One click, traced
You tap a link. Without a VPN, your device asks a DNS server for the site's address and sends the request straight there, and every network along the way can see where it is headed. With a VPN, the request is encrypted on your device and addressed to the VPN server. The Wi-Fi, the provider and everything in between see a sealed packet on its way to one address. The server opens it, sends the real request onward under its own name, takes the reply, seals it and sends it back. Your browser never notices the difference.
That is how VPNs work, every time, for every app.
The same thing in five stages
Handshake: your client and the server prove who they are and agree on temporary keys. With VLESS over Reality this looks like the start of any secure website visit.
Capture: the client creates a virtual network adapter, and the system sends traffic into it.
Wrap: every outgoing packet is encrypted and placed inside a packet addressed to the server.
Exit: the server unwraps it and forwards the original request from its own address.
Return: the answer takes the same route back, and the client hands it to the app that asked for it.
What each party can see
- The Wi-Fi owner and your provider: that you are connected to one server, how much data moves and when.
- The VPN server: your real address and the destinations. It cannot read pages protected by HTTPS.
- The website: the server's address, plus whatever you reveal by logging in.
- Nobody along the path: the contents of HTTPS pages.
How to VPN settings, the short list
Searches like how to VPN settings suggest a wall of options. Three of them matter. Mode: proxy mode covers programs that follow the system proxy, and TUN or VPN mode covers the whole device. DNS: lookups should travel inside the tunnel, and clients have a switch for it. Routing: you can leave one app or one site outside, which helps with a fussy banking app. Ports, ciphers and keys are all contained in the vless:// line, and importing it sets them.
Where it can leak
- DNS lookups that go to your provider instead of through the tunnel.
- IPv6 traffic, when the tunnel carries only IPv4.
- WebRTC inside the browser, which can reveal addresses to a web page.
- Programs that ignore the system proxy while the client is in proxy mode.
- A dropped tunnel with nothing set to block traffic until it returns.
Proof that yours works
- An IP lookup shows the server's city and a hosting company.
- A DNS leak test shows none of your provider's servers.
- An app outside the browser also shows the new address.
- After waking from sleep, the result is still the same.
- When you disconnect on purpose, your own address comes back.
If you wondered what is VPN how does it works, try it
Reading explains the mechanism. Thirty seconds with a real key makes it obvious. Ask @valideo_bot for the free days, import the key and run the checks above. You will see each stage do its job on your own device: the lookup page changes city, the leak test goes quiet, and an app that was blocked a minute ago opens. That small experiment teaches more than any diagram, and it costs nothing, because the trial takes no card.
Q.How do VPNs work on a phone compared with a laptop?
A.Identically under the hood. iOS and Android simply offer a ready made slot for the tunnel, so there is no mode to choose.
Q.Where exactly does the encryption stop?
A.At the VPN server. From there to the website your data is protected by the site's own HTTPS, as it always was.
Q.Protocol, client, key: what is what?
A.The protocol is the set of rules, for example VLESS or WireGuard. The client is the program that follows them. The key tells the client which server to call and how to prove itself.
Q.Can a network tell that I am using a VPN?
A.It can spot older protocols by their opening packets. Reality copies the opening of an ordinary secure website visit, so there is little to spot.
Q.Is there anything to type in, such as ports or certificates?
A.Nothing. One paste of the vless:// line carries every value the client needs.
Q.My own IP still shows on a lookup page. Why?
A.Three usual suspects: the client is in proxy mode and that program ignores proxies, IPv6 is slipping past, or the browser's WebRTC is talking. Full tunnel mode plus a leak test sorts it out.