Privacy & security

VPN, DNS and HTTPS Explained: What Actually Protects Your Privacy Online

VPN, DNS and HTTPS explained in plain English: what each one hides, who can still see your browsing, and the simple settings that really protect your privacy.

GIGAXXX Editorial7 min readUpdated

Glowing fiber-optic strands in magenta and cyan

Key takeaways

  • HTTPS encrypts what you do on a site, but the site's domain name and IP address can still be visible to your network and ISP.
  • Encrypted DNS (DoH or DoT) hides your lookups from your network and ISP, and family resolvers such as 1.1.1.3 add filtering.
  • A VPN hides the sites you visit from your ISP and your IP address from websites, but it shifts that visibility to the VPN provider.
  • Free VPNs often pay their bills with your data, so an established, independently audited paid provider is the safer choice.
  • No tool hides your activity from the website itself or cleans up your device, so private windows and clearing history still matter.
On this page
  1. HTTPS: what the padlock protects
  2. DNS: the internet’s address book
  3. VPNs: moving trust, not removing it
  4. Who can see what
  5. A practical setup for most people
  6. Where GIGAXXX fits in
  7. The bottom line

HTTPS, encrypted DNS and VPNs all promise privacy, but each one hides different things from different people. Knowing which layer does what is the difference between feeling private and actually being private. Here’s what each technology protects, where the gaps are, and a simple setup that covers most people.

HTTPS: what the padlock protects

HTTPS is the encrypted version of HTTP, the protocol your browser uses to load web pages. Using TLS encryption, it does three jobs: it scrambles the traffic between your browser and the site, it proves through a certificate that you’ve reached the real domain, and it stops anyone in between from reading or changing what you see.

What HTTPS hides

On an HTTPS connection, your Wi-Fi network, your internet service provider (ISP) and anyone else along the way can’t read:

  • the specific pages you open, meaning everything in the address after the domain name, including search terms;
  • what you type into forms, including passwords;
  • the pages, images and videos themselves;
  • cookies and the other details your browser sends.

What HTTPS doesn’t hide

HTTPS protects the conversation, not the fact that it’s taking place. Observers can still see:

  • your IP address and the IP address of the server you connect to;
  • in most cases, the domain name. Your device looks it up through DNS, often unencrypted, and your browser names the site at the start of the connection in a field called Server Name Indication (SNI), so the server knows which certificate to present. A newer standard, Encrypted Client Hello (ECH), hides that field, but only when both your browser and the site support it;
  • when you connect, and roughly how much data moves.

HTTPS doesn’t protect you from the website either: the site sees everything you do on it.

A padlock is not a seal of approval

HTTPS means the connection is private, not that the site is honest or safe. Scam and phishing sites get certificates too, so check the domain name carefully. Our guide to spotting fake adult sites and scams shows what to look for.

DNS: the internet’s address book

Before your browser can connect to a site, it has to turn the name into an IP address. That lookup is DNS, the Domain Name System. By default, it goes to a resolver chosen by your network, usually your ISP’s or your router’s, and it travels in plain text. Whoever handles it can see, log, block or redirect the names you look up.

Encrypted DNS: DoH and DoT

Two standards encrypt those lookups:

  • DNS over HTTPS (DoH) carries them inside ordinary HTTPS traffic. Major browsers offer it under names such as Secure DNS or DNS over HTTPS, and Windows 11 supports it system-wide.
  • DNS over TLS (DoT) encrypts them over a dedicated connection. Android’s Private DNS setting is built on it.

Encrypted DNS hides your lookups from the local network and your ISP, but the DNS provider you choose still sees them, so pick one with a clear privacy policy. It also doesn’t hide the site’s IP address or, without ECH, the domain name in SNI.

Family DNS filters

Some resolvers filter as well as answer. Cloudflare for Families offers 1.1.1.3, which blocks known malware and adult content for every device that uses it, a free extra layer when you set it on a family router. It supports encrypted DNS too.

One catch: a browser configured with its own secure DNS provider can bypass a filter set on the router. Set the same resolver in the browser, or lock the settings with parental controls; our parental controls guide walks through it device by device.

VPNs: moving trust, not removing it

A virtual private network (VPN) creates an encrypted tunnel from your device to a server run by the VPN provider. Your traffic, including DNS lookups in a well-built app, goes through the tunnel and reaches the internet from that server.

What a VPN hides, and from whom

  • From your network and ISP: which sites you visit. They see only that you’re connected to a VPN server, when, and how much data flows. That’s valuable on public Wi-Fi in hotels, airports and coffee shops.
  • From websites: your real IP address, and with it your approximate location. Sites see the VPN server’s address instead.

What a VPN doesn’t hide

  • From the VPN provider: it now sits where your ISP used to. It can see your real IP address and the sites you connect to, and it could log them.
  • From the websites themselves: everything you do on the site, plus cookies, logins and browser fingerprinting that can recognize you whatever your IP address.
  • From your own device: browser history, saved passwords and downloads stay where they are.

