Internet without VPN is the normal mode of operation of your phone and computer. The browser accesses the domain name system, the device transmits packets through the router or mobile network, and the secure site establishes an HTTPS connection. VPN adds a tunnel to a separate server to this chain, but does not replace the Internet itself and site protection.
To understand the difference, it's useful to break down the request path into layers. This article describes the technical model. The practical answer “do I really need a VPN” is included in a separate short guide.
Step 1. The device connects to the local network
At home, this is usually a Wi-Fi router or cable; when traveling, it is a mobile network or a public access point. The device receives a local address, gateway address, and DNS settings. These options allow you to find your way to other networks.
The quality of this first section depends on the signal, router and operator. VPN does not enhance Wi-Fi or fix line faults. If the Internet disappears before the tunnel is established, first check the local connection, gateway address and access without a VPN.
Step 2: DNS converts name to address
When a user enters a domain name, the system usually needs to know the server's IP address. DNS is used for this. The request can be sent in the usual way or through a secure mechanism supported by the system, browser or network. The specific route depends on your device and application settings.
DNS answers the question “where to connect”, but does not transfer the content of the page. It also does not confirm that the user has selected the correct domain. A typo or link to a fake address remains a risk even with a secure DNS transfer.
Once VPN is enabled, DNS queries can go through the tunnel, but this is determined by configuration. The VPN icon itself does not prove which DNS each app is using. An accurate answer requires documentation of the configuration owner and verification of the actual behavior.
Step 3. Packets pass through the provider
Without a VPN, traffic travels from the device through the local network and Internet provider to the destination nodes. Routers see the service information necessary for delivering packets: addresses and connection parameters. The content of a secure HTTPS session, when the certificate is correctly verified, is encrypted between the application and the site.
The provider still needs to forward the traffic to its destination, so complete invisibility of network communication is not possible. At the same time, the site sees the incoming connection and can recognize the user by account, cookie and other application data.
Step 4. HTTPS protects communication with the site
HTTPS uses TLS to encrypt data between the browser and the server and verify the site's certificate. Normally, this protects page content, form inputs, and server responses during transmission. Mobile applications can also use TLS if the developer has implemented and configured it correctly.
HTTPS does not make the site fair. The fraudulent domain may also have a valid certificate. Encryption confirms a secure channel to the specified domain, so the user must still check the address and browser warnings.
VPN and HTTPS work in different areas. VPN protects the path from the device to the VPN server. HTTPS continues to secure communications from the application to the site. The presence of one layer does not negate the need for a second.
What changes after turning on VPN
The device creates a virtual network interface and forwards selected traffic to an encrypted tunnel. On the external site, the connection to the sites appears to be coming from the VPN server. The local network and the provider see the connection to this server, but the contents of the tunnel are protected by the selected protocol.
After the VPN server, the traffic continues on its way to the site. Therefore, trust does not disappear, but its distribution changes: the VPN operator participates in routing. NCSC considers VPN as an architectural element that must be selected and configured taking into account the specific network model.
The tunnel can cover all traffic or only selected routes. In the second case, some applications will continue to work directly. This mode is often called split routing, but the specific behavior is determined by the configuration.
What connection participants see
| Member | Without VPN | With VPN | | ------------------ | ----------------------------------------------------------- | --------------------------------------------------------------- | | Local network | Device network connections; HTTPS content is encrypted | Connection to VPN server; tunnel contents are encrypted | | Internet Service Provider | Routes and service connection parameters | Connecting to a VPN server and its parameters | | VPN operator | Not participating | Participates in post-tunnel routing within the configuration | | Website | Incoming connection and account details | Incoming connection from VPN server and account information |
The table simplifies a real network: applications can use their own channels, proxies, and DNS settings. It shows the main thing - VPN does not erase accounts and does not make all parties invisible.
Public Wi‑Fi as a separate first section
On a public Wi-Fi, the user does not control the access point. An attacker can copy its name or offer a fake login page. Australian Cyber Security Center recommends checking the network name, turning off automatic connection and choosing a mobile network if possible.
HTTPS remains the primary encryption for websites. A VPN can further protect the area up to its server, but does not verify the identity of the access point, domain, or file. You cannot ignore a certificate warning or install an unknown profile just because the tunnel is enabled.
Built-in system capabilities
Android lets you add a VPN through the app or system settings, including always-on for compatible configurations; this is described in Google help. Windows has a built-in client, but requires the server address, connection type, and login information as specified in Microsoft documentation.
The presence of a VPN item in the system does not mean the availability of the service. The parameters, keys and server are provided by the organization or access operator. Without them, the built-in interface does not create a working connection.
Technical summary
Without a VPN, the Internet usually passes through the local network and the provider, DNS helps to find the address, and HTTPS protects the content of the exchange with the site. A VPN adds a separate tunnel to the server and can change the route, DNS, and external exit point. It does not fix Wi‑Fi signal, spoofed domain, infected device or weak password.
The detailed design of tunnels is described in the article “What is a VPN”. Instructions for systems are collected in the devices section, and questions about a specific configuration can be directed to support.
