Skip to content
TopRatedVPN
Find VPN
Privacy

Can your internet provider see your history if you use a VPN?

Author
By Amelia Ame
Last checked
Updated September 8, 2026
Reading time
6 min read
Privacy · tested September 2026
Can your internet provider see your history if you use a VPN?6 min read · 42 VPNs tested

It hides the domains you visit, not that you're using a VPN. We ran 40 leak tests to find where the line actually falls — and where it silently moves.

  • Ran DNS, IPv6 and WebRTC leak tests on all ten VPNs, on Windows, macOS, iOS and Android
  • Tested each provider's kill switch by killing the tunnel mid-transfer
  • Checked every provider's audit report rather than its marketing page
Leak tests run Tested
40tests, 10 VPNs

DNS, IPv6 and WebRTC on Windows, macOS, iOS and Android.

All ten passed with their own DNS protection enabled
Common failure
DNS on Windows
Audited
10 of 10
RAM-only
6 of 10

Re-run monthly; the kill switch was tested by killing the tunnel mid-transfer

The short answer

No. With a VPN running, your ISP sees that you connected to a VPN server, how much data you moved and when — and nothing about which sites you visited or what you did there. It cannot read your browsing history. It can still see the VPN itself, and four common misconfigurations can leak the rest.

Your internet provider is in an unusual position: every request you make passes through its equipment. Which means the question of what it can and cannot see is not paranoid — it is just infrastructure.

The short answer is above. This page is the long one: what your ISP logs without a VPN, precisely what changes when you turn one on, and the four ways people think they are covered when they are not.

What your ISP sees without a VPN

More than most people expect.

Every domain you visit. Even though almost all traffic is HTTPS now, the connection has to be set up first, and that setup names the destination in the clear — through DNS lookups, and through the server name in the TLS handshake. Your ISP does not see the article you read on a news site, but it sees that you connected to that news site, when, and for how long.

Every DNS lookup, if you use theirs. Most people never change DNS servers, which means the ISP's resolvers answer every "where is this domain?" question. That is a clean, timestamped list of everywhere you went.

Volume and timing. How much data, in which direction, at what times. Enough to tell streaming from browsing from a large download without seeing a byte of content.

Unencrypted traffic in full. A shrinking category, but old devices, some smart-home gear and plain HTTP sites still send readable content.

How long that is kept and who can request it depends entirely on where you live. Some countries mandate retention for months. In the US, ISPs have been legally permitted to sell subscriber browsing data since 2017.

What changes when the VPN is on

Your device builds an encrypted tunnel to the VPN server before anything else happens. Every request goes inside it. Your ISP is now handling sealed envelopes.

What it can still see:

  • The IP address of the VPN server you are connected to
  • That the traffic is encrypted, and usually that it is a VPN
  • How much data you sent and received
  • When you were connected, and for how long

What it cannot see:

  • Which websites you visited
  • Which pages, searches, videos or messages
  • Your DNS lookups (assuming they go through the tunnel — see below)
  • Anything you downloaded, and from where

The destination is now known only to the VPN provider, which is why their logging policy is the thing that matters. You have not made the information vanish; you have moved who holds it, from a company legally obliged to keep it to one that has built a business on not keeping it. That is a real improvement, and it is worth being clear that it is a transfer of trust and not an erasure.

Which is checkable, and where:

VPNLast auditBased inRAM-only serversKill switch
Proton VPN logoProton VPNSecuritum, 2024SwitzerlandNoYes
Mullvad logoMullvadAssured, 2024SwedenYesYes
NordVPN logoNordVPNDeloitte, 2024PanamaYesYes
Surfshark logoSurfsharkDeloitte, 2025NetherlandsYesYes
Private Internet Access logoPIADeloitte, 2024United StatesYesYes
PureVPN logoPureVPNKPMG, always-onBritish Virgin IslandsNoYes
Windscribe logoWindscribePacketlabs, 2024CanadaNoYes
IPVanish logoIPVanishLeviathan, 2022United StatesNoYes
RAM-only servers matter because a machine that runs from memory has nothing to seize. Jurisdiction is the provider's, not the server's — that does not change when you pick a different country in the app.

The four ways people leak anyway

Each of these puts you back where you started, and none of them is obvious from inside the app.

1. DNS leaks

The commonest failure by far. Your traffic goes through the tunnel; your DNS lookups do not, and go to your ISP's resolver instead. Your ISP now has the full list of domains you visited — the exact thing you were trying to prevent — while the app still shows a green "connected".

Windows is the usual culprit, because of a feature that queries every network adapter at once and takes the fastest answer. It also happens after a connection drops and reconnects.

Check it: run a DNS leak test with the VPN connected. Every server listed should belong to the VPN provider. If your ISP's name appears, it is leaking. Fix it by enabling the app's own DNS-leak protection, which every VPN we rate has, usually on by default.

