Also on CyberFence: compare CyberFence to other VPNs side-by-side · the free CyberFence security tools .

Man in dark blazer focused on laptop screen in blue-lit modern apartment at dusk with city lights visible through window and bookshelf beside him

The direct answer is layered: parts of your VPN use can be detected by different parties, but the content of what you do online cannot be read when a properly functioning VPN is active. Understanding which observers can see what — and under what circumstances — is the practical privacy knowledge most VPN explainers leave out.

Here's a precise breakdown of what your ISP, the government, the websites you visit, and other parties can actually track when you're using a VPN.

What Your ISP Can See

Your Internet Service Provider routes all of your internet traffic — with or without a VPN. When you connect to a VPN, they still see every packet that leaves your home, but the information they have access to changes significantly.

What your ISP CAN see with a VPN on:

  • That you're connecting to a VPN server (they can see the destination IP address, which belongs to the VPN provider)
  • The volume of data you're transmitting (how many bytes, roughly when)
  • That you're using an encrypted connection (the packets are clearly VPN protocol traffic)
  • Timing patterns — when you connect, disconnect, and how long sessions last

What your ISP CANNOT see with a VPN on:

  • Which websites you're visiting (the DNS queries and HTTP requests go through the VPN tunnel)
  • The content of any page, search, message, or file
  • Your actual browsing history
  • What services you're using (streaming, email, banking — all encrypted)

In practical terms: your ISP knows you're using a VPN, but cannot tell anyone what you're doing with it. For ISPs that sell anonymized browsing data to advertisers, a VPN makes that data nearly useless.

What the Government Can See

Government tracking of VPN use operates through several different channels, each with different capabilities:

Through your ISP

Law enforcement can subpoena your ISP for records of your internet activity. With a VPN active, those records show only that you connected to a VPN server at certain times — not what you did there. This is why VPN use significantly limits what ISP records reveal in a legal context.

Through the VPN provider

If law enforcement serves legal process on the VPN provider, the provider's response depends entirely on what they log. VPN providers with genuine zero-log policies have no connection logs, activity logs, or timestamps to provide — there's nothing to hand over. Providers that log connection times, IP addresses, or session data can be compelled to produce those records.

CyberFence maintains a verified zero-log policy: no connection logs, no session timestamps, no activity records. There is nothing to compel in response to legal process because the data doesn't exist.

Through traffic analysis

Sophisticated intelligence agencies with access to large segments of internet infrastructure can potentially correlate VPN traffic through traffic timing analysis — matching the timing and volume of encrypted traffic entering the VPN with traffic exiting on the other side. This is technically complex and operationally expensive, and is generally limited to high-value national security targets rather than general surveillance. For ordinary privacy purposes against ordinary threats, VPN encryption is effective.

Through your device

A VPN doesn't protect data that's collected directly from your device. If a government has legal authority to examine your device or install monitoring software, a VPN doesn't prevent that access. Device-level surveillance is a different threat model than network-level surveillance.

Zero-Log VPN — Nothing to Track, Nothing to Hand Over

CyberFence maintains a strict zero-log policy: no connection logs, no timestamps, no activity records. AES-256-GCM encryption, US-operated infrastructure. Start your free trial.

See Plans →

What Websites Can See

Websites you visit while connected to a VPN see requests coming from the VPN server's IP address — not yours. But they collect other signals that may partially identify you:

What websites see with a VPN on:

  • The VPN server's IP address (not your real IP)
  • Your browser's user agent string (browser type and version)
  • Your screen resolution, timezone, and system fonts (browser fingerprint signals)
  • Cookies set during previous visits (if you're using the same browser profile)
  • Your logged-in account identity (if you sign in)

What websites cannot see with a VPN on:

  • Your real IP address
  • Your actual geographic location (they see the VPN server's location)
  • Your ISP or the network you're connecting from

The practical implication: a VPN prevents IP-based tracking. But if you log in to Google, Facebook, or any other account while using a VPN, those services know who you are through your account — the VPN only masks your IP, not your authenticated identity.

