Most pages answering this question sell a VPN in the second paragraph. Here is the answer we actually reach after describing what happens on a home connection: for most people at home, a VPN adds far less than the advertising implies, and there are four specific cases where it genuinely helps.
What is already protected without one
Two things changed in the last decade and both work against the standard sales pitch.
Your home network is already encrypted. WPA2 and WPA3 encrypt the link between your device and your router. A neighbour with an antenna does not read your traffic.
Nearly every site is served over HTTPS. TLS 1.3, published as RFC 8446 in August 2018, encrypts the content of the exchange end to end. Your provider, the network and anyone in between cannot read the page, the message or the form you submit.
So the content is not the exposed part. Something else is.
What your provider can still see
The honest list is short and specific.
The destination address, and usually the server name. Even over HTTPS, the address you connect to is visible, and the server name travels in the clear during the handshake unless encrypted client hello is in use. Your DNS lookups are visible too, unless you have enabled DNS over HTTPS (RFC 8484, October 2018) or DNS over TLS on port 853 (RFC 7858, May 2016).
Timing and volume. When you connect, for how long, and how much passes.
That is a list of places and times, not a transcript. A VPN hides that list from your provider and shows it to the VPN company instead. That can be a genuine improvement, because you chose the VPN company and you did not choose your provider. It is a transfer of trust, not a removal of it, and the pages that call it anonymity are overselling.

The situation the question is really about. On this sofa, on this network, most of the protection is already in place before any VPN is installed.
The four cases where it does help at home
Your provider or your country filters or logs. Where connection records are retained by law, or sites are blocked at the network level, a VPN changes what is recorded and what you can reach. This is the strongest case and it is not hypothetical in many countries.
You need an address in another country for something you pay for. A subscription that follows you across a border is a legitimate use, and it is the one most people actually buy for.
You share the connection, or you are on someone else's. A building network, a landlord's router, a flatshare where you do not control the equipment: the network operator changes, and so does the calculation. The same reasoning applies to a shared connection you did not set up, and the comparison with a phone hotspot is covered in mobile hotspot versus public Wi-Fi.
A device on your network cannot be trusted. A VPN on your own machine limits what a compromised device elsewhere in the house can observe.
Outside these four, the honest answer for a home connection is that a VPN adds little that HTTPS and WPA3 are not already doing.
What it costs you when you do not need it
Speed. Your traffic takes a longer path through another server. On a fast line this is often unnoticeable; on a slow one it is not.
Sites that break. Streaming services, banks and online shops frequently block known VPN address ranges. The failures look like bugs rather than blocks, which makes them annoying to diagnose.
One company holding the whole list. Without a VPN, the list of domains is split between your provider and your DNS resolver. With one, it is concentrated in a single company's logs. That is fine if you trust them more than your provider, and it is worth being deliberate about.
See NordVPN's current offer
If one of the four cases above describes you, this is a reasonable place to start. If none of them does, the honest recommendation is to enable encrypted DNS on your router and spend nothing.
What to do instead, if none of the four apply
- Turn on encrypted DNS. Most routers and all major browsers support DNS over HTTPS. It removes the easiest part of the list from your provider's view, and it is free.
- Check that WPA3 is enabled on your router if the hardware supports it.
- Keep the browser updated, since encrypted client hello is arriving through browser and server updates rather than through anything you buy.
Private browsing is not part of this list, and the reason is worth reading once: incognito mode hides your history from the device, not your address from the network.
The short version
- At home, on your own encrypted Wi-Fi, most of the protection is already there. HTTPS covers the content.
- What remains visible is a list of domains and times, not what you read or wrote.
- A VPN moves that list to a company you chose. That is useful, and it is not anonymity.
- Four cases justify it: filtering or logging, a paid service in another country, a network you do not control, an untrusted device at home.
- If none applies, enable encrypted DNS and keep your money.
We describe what these protocols do and where the visibility sits. Commercial links carry the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.
Privacy-first VPN → Proton VPN
Audited no-logs · Swiss jurisdiction · open-source · free tier