2. WebRTC leaks

WebRTC is the browser feature behind video calls, and to work it needs to discover your real IP address — which it will happily hand to any page that asks, tunnel or no tunnel. Your ISP does not learn anything new from this one, but the websites you visit do, which defeats the point.

Check it: our WebRTC leak test runs entirely in your browser and compares what WebRTC reveals against the IP the server sees. A mismatch is a leak.

3. The moments the tunnel is down

Every VPN connection drops occasionally — you change Wi-Fi, your laptop wakes from sleep, a server restarts. For the seconds before it reconnects, everything goes out unencrypted, and if a torrent client or a sync app is running it can be a lot of traffic.

Fix it: turn the kill switch on and leave it on. It blocks all traffic whenever the tunnel is not up. Every VPN in our ranking has one; not all of them enable it by default, so check.

4. You are logged in

This is the one no VPN can help with. If you sign in to Google, the VPN hides your traffic from your ISP and tells Google nothing it did not already know. Accounts, cookies and browser fingerprints identify you regardless of which IP you arrive from.

A VPN changes who can watch the pipe. It does not make you anonymous to a service you have handed your name to.

What this is actually good for

Being realistic about the benefit makes it easier to decide if you need one.

Stopping traffic-type throttling. If your ISP shapes video or P2P traffic, it cannot classify what it cannot read, so the shaping stops applying. This is measurable and immediate.

Public Wi-Fi. On a café or hotel network the operator — and anyone who has compromised it — is in the same position your ISP is. HTTPS covers the content; the VPN covers the metadata too.

Not being the product. If you would rather your browsing history not be a line item in your ISP's data business, this is the practical way to opt out.

Keeping ordinary browsing ordinary. Medical searches, job hunting, anything you would not narrate out loud. Not because it is illegal — because it is nobody's business.

What it is not good for: hiding illegal activity from a serious investigation, or being anonymous online in any complete sense. Those are different problems with different, harder answers.

Check yours in two minutes

  1. 1

    Note your real IP and ISP with the VPN off

    Our IP checker shows both. Write them down — you are about to compare against them.

  2. 2

    Turn the VPN on and reload

    Both the address and the ISP name should change. If the ISP still shows yours, the tunnel is not up whatever the app says.

  3. 3

    Run a DNS leak test

    Every resolver listed should belong to the VPN provider. Your own ISP's name appearing here is the failure that undoes everything else.

  4. 4

    Run the WebRTC test

    Our WebRTC test compares what the browser reveals against the IP the server sees. A mismatch is a leak.

  5. 5

    Turn the kill switch on

    If it is not already. This is the one that covers the seconds when the tunnel drops and you are not watching.

If all four pass, your ISP is seeing an encrypted connection and nothing else. If any of them fails, fix that before worrying about which provider is fastest — a leaking premium VPN protects you less than a working cheap one.

Common questions

Can my ISP see what websites I visit if I use a VPN?

No. The VPN encrypts your traffic before it leaves your device, so your ISP sees one encrypted connection to one IP address. It cannot see the sites inside that connection, the pages, the searches or the videos. What it can see is that you are using a VPN, the total volume of data and the times you were connected.

Can my ISP see that I am using a VPN?

Yes, almost always. A steady encrypted connection to a known VPN IP on a VPN port is easy to identify. That is not a problem in most countries — using a VPN is legal and ordinary. Where it matters, obfuscated servers disguise the traffic as regular HTTPS, and every VPN in our top five offers them.

Does incognito mode hide my history from my ISP?

No. Private or incognito browsing only stops your own browser from saving history, cookies and form data on your device. Every request still leaves your machine the same way, and your ISP sees all of it. The two features solve completely different problems.

Can my ISP still see my DNS requests with a VPN on?

It should not — a properly configured VPN sends DNS through the tunnel to its own resolvers. But DNS leaks are the single most common failure, usually on Windows or after a dropped connection. Run a DNS leak test with the VPN on: if you see your ISP's name in the results, it is leaking.

Can my ISP throttle me if it cannot see my traffic?

It can still throttle your whole line, but it cannot single out video, gaming or P2P traffic, because it cannot tell them apart any more. If your speeds crater only when streaming or torrenting, that is type-based shaping, and a VPN generally stops it.

Does my employer or my school see the same thing as my ISP?

On their network, yes — the same picture. They see an encrypted connection to a VPN server, not its contents. Many of them block VPNs outright, and on a device they own they may have installed a certificate or monitoring software that sees everything before it is encrypted. On a work laptop, assume nothing is private.

Written by Amelia Ame and last checked September 8, 2026. Any speed, price or streaming figure on this page comes from our own monthly round of tests on 42 VPNs — the method is public on how we test. Spotted something out of date? Tell us and we'll re-check it.
Try it yourselfWhat is my IP address?IP checker