VPN basics · Plain-English answer
A VPN works by encrypting your traffic on your device, sending it through a secure tunnel to a VPN server, then passing it on to the internet from there. Websites see the server's IP address, not yours, and anyone watching your local connection sees only scrambled data going to one server.
First, the VPN app on your device and the VPN server agree on encryption keys. From that point, every packet your device sends is encrypted before it leaves your network card. The packets travel across your normal internet connection to the VPN server, which decrypts them and forwards them to their real destination.
Replies come back the same way in reverse. The server encrypts them and sends them down the tunnel, and your device decrypts them locally. To the outside world, all your traffic appears to come from the server.
The rules for building that tunnel are called a VPN protocol. Older protocols like OpenVPN and IKEv2 are still common, while WireGuard is a newer design that uses modern cryptography with far less code, which generally means faster speeds and quicker connections. ROOT VPN is built on WireGuard for exactly that reason.
Whatever the protocol, the principle is the same. Encryption hides the content of your traffic, and the server hides your IP address from the sites you visit.
More from the ROOT VPN answers hub.
ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.
Get ROOT VPN, free