Two opposite beliefs are common: «the ISP sees everything» and «with a VPN the ISP sees nothing». Both are inaccurate. Let's break it down concretely.
What the ISP sees without a VPN
- Site names. Even with HTTPS, the domain is sent in the clear during connection setup, and name-resolution queries go through the ISP's servers.
- The IP addresses you connect to.
- Volume and timing. How much data was transferred and when.
- The type of traffic. A video stream differs from page loading by its characteristic pattern.
The ISP does not read page contents over HTTPS — that's thanks to HTTPS itself, not the VPN.
What stays visible with a VPN
- That you are connected to a VPN server. The fact itself usually can't be hidden: a connection to some address exists.
- The VPN server's address.
- The volume of data transferred and session times.
- The rough nature of the load. A steady stream looks like video, short bursts — like browsing pages.
What stops being visible
- The names of the sites you open — provided DNS queries go through the tunnel.
- The addresses of the destination servers.
- The match of «opened this site at this moment».
An important caveat about DNS
Test it on your own device
8 hours free, no card required. Full access to all servers.
If DNS queries go outside the tunnel, the ISP still sees the list of domains even though the IP address is substituted. This is called a DNS leak, and it's worth checking separately — we have a breakdown of how to do it.
Does a VPN hide the fact that a VPN is in use
Ordinary protocols — no: WireGuard or OpenVPN traffic is recognizable by its characteristic signs. Protocols with masking — VLESS Reality, Trojan — make the connection look like ordinary web traffic, and it's harder to tell apart. But it would be wrong to guarantee that this is impossible in principle: analysis tools evolve too.
What to do about it in practice
If the goal is for the ISP not to see the list of your sites, an ordinary VPN is enough, but check for a DNS leak. If the goal is for the connection not to stand out, you need a protocol with masking. VolnaLink uses VLESS Reality, Trojan and Hysteria 2; the client picks the suitable option itself.