How do VPNs work? One request, start to finish

Open one page with the key on, and watch who sees what.

The short version of the trip

With the key on, a request from your phone takes a detour. It is encrypted on the phone, travels to a Softech VPN server, leaves from there to the site, and the answer returns along the same path. Everyone along the way sees a little less than before, except the VPN server, which now stands where your provider used to.

One request, step by step

  1. 1

    You tap a link to a scores page. The client catches the request before it leaves the phone.

  2. 2

    The phone needs the site's address, so it asks a DNS server; in full-device mode that question goes inside the tunnel.

  3. 3

    The client wraps the request in TLS 1.3 and sends it to the Softech VPN server. To the Wi-Fi, it looks like an ordinary HTTPS connection to one address.

  4. 4

    The server unwraps it and sends the request to the scores site from its own IP address.

  5. 5

    The site answers the server. The server wraps the answer and sends it back.

  6. 6

    The client unwraps it and hands the page to the browser, a fraction of a second later than without the detour.

The same trip with the key off

  • Your phone asks your provider's DNS server for the site's address, so the provider learns the name.
  • The opening handshake of the HTTPS connection usually carries the site's name in the clear as well.
  • The Wi-Fi owner and the provider see each site you open, though not the pages themselves.
  • The scores site sees your home IP address and the area it belongs to.

Who sees what along the way

  • The Wi-Fi owner and your provider see one encrypted connection, its timing and its size.
  • The Softech VPN server sees that a key reached the scores site, but not the content of the page.
  • The scores site sees the server's IP address, plus anything you give it by signing in.
  • Your phone sees everything, as before.

Where the time goes

The detour adds distance, and distance is what you feel. A server in your region adds a few milliseconds; one across the country adds more, and one overseas more still. Encryption itself costs very little on a modern phone. That is why the nearest server in the bot is almost always the right one.

The settings that change the path

Four settings decide which traffic takes the detour. The mode, full-device or proxy, decides whether every app goes through. Per-app rules, also called split tunneling, let chosen apps skip it. The DNS option decides whether address lookups stay inside. Auto-connect decides whether the tunnel comes back after the phone sleeps or changes networks.

Get those four right and the step-by-step above holds for every app on the device. That, in practice, is how VPNs work on a phone.

Questions

Is my data decrypted on the VPN server?

The tunnel layer is. If the site uses HTTPS, the page itself stays encrypted end to end.

Does a VPN change my DNS?

In full-device mode, DNS lookups go through the tunnel instead of to your provider.

Why is the first page slower?

The client sets up the tunnel first. After that, pages load at almost normal speed.

Can the VPN server change the pages I see?

Not on HTTPS sites; the page is encrypted between you and the site.

What does the scores site know about me?

The server's address and approximate location, and whatever your account or cookies tell it.

Back to How it works

First pitch in 60 seconds

Five free days on every screen in the house. No card, no account.

Get 5 days freeOpens Telegram