Home/Answers/VPN basics

VPN basics · Plain-English answer

What is a VPN tunnel?

A VPN tunnel is the encrypted connection between your device and a VPN server. Your traffic is wrapped inside encrypted packets, travels across the ordinary internet, and is unwrapped at the server. Anyone in between sees only scrambled data addressed to the server, not what you are actually doing.

Why it is called a tunnel

Your packets still cross the same physical internet as everyone else's. The tunnel is a metaphor for encapsulation. Each original packet is encrypted and placed inside a new packet addressed to the VPN server, like a sealed letter inside an outer envelope. Routers along the way handle the outer envelope only. The server opens it, decrypts the contents, and sends your original traffic on to its destination.

Because only your device and the server hold the keys, nothing in between can read or tamper with the contents.

Protocols and tunnel integrity

The protocol defines how the tunnel is built and secured. WireGuard, which ROOT VPN uses, establishes tunnels almost instantly and re-establishes them smoothly when you change networks, which older protocols handled poorly.

A tunnel is only as good as its coverage. If DNS queries slip outside it, observers can still see which sites you visit, so it is worth running the checker at /tools/dns-leak-test/ once after setup to confirm everything flows through the tunnel.

Related questions

Can my ISP see inside the VPN tunnel?
No. Your ISP sees encrypted packets going to one server and can measure volume and timing, but the content and destinations of your traffic are hidden.
What happens if the tunnel drops?
Without protection, your device falls back to the open connection and exposes your real IP. A kill switch blocks traffic until the tunnel is rebuilt.

Keep reading

More from the ROOT VPN answers hub.

Private in one tap.

ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.

Get ROOT VPN, free