How to Choose a VPN (and See Through the Marketing)
Sivaram
Founder & Chief Editor
Reviewed by Sivaram

You're about to check your bank balance on a café's Wi-Fi, or you'd simply rather your internet provider not log every site you visit — and a hundred apps promise to fix it. Shopping for a VPN means wading through some of the most aggressive marketing on the internet: "military-grade encryption," "100% anonymous," "the fastest VPN on Earth," "complete privacy." Most of it is designed to make one product sound different from thirty near-identical ones. The truth is that the right VPN for you depends almost entirely on what you're trying to protect against — and for some goals, a VPN is the wrong tool entirely. This guide cuts through the claims: what a VPN really does, how to decode the marketing, the few features that actually matter, and how to match one to your situation.
For that situation, the EFF's Surveillance Self-Defense is a free, expert-maintained starting point built for exactly those threat models — and it is a far better first stop than any product. Our full terms are on our disclaimer page.
Who this is for, and how we chose what to cover
This is for an ordinary person deciding whether to buy a VPN and which one — someone whose realistic concern is their internet provider, advertisers, or an untrusted network, not a state adversary.
How we chose what to put in this guide:
- We organise around the threat model, because in this category the honest answer for a meaningful number of readers is "you don't need one" — and no article funded by affiliate commissions will tell them that.
- We do not rank the providers or test them. No public, current, methodologically sound cross-provider speed or privacy comparison exists; every one you will find is either vendor-supplied or unreproducible.
- We name them anyway, with links, because telling a reader to "pick an audited no-logs provider" without naming one is an instruction they cannot execute.
- We give the verification steps — how to read an audit, how to test for leaks — because they are the only things in this category a reader can check for themselves.
Who this is not for: the high-risk reader in the callout above. That is not modesty; it is the most important sentence in the article.
What a VPN actually does — and the three words the marketing blurs
(Fact.) A VPN creates an encrypted tunnel between your device and the VPN company's server. Two concrete effects follow: your internet provider can no longer see which sites you visit (only that you're connected to a VPN), and the sites you visit see the VPN server's IP address instead of yours.
That's genuinely useful — but notice what it does not do, because the marketing deliberately blurs three different things:
- Privacy — keeping your activity from being linked to you by observers like your ISP or advertisers. A VPN helps here.
- Security — protecting your data from being stolen or tampered with. A VPN encrypts the tunnel, but modern websites already use HTTPS, which encrypts the content either way.
- Anonymity — being untraceable. A VPN does not give you this.
The bottom line: a VPN shifts who can see your traffic — from your ISP to the VPN company — and hides your IP from websites. It is a privacy tool, not an invisibility cloak. Keeping those three words separate is the single most important thing to understand before you spend a dollar.
Does a VPN make you anonymous? No — and here's exactly why
(Fact + independent consensus.) This is the claim to be most skeptical of. A VPN does not make you anonymous, for three concrete reasons:
- The VPN company can still see you. You've moved your trust from your ISP to the provider — they can see your real IP and where you're going, unless they genuinely don't log it (more on that below). You're trusting them instead of your ISP, not trusting no one.
- A VPN doesn't touch the biggest trackers. Cookies, browser fingerprinting, and simply being logged into Google or a social account identify you regardless of your IP. Hide your IP, stay logged into your email, and you're not anonymous.
- There's usually a money trail — the payment that can tie the account back to you.
In short: if your goal is genuine anonymity (not just privacy), a VPN alone is insufficient — that's the job of tools like Tor, layered carefully, and it's a different and harder problem. Treat any "100% anonymous" claim as a red flag about the vendor's honesty.
The flagship: match the VPN to your threat model
Here's the reframe that makes the whole decision easy. Stop asking "which VPN is best?" and ask "what am I defending against?" — because the answer changes what you need, and sometimes changes whether you need a VPN at all. This isn't an idiosyncratic framing: it's how the providers themselves reason, and Proton VPN's own threat-model documentation is a good example of a vendor being explicit about what its product does and does not defend against. (The specific matching below is our editorial judgment, built from the technical facts that follow.)
| If your real goal is… | What you actually need | Does a VPN solve it? |
|---|---|---|
| Stop my ISP/advertisers profiling my browsing | Any reputable, audited no-logs VPN | Yes — this is the core use case |
| Stay safe on public Wi-Fi | HTTPS (you already have it) + optionally a VPN | Partly — mostly solved by HTTPS already; a VPN adds a modest margin |
| Watch content from another region | A VPN with servers there | Yes — but it may violate a service's terms |
| Evade a government / protect a source as a journalist or activist | A serious operational-security setup — Tor, compartmentalization, expert guidance | No — a VPN alone is the wrong tool, and over-trusting one here is dangerous |
The bottom line: most people's honest threat model is the first row — keeping their ISP and advertisers from profiling them — and for that, almost any audited no-logs VPN works. The people with the highest stakes (the last row) are exactly the ones a consumer VPN can't adequately protect. Buy for your real threat model, not the marketing's implied one.
