VPN vs proxy: which do you actually need
Mullvad’s list price is €5 a month at the time of writing, and for that one VPN app covers every program on your laptop and phone. A proxy can be free or billed per gigabyte or per port, and it covers only the app you point at it. That gap is most of the answer.
I run 4G modem proxies out of Singapore, so people assume I’ll say “proxy”. Usually I say VPN. If you’re one person who wants a private connection on your own devices, get a VPN. If you need a particular kind of IP address for a particular job, like checking local search results or testing an ad from another country, get a proxy. The rest of this piece is about why, and where each one lets you down.
What it is
A VPN (virtual private network) is a service where an app on your device builds an encrypted tunnel to a server run by the VPN company. Your traffic goes into the tunnel and comes out of that server. Websites see the server’s IP address instead of yours, and your ISP sees one encrypted connection to one address.
A proxy is a server that makes requests for you. You tell one application, say a browser or a Telegram client, to send its traffic to the proxy’s address and port. The proxy forwards it and passes the reply back. Websites see the proxy’s IP. Nothing else on your device changes.
Proxies come in a few types, and the type decides what they can carry:
- HTTP or HTTPS proxy: built for web traffic. Your browser asks it to open a connection and it relays the bytes.
- SOCKS5: a lower-level protocol defined in RFC 1928. The spec covers TCP and UDP, so it can carry chat apps and game clients as well as browsers, though plenty of providers only support the TCP part.
- residential or mobile proxy: this describes where the IP address comes from, a home broadband line or a carrier’s 4G/5G network. It says nothing about the protocol, which is still HTTP or SOCKS5 underneath.
How it works
When you switch a VPN on, the app creates a virtual network adapter and changes your routing table so the default route points into it. Every packet from every app gets encrypted and sent to the VPN server, which unwraps it, forwards it, and does the reverse with the reply. That is why a VPN covers apps you never configured.
The protocol underneath matters. WireGuard is the modern default: it uses ChaCha20-Poly1305 for encryption and has been in the Linux kernel since version 5.6, released in March 2020. OpenVPN is older and usually slower. IKEv2/IPsec is common on phones because it reconnects quickly when you jump from wifi to mobile data.
A proxy is much simpler. You enter a host, a port and usually a username and password in the app’s settings. For a plain http page, the browser sends the whole request to the proxy, which fetches the page and hands it back. For an https site, the browser sends a CONNECT request (CONNECT example.com:443), the proxy opens a raw pipe to that host, and the TLS handshake happens between your browser and the site through the pipe. MDN’s page on proxy servers and tunneling walks through this. So an HTTP proxy learns which hostname you asked for, but not what the page said.
The catch: plain HTTP proxies and SOCKS5 don’t encrypt the leg between you and the proxy. Whoever sits on that leg, your cafe wifi or your ISP, can see you talking to the proxy and usually the destinations you ask it for.
Here is who sees what:
- your ISP, with a VPN: an encrypted stream to the VPN server, plus timing and volume
- your ISP, with a proxy: a connection to the proxy and usually the destinations you request
- the website, with either: the exit IP address instead of yours
- the operator, with either: the destinations you visit, and the content too if it’s plain http
That last line is the real trade: you swap your ISP for a company you picked.
Why it matters
Four situations where the choice changes what you do.
Untrusted networks. Hotel and cafe wifi are the classic case. Most of the web is https now, so someone on the same wifi can’t read your pages, but the network still sees which hostnames you look up, and my piece on what your router sees covers how much that gives away. A VPN hides that from the local network. The risk is smaller than VPN ads make it sound, and the fix is cheap.
Choosing a location. A VPN gives you an exit in another country. Streaming services know the big providers’ IP ranges and block many of them, so results vary week to week, and it’s worth reading the service’s terms before you build a habit on it.
A specific IP for a specific job. This is proxy territory, and it’s the business I’m in. Mobile carriers put many real subscribers behind one shared address, so sites are slow to ban those IPs. People use that for checking local search results (our sister site The SEO Desk covers that side), verifying ads, monitoring prices, and running separate accounts in separate browser profiles, which Antidetect Review goes into. Every platform has its own rules on multiple accounts, and the IP is only one of the signals they check.
Per-app control. A proxy lets you send one browser profile out through Singapore while everything else goes direct. Most consumer VPN apps are all or nothing, although some offer split tunnelling.
So which one? Privacy for yourself on your own devices is a VPN. Control over which IP a specific task uses is a proxy. Running both stacked is possible and occasionally makes sense, but if you’re reading an explainer to work this out, you almost certainly want the VPN.
Common misconceptions
“A VPN makes me anonymous.” It changes who can see your traffic. It doesn’t change who you are once you sign in to Google or Facebook, and it does nothing about trackers that build a profile from your browser and device, which how websites recognise you without cookies covers. If anonymity is the goal, Tor works differently and has its own costs.
“A proxy is just a cheap VPN.” The scope is different, and there’s no encryption on the hop to the proxy. Browsing on hotel wifi through a plain proxy gives you a feeling of cover and not much else.
“Free is fine for casual use.” This is the one I’ll get argued with about, but I won’t use a free VPN or a free proxy list for anything I care about. Someone is paying for those servers. In 2015 it was reported that Hola’s free tier routed other people’s traffic through its users’ machines, with the bandwidth resold through a related company, Luminati, now called Bright Data. Plenty of free services are harmless. If you can’t see how one makes money, assume it’s you.
“No-logs means nobody can see anything.” A no-logs policy is a promise. Third-party audits help, and Mullvad and Proton VPN both publish them, but an audit is a snapshot of one moment. I haven’t audited any provider myself, so everything I say about logging comes from what they and their auditors have published. The EFF’s guide to choosing a VPN makes the underlying point that a VPN shifts your trust from your ISP to the VPN company.
Where to go from here
- Tor is the other tool people weigh against a VPN. Tor vs VPN: what each actually hides sets out what each one exposes.
- Trackers don’t need your IP address at all. How websites recognise you without cookies covers the fingerprinting side, which no tunnel fixes.
- For most people a browser with sane defaults does more than any tunnel: the best private browsers in 2026.
- The privacy settings worth ten minutes are free and quick.
Everything else is on the blog index.
Written by Xavier Fok
disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-25.