What Advertisers Can See

Online advertising relies on multiple tracking mechanisms. A VPN defeats some of them but not others:

Defeated by VPN:

  • IP address-based targeting (your IP is replaced with the VPN server's IP)
  • ISP-level data that advertisers purchase (your ISP can't see your browsing to sell it)
  • Cross-site tracking that uses IP correlation to link activity across different websites

Not defeated by VPN alone:

  • Cookie-based tracking (cookies follow your browser session regardless of VPN)
  • Browser fingerprinting (your device's unique combination of settings, fonts, timezone, and hardware identifies you without IP)
  • Tracking pixels in email (email clients load tracking images regardless of VPN)
  • Google/Facebook tracking when you're logged into those accounts

For comprehensive ad tracking reduction, a VPN is most effective when combined with a privacy-focused browser, tracking protection extensions, and regular cookie clearing. CyberFence's Web Shield DNS filtering adds another layer by blocking known tracking and advertising domains at the DNS level — before your browser loads them.

Can VPN Traffic Be Identified by Deep Packet Inspection?

Deep Packet Inspection (DPI) is a technique that some ISPs and governments use to analyze network traffic patterns. DPI can often detect that traffic is VPN-encrypted — and can sometimes identify the specific VPN protocol being used — without being able to read the content.

Some countries use DPI to block VPN traffic or detect VPN use for regulatory purposes. Modern VPN protocols have developed obfuscation features that disguise VPN traffic to look like ordinary HTTPS traffic, making DPI-based detection significantly harder. WireGuard — the protocol CyberFence uses — has a distinct packet signature that can be detected by DPI; obfuscated versions of WireGuard traffic make detection more difficult but not impossible.

For most users in countries with open internet access, DPI-based VPN detection is not a relevant threat. It becomes relevant in jurisdictions where VPN use itself is restricted.

When a VPN Doesn't Fully Protect You

Knowing the scenarios where a VPN's protection is incomplete helps calibrate realistic expectations:

  • WebRTC leaks — some browsers can expose your real IP address through WebRTC connections that bypass the VPN tunnel. Disabling WebRTC in browser settings or using CyberFence's leak protection closes this gap.
  • DNS leaks — if DNS queries are sent to your ISP's servers rather than through the VPN tunnel, your ISP can see which domains you're looking up. CyberFence routes all DNS through its own encrypted servers to prevent this.
  • Account login — any account you're logged into knows who you are regardless of VPN status. The VPN masks your IP but not your authenticated identity.
  • VPN kill switch disabled — if your VPN connection drops and you don't have a kill switch active, your device briefly uses your real IP until the VPN reconnects. Always enable the kill switch.
  • The VPN provider itself — your traffic is encrypted to the VPN server and decrypted there before continuing to its destination. The VPN provider can theoretically see your traffic. This is why zero-log policies and jurisdiction matter.

What "Can't Be Tracked" Actually Means With a Good VPN

With a properly configured, zero-log VPN using strong encryption:

  • Your ISP cannot see your browsing content or history
  • Your real IP address is invisible to websites
  • IP-based ad targeting and cross-site IP correlation is broken
  • Your ISP records (if subpoenaed) show only that you used a VPN
  • The VPN provider (if subpoenaed) has no records to produce
  • Network-level surveillance on public Wi-Fi cannot read your traffic

What remains visible: that you're using a VPN (to your ISP and network-level observers), your browser fingerprint and cookies (to websites), and your identity when you're logged into accounts.

For most people's practical privacy goals — protecting browsing from ISP data collection, preventing IP-based tracking, securing connections on public Wi-Fi, and limiting what a data subpoena could reveal — a zero-log VPN with strong encryption accomplishes exactly what it's supposed to.

A VPN That's Built to Have Nothing to Hand Over

CyberFence: zero-log policy, AES-256-GCM encryption, US-operated infrastructure, Web Shield DNS filtering. Download from the App Store or Google Play and start your free trial.

View Plans →

Want to go deeper? Read the CyberFence competitor comparison hub , our free privacy and security tools , or CyberFence plans and pricing .