Decoding the marketing claims
(Fact + editorial translation.) The category runs on a handful of phrases that sound technical and mean less than they imply:
| The claim | What it actually means |
|---|---|
| "Military-grade encryption" | A marketing phrase with no fixed definition — there's no single "military" standard. In practice it's AES-256, which is the industry norm on virtually every VPN. It's not a differentiator. |
| "No-logs policy" | Ambiguous by design. "Logs" can mean usage logs (the sites you visit) or connection logs (timestamps, data volume) — and some providers keep the latter for 24–48 hours. The phrase only means something if it's been independently audited. |
| "The fastest VPN" | Speed depends on the protocol, your distance to the server, and your own connection — not a fixed property. Treat unaudited speed superlatives as noise. |
| "100% anonymous" / "complete privacy" | Overstatements (see above). A more honest vendor says "more private," not "anonymous." |
The bottom line: encryption strength and "military-grade" labels are not where VPNs differ — they nearly all use AES-256. What separates a trustworthy VPN from a dubious one is whether its no-logs claim has been independently verified, not its adjectives.
The features that actually matter
Ignore the superlatives; check these (fact; independent evidence where noted). Use it as a purchasing checklist, in priority order:
✓ Independently audited no-logs policy · ✓ Kill switch · ✓ WireGuard support · ✓ DNS-leak protection · ✓ Jurisdiction (secondary)
- An independently audited no-logs policy. This is the one that counts. Reputable providers publish audits from firms like PwC, KPMG, Deloitte, Cure53, or Securitum; some (e.g. Proton VPN) have passed multiple annual audits. An unaudited no-logs claim is just a promise.
- A kill switch. If the VPN connection drops, a kill switch cuts your internet so your traffic doesn't silently fall back to the open connection. Without it, a crash exposes you without warning.
- DNS-leak protection, so your site lookups don't leak outside the tunnel.
- Modern protocol — WireGuard (generally faster and leaner than the older OpenVPN; some providers are phasing OpenVPN out). This is a documented technical property, not a claim we tested.
- Jurisdiction — with perspective. Providers outside the "14 Eyes" intelligence-sharing countries are often marketed as safer from legal data demands. It's a real consideration, but secondary to an audited no-logs policy — a provider that keeps nothing has nothing to hand over regardless of where it's based.
What to check: an audited no-logs policy plus a working kill switch matters more than the country flag or the encryption adjective. Buy on verification, not vocabulary.
How to actually read an audit
"Independently audited" is the criterion the whole article rests on, so here is how to check one rather than take the badge.
Where they live. Reputable providers publish audits on their own site, usually under a transparency, security or trust section, and often as a full PDF. A provider that references an audit without publishing it has not given you anything to check.
Three questions that separate a meaningful audit from a decorative one:
- What was the scope? An audit of the no-logs infrastructure is the one that matters here. An audit of the mobile app's code, or of the company's ISO compliance, is a different and much weaker claim wearing the same word.
- When was it done? Infrastructure changes. An audit from several years ago describes a system that may no longer exist. A provider that repeats the audit annually is making a much stronger statement than one that did it once.
- Who did it, and can you see the findings? A named firm and a published report — including what it found and what was fixed — tells you far more than a summary page asserting a clean result.
The honest limit, because no article should oversell this either: an audit is a point-in-time examination of what the auditor was shown. It raises the cost of lying substantially; it does not make lying impossible. It is the best signal available to a consumer, and it is a signal rather than a proof.
The providers, named and unranked
Six a US consumer will encounter that publish independent audits, alphabetically, not ranked, not tested by us, with no price, speed or privacy claim asserted here. Each link goes to that company's own site, where its current pricing and audit reports live:
How to choose between them in fifteen minutes: open each one's transparency or audit page and apply the three questions above; confirm a kill switch and WireGuard on the platforms you actually use, which is where providers genuinely differ; check the renewal price, not the introductory one; and confirm there is a refund window, since the only real test is running it on your own connection. If two providers both pass the audit questions, the remaining difference is unlikely to matter to you — and that is the article's honest position rather than a hedge.
What it should cost
Pricing in this category follows one pattern, and knowing it is worth more than any specific figure:
- The advertised price is almost always a multi-year prepayment, divided by the number of months, presented as a monthly rate. The equivalent month-to-month price is typically several times higher.
- The renewal price after that term is usually much higher than the introductory one, and renews automatically. This is where the category makes its money.