A VPN doesn’t change the law either. GIGAXXX’s rules, for example, require you to be 18 or the age of majority where you live, whichever is higher, and viewing adult content must be legal where you are, whatever your connection. And because many people share each VPN address, sites protected by security services such as Cloudflare may sometimes ask you to confirm that you’re human.

Why free VPNs are a risk

Running VPN servers costs money. If you aren’t paying, the provider is usually making money another way:

  • collecting and selling your browsing data;
  • injecting ads or tracking into your traffic;
  • reselling your bandwidth by routing other people’s traffic through your connection;
  • shipping apps with malware, weak encryption or DNS leaks that expose the very lookups you meant to hide.

If you use a VPN, choose an established paid provider whose no-logs policy has been independently audited, with a kill switch that blocks traffic if the tunnel drops, and install its apps from official app stores.

Who can see what

Here’s how the layers combine in practice.

Your setup Your network and ISP see The website sees The VPN provider sees
HTTPS only Your IP, the site’s IP and domain (via DNS and SNI), timing and data volume, but not pages or content Your IP address and everything you do on the site Nothing, it isn’t involved
HTTPS + encrypted DNS The site’s IP and usually its domain (via SNI), but not your DNS lookups, which go to the resolver you chose Your IP address and everything you do on the site Nothing, it isn’t involved
HTTPS + VPN That you use a VPN, when, and how much data, but not which sites The VPN server’s IP instead of yours, and everything you do on the site Your real IP, the sites you connect to and when, but not content protected by HTTPS

Two things never change: the website always sees what you do on it, and your own device keeps its history unless you browse privately or clear it.

A practical setup for most people

  1. Keep your browser and system updated. Updates bring security fixes and newer protections such as ECH.
  2. Turn on HTTPS-only browsing. It’s called HTTPS-Only Mode in Firefox and Always use secure connections in Chrome. Never click through a certificate warning.
  3. Switch on encrypted DNS in your browser or system settings, under Secure DNS, DNS over HTTPS or Private DNS.
  4. Add a filter on family devices. A resolver such as 1.1.1.3, combined with parental controls on each device, covers most homes.
  5. Use a VPN on networks you don’t control, such as public Wi-Fi, or when you don’t want websites to see your IP address. Pick a reputable paid provider and skip free VPNs.
  6. Look after the device itself. Use a private window on a shared device and clear your history when needed; our guides to incognito mode and clearing your browsing history cover both.

Where GIGAXXX fits in

Whatever setup you choose, the website you visit still sees your requests, so what it does with them matters as much as how you connect. At present, GIGAXXX itself sets no cookies and uses no analytics, advertising cookies, third-party trackers, or third-party fonts or embeds; the only third-party script is Cloudflare’s anti-spam check, which loads only on our contact and report forms.

Cloudflare, our CDN and security provider, processes every request, including your IP address, to deliver and protect the site, and may set strictly necessary security cookies. Our server’s access logs are deleted automatically after about 5 days, and features such as Watch later and Favorites are stored only in your browser. The details are in our Privacy Policy.

The bottom line

HTTPS protects what you send and receive, encrypted DNS hides your lookups from your local network and ISP, and a VPN hides the sites you visit from your ISP and your IP address from websites, by handing that visibility to the VPN provider. None of them hides what you do from the site itself or cleans up your device. Turn on HTTPS-only mode and encrypted DNS, add a family filter where children share the connection, use a reputable paid VPN on networks you don’t control, and favor sites that collect as little as possible.

Frequently asked questions

Does HTTPS hide which websites I visit?

Not completely. HTTPS encrypts the pages you open and everything you send, but your network and ISP can usually still see the site’s domain name, through DNS lookups and the Server Name Indication field, plus the server’s IP address. Encrypted DNS and a VPN close most of that gap.

Does a VPN make me anonymous?

No. A VPN hides the sites you visit from your ISP and your IP address from websites, but the VPN provider can see which sites you connect to, and websites still see everything you do on them, along with cookies and logins. It improves privacy without making you anonymous.

What is 1.1.1.3?

It’s the Cloudflare for Families DNS resolver that blocks known malware and adult content. Set it on your router to cover the devices on your home network, or on a single device, ideally with encrypted DNS. It’s free, and it works best combined with parental controls on each device.

Are free VPNs safe to use?

Many are not. Running a VPN is expensive, so free services often make money by collecting or selling browsing data, injecting ads or reselling your bandwidth, and some apps contain malware. If privacy matters to you, choose a paid provider with an independently audited no-logs policy.

Guides are general information, not legal or technical advice for your specific situation. Menu names in apps and devices can change with updates.

Keep reading

GIGAXXX currently uses only essential browser storage for the settings you choose. If analytics or advertising are ever added, they stay off until you allow them.

EssentialOrientation, saved videos and history (if enabled). Always on.
AnalyticsAnonymous usage statistics. Not in use yet.
AdvertisingAd personalization and measurement. Not in use yet.

See our Cookie Policy and Privacy Policy.