, or a phishing filter — they're adjacent features, not a redefinition of what a VPN fundamentally is. If you want to compare how the four providers covered on this site position their app feature sets, our individual reviews go through each one in more detail: NordVPN review, Proton VPN review, PureVPN review, and FastestVPN review.

A simple mental model

If one sentence has to summarize all of this: a VPN protects the pipe your data travels through, not the endpoints on either side of it and not you as a person interacting with whatever is on the other end. Your device is one endpoint, and a VPN doesn't defend it against malware, weak passwords, or a bad app permission grant. The website or service you're connecting to is the other endpoint, and a VPN doesn't defend against that service being breached, tracking you through cookies and fingerprinting once you arrive, or simply being a phishing page pretending to be something else. And you, in the middle, are not defended by a VPN against being socially engineered, against reusing a password that later leaks, or against patterns in your own behavior that identify you regardless of your IP address. Understanding that boundary clearly is what turns a VPN from a vague "protection" product into a specific tool you can actually reason about — used for the right job, alongside the other tools that cover what it structurally cannot.

Frequently asked questions

Does a VPN protect me from viruses and malware?

No. A VPN encrypts your network traffic but has no ability to scan, detect, or remove malware on your device. Antivirus software and being careful about what you download and install are what actually address this risk, not a VPN.

Can a VPN stop phishing emails or fake websites?

No. A phishing page typically uses a valid, properly encrypted connection just like a legitimate site does, so a VPN has no technical way to distinguish a fraudulent page from a real one. Recognizing phishing attempts yourself, or using a browser/security tool with a known-phishing-site blocklist, is what actually helps here.

If I use a VPN, am I anonymous online?

Not fully. A VPN hides your IP address from the sites you visit, but being logged into an account, browser fingerprinting, cookies, and your own behavioral patterns can all still identify you regardless of your IP address. A VPN reduces one specific kind of tracking; it doesn't eliminate identifiability in general.

Does a VPN protect my passwords or stop account hacking?

Not directly. A VPN secures your network connection, not your login credentials. If a password is weak, reused, or exposed in a data breach at another company, a VPN does nothing to prevent someone from using it to log into your account. A password manager and two-factor authentication address that risk instead.

Will a VPN stop websites from tracking me with cookies?

No. Cookies are stored and read by your browser and are unaffected by whether a VPN is active. A VPN changes the IP address a site sees; it does not clear, block, or manage cookies. Browser privacy settings or a dedicated tracker-blocking extension are the relevant tools for that.

Can a VPN protect me if the company I have an account with gets hacked?

No. A data breach at a company happens on that company's own servers, independent of how you originally connected to it. A VPN only secures your connection to a service at the time you use it — it has no bearing on how that service later stores or protects (or fails to protect) your data.