- Long "free trial" offers are usually refund windows, which is not the same thing — you pay first.
What to do about it: buy the shortest term that lets you test the service properly, set a calendar reminder before the renewal date, and re-evaluate then. We do not publish prices — they change constantly and are heavily promotional; each provider's own page above carries the current one, and the number that matters is the renewal, not the headline.
Free VPNs: if you're not paying, you're often the product
Running a global server network costs money, so a "free" VPN has to earn it somewhere — and the evidence on how is not reassuring. The most-cited analysis is a peer-reviewed study of 283 Android VPN apps presented at the 2016 Internet Measurement Conference — Ikram et al., "An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps" — which found a substantial share embedded third-party tracking libraries, a meaningful number were flagged by antivirus engines as containing malware, and several did not tunnel traffic as claimed. The most notorious case, Hola, resold its users' bandwidth as part of a botnet. That study is now some years old and the market has changed, but nothing has emerged to overturn its basic finding: the business model has to close somehow.
Our take: a free VPN can leave you worse off than no VPN — you're handing your traffic to an unknown company with an incentive to monetize it. If a VPN is worth using, it's worth a few dollars a month for an audited one. And if the underlying worry is account security rather than network privacy, a password manager does far more for you than any VPN.
If your data has already been exposed in a breach, a VPN does nothing about that either — identity-theft protection and credit freezes are the relevant tools there.
Do you even need one?
(Editorial judgment, grounded in fact.) Honestly, not everyone does. Because most of the web is already HTTPS-encrypted, the old "hackers on public Wi-Fi will steal your passwords" pitch is largely outdated — the content is already encrypted. A VPN is genuinely worth it if you want to stop your ISP and advertisers from profiling your browsing, if you need to reach region-locked content, or if you're on a network you truly don't trust. It's not a magic privacy button, and it won't fix tracking you do to yourself by staying logged in everywhere.
The decision: buy a VPN for a specific, honest reason from your threat model — not because an ad implied the internet is unsafe without one.
A worked example: three people, and only two of them should buy one
Illustrative cases. What varies is only what actually drives the answer: who they are defending against, and whether a VPN is the tool that defends against it.
| Priya — remote worker, home broadband | Marcus — travels constantly, hotel Wi-Fi | Elena — freelance journalist working on a sensitive story | |
|---|---|---|---|
| Actual concern | ISP profiling and selling browsing data | Untrusted networks in a different country every week | Protecting a source's identity |
| Threat-model row | Row 1 | Rows 1 and 2 | Row 4 |
| Does a VPN solve it? | Yes | Yes, and it is the strongest case here | No |
| What she or he should do | Any audited no-logs provider, cheapest audited option | Same, prioritising apps on every platform and a reliable kill switch | Not start with a product at all |
Priya — the ordinary case, and the one the whole category is built for. Take someone working from home on a domestic connection. Her ISP can see every domain she visits and, in the US, faces few restrictions on what it does with that. A VPN genuinely solves this, and the cheapest audited provider solves it exactly as well as the most expensive one, because the mechanism is identical. Her decision should take fifteen minutes and then never be revisited.
Marcus — where the marginal value is highest, and it is still not dramatic. Suppose you are on a different hotel or airport network every week. HTTPS already protects the contents of what you do, so the classic "someone will steal your password on public Wi-Fi" pitch overstates it. What a VPN adds is that the network operator cannot see which services you use, and that a hostile network cannot easily manipulate unencrypted requests. That is a real margin and worth paying for at his frequency — the kill switch matters more for him than for anyone else here, because a dropped connection on an untrusted network is exactly the failure case.
Elena — where the honest advice is the opposite of a sale. Imagine a freelance journalist whose actual risk is that a source is identified. A consumer VPN moves her trust to a company that can be compelled, and does nothing about the metadata, devices and accounts that would actually expose the source. Buying one and feeling protected is worse than buying nothing and knowing she is not. Her correct first step is Surveillance Self-Defense and expert help, not a subscription.
What these assume, and what would change them. They assume US-style consumer broadband, no legal restriction on VPN use where they live, and no employer policy governing the device. Marcus's case changes if he travels to a country that restricts VPNs — that is a legal question to check before travelling, not after arriving. Which row is closest to you? Answer one question: who specifically are you trying to keep your browsing from? If you cannot name them, that is informative.
Setting it up, and how to check it actually works
Setup, in order. Install the provider's own app rather than configuring it manually — the app implements the kill switch and leak protection you are paying for. Then, before you rely on it: turn the kill switch on (it is frequently off by default), select WireGuard if the provider offers a protocol choice, and enable connect-on-launch so it is not a thing you have to remember.
