Name lookup (DNS)
Unencrypted on most devices, so the network reads the site name.
Whoever runs a Wi-Fi network sees more than most people think, even on HTTPS sites. This page shows it with your own visit, worked out in your browser. Nothing is sent anywhere.
It can't read this page, or anything you type on it: HTTPS encrypts that.
Every line on the right is something the equipment of the network you're on can record. Switch to PryVPN to see what's left.
Your browser measured these while this page loaded. HTTPS doesn't hide timing or size, so the network can work out the same things.
Unencrypted on most devices, so the network reads the site name.
The handshake shows the site name (SNI) before encryption starts.
Size and timing hint at what you're doing: a video looks nothing like a message.
Visible to the network, like the server address.
What your browser says about the network, if it says anything.
The network can't read this label, but it can usually guess the same from your traffic.
The same for a café, a hotel, an office network, or whoever else controls the router.
| Without a VPN | With PryVPN | |
|---|---|---|
| Names of the sites you visit (DNS) | Yes, in plain text on most devices | No, they travel inside the tunnel |
| Site names when a connection starts (SNI) | Yes, on most sites | No |
| Addresses of the servers you reach | Yes | Only the PryVPN server's |
| When you're online, and how much data | Yes | Yes, the total but not per site |
| Your device type | Often, from network hints | Often |
| Pages, searches and passwords on HTTPS sites | No, HTTPS encrypts them | No |
| Everything on a plain HTTP site | Yes, all of it | No, it's inside the tunnel |
Safer than it used to be. Nearly every site uses HTTPS now, so the network can't read your passwords or messages. What it can still see is which sites you visit, when and for how long, and that's enough to build a detailed picture of you.
The bigger risks are networks that aren't what they claim to be: a fake hotspot with the café's name, a login page that asks for too much, or a network that redirects your lookups. A VPN puts all of your traffic behind encryption the network can't open.
We don't keep the result. Your address and your answers stay in this browser tab, and no other company is involved.
For most browsing it's safer than it used to be, because HTTPS encrypts pages and passwords. The network can still see which sites you visit and when, and fake hotspots are a real risk. A VPN hides your sites from the network and encrypts everything else.
They can see the names of the sites you visit and when, but not the pages or what you type on HTTPS sites. Incognito mode doesn't change that: it only affects what's saved on your phone. See incognito vs VPN.
It hides what you do on a site, not which site it is. The name usually travels in the open twice: in the DNS lookup and at the start of the secure connection (SNI). Encrypted DNS and Encrypted Client Hello help, but most phones and sites don't use both yet.
That your phone is connected, when, and how much data it sends in total. The network sees one encrypted connection to a VPN server instead of your sites.
Usually, against strangers nearby: mobile data is encrypted over the air and fake networks are much harder to set up. Your mobile operator still sees what a Wi-Fi operator would. See what your provider can see.
No. Everything here is worked out in your browser from your own visit, and the site you type in the box is never sent anywhere.
Whoever runs a Wi-Fi network can see your devices, which sites you visit and how much data you use. Here's what HTTPS, incognito mode and a VPN change.
Read itGuideWhat the owner of a café, hotel or airport hotspot can see, how fake hotspots work, and a simple checklist for using public Wi-Fi safely.
Read itSolutionPublic Wi-Fi lets whoever runs it see where you go online. PryVPN encrypts your traffic and connects by itself on untrusted networks. Free for Android.
Read itGuideIncognito mode and a VPN protect different things. Here is exactly what each one hides, what it doesn't, and why most people need both.
Read itHelp centerPublic Wi-Fi is where a VPN helps most, and also where VPNs get blocked most often. Here's how to get connected and stay protected.
Read itHelp centerMany public networks make you accept terms or sign in on a web page before anything works. Do that first, then connect.
Read itHelp centerPryVPN blocks known tracker and malware domains with its own DNS, and ads if you turn that on. Android's Private DNS or a custom DNS switch that blocking off.
Read itYour public IP address as sites see it, what it reveals, and whether your browser leaks another one.
Check my IPTwo questions about where you are and what you see, then the steps that fix it.
Find the fixEvery check in one place: IP, WebRTC, Wi-Fi and blocked VPNs.
All toolsPryVPN encrypts everything between your phone and our server, on every network. Free, no activity logs, WireGuard. Join the beta.