Then verify it, which almost nobody does. Three checks, all free, all under five minutes:
- Confirm your IP changed. With the VPN off, note the IP address a site like ipleak.net reports. Turn the VPN on and reload. If it has not changed, nothing else in this article matters — the tunnel is not up.
- Test for DNS leaks at dnsleaktest.com or the same ipleak page. A pass shows DNS servers belonging to your VPN provider or an unrelated resolver. A fail shows your own ISP's name — which means your provider can no longer see the content of your traffic but can still see every site you look up, defeating most of the point.
- Test the kill switch deliberately. Start a large download, then disconnect the VPN — not the internet, the VPN. Traffic should stop. If the download continues, the kill switch is off or not working, and you have been exposed on every dropped connection so far without knowing.
The test three months on: is it actually on? The most common failure of a VPN subscription is not a technical one — it is an app that quietly stopped launching after an update, on a machine whose owner assumed it was running. Re-run check 1 occasionally.
The alternatives, and when they beat a VPN
A VPN is one tool. For several of the goals people buy one for, something else is better:
| Goal | The better tool | Why |
|---|---|---|
| Stop websites and advertisers tracking you | A privacy-respecting browser and a content blocker | Tracking is done with cookies and fingerprinting, which a VPN does not touch at all |
| Stop your ISP seeing which sites you look up | Encrypted DNS (DoH/DoT), built into modern browsers and operating systems | Free, no subscription, and closes the specific leak — though your ISP still sees the destination IPs |
| Genuine anonymity | Tor, used correctly (linked below) | Designed for this problem. A VPN is not, and says so |
| Protect your accounts | A password manager and 2FA (linked below) | Account takeover is a far more common harm than network snooping, and a VPN does nothing about it |
| Secure access to a work network | Your employer's own VPN | A consumer VPN is a different product with a different purpose; do not substitute one for the other |
| Nothing in particular | Nothing | The correct answer more often than the advertising suggests |
Bottom line: the goals a consumer VPN uniquely serves are narrow — ISP and network-operator visibility, and region-locked content. For everything else on this list, something cheaper or free does the job better.
Common mistakes
- Buying on "military-grade encryption." It's AES-256, same as everyone. Not a differentiator.
- Trusting an unaudited no-logs claim. Without an independent audit, it's just words.
- Believing a VPN makes you anonymous. It moves your trust; it doesn't erase you.
- Using a free VPN for privacy. Often the opposite of private (FTC/CSIRO).
- Over-relying on a VPN for high-stakes safety. If your life or freedom depends on it, a consumer VPN is not enough — get expert help.
- Forgetting the kill switch, so a dropped connection silently exposes you.
Putting it together
Decide what you're actually defending against, translate the marketing back into plain facts (it's AES-256; "no-logs" only counts if audited; "anonymous" is a red flag), and then pick any reputable, independently-audited no-logs VPN with a kill switch — jurisdiction and protocol as tiebreakers. For the vast majority of people that's the whole decision. And if your threat model is genuinely serious, the honest advice is the opposite of an upsell: a VPN alone isn't enough — get real security help.
If you remember one thing, don't ask "which VPN is best?" — ask "what am I defending against?" Answer that honestly and the right VPN, or the fact that you don't need one, becomes obvious.
Your next three moves, in order: (1) name who specifically you are defending against — if you cannot, stop here and save the money; (2) open two providers' audit pages and apply the three questions, then buy the shorter term; (3) run the three verification checks before you rely on it, and set a reminder before the renewal.
Where to go from here
- If what actually worries you is your accounts rather than your network, a password manager and 2FA does far more for you than any VPN, at lower cost.
- If your data is already out in a breach, a VPN does nothing about it — credit freezes and the free protections are the relevant tools.
- If you are the reader in the opening callout, start at the EFF's Surveillance Self-Defense, not at a product page.
Our full terms are on our disclaimer page.
FAQ
(Only questions the body doesn't fully answer.)
- Can a VPN be traced back to me? Potentially — the provider may see your real IP and there's usually a payment trail, so a VPN is not untraceable. An audited no-logs provider minimizes what could ever be handed over, but "no VPN makes you anonymous" still holds.
- Is using a VPN legal? In most countries yes, and the uses here (ISP privacy, public Wi-Fi, region-locked content) are legitimate — though a few countries restrict VPNs, and bypassing a service's region lock may break its terms. Check your local law.
- WireGuard or OpenVPN? WireGuard is generally faster and simpler and is becoming the default; OpenVPN is older and still widely supported. For most users WireGuard is the better pick where offered.
- Does the provider's country really matter? Somewhat — a provider outside the 14 Eyes is harder to legally compel — but an audited no-logs provider that stores nothing is the stronger protection regardless